Courseiva

PCA · domain

scenario questions

Practise Google Professional Cloud Architect scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

807 questions222 easy349 medium236 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (807)

Click any question to see the full explanation, or start a practice session above.

1

A company uses BigQuery for large-scale analytics. They have a fixed monthly budget and want to ensure predictable costs for query processing, even when many users run concurrent queries. Which BigQuery pricing model should they use?

Hard
2

Refer to the exhibit. A cloud administrator is attempting to grant the BigQuery Data Viewer role to an external user (user@example.com) but receives the error shown. What is the most likely cause?

Medium
3

A company needs to store archival data that is accessed less than once a year. They want the lowest storage cost possible, but they can accept a retrieval time of up to 24 hours. Which Cloud Storage class should they use?

Easy
4

A company is deploying a microservices application on Google Kubernetes Engine (GKE). The architect needs to ensure that the cluster can automatically scale nodes based on pod resource requests and that pods are scheduled efficiently across nodes. The company also wants to minimize costs by scaling down when demand is low. Which two configurations should the architect implement? (Choose two.)

Medium
5

A security team needs to detect and redact personally identifiable information (PII) in documents stored in Cloud Storage before sharing them with external partners. Which two Google Cloud services should they use together? (Choose two.)

Medium
6

An engineer needs to view the logs of a specific Compute Engine instance in near real-time from the command line. Which gcloud command should they use?

Easy
7

A healthcare organization stores Protected Health Information (PHI) in Cloud SQL. They have implemented encryption at rest using CMEK and enforce TLS for all connections. To meet HIPAA compliance, they need to ensure that PHI cannot be exfiltrated from the Cloud SQL instance even if an application is compromised. The Cloud SQL instance is accessed by Compute Engine instances in the same VPC using private IPs. The security team wants to add an additional layer of defense against data exfiltration. What should they do?

Hard
8

Your company's global e-commerce platform uses a managed instance group (MIG) in us-central1 and a Cloud Load Balancer. Traffic has grown, and you want to improve availability by distributing load across multiple regions. What should you do?

Medium
9

Refer to the exhibit. A user (ops@example.com) is unable to create a new VPC network in the project. What should the administrator verify first?

Easy
10

Refer to the exhibit. All five nginx pods are scheduled on the same node (default-pool-1). What is the most likely reason?

Hard
11

An online retailer runs a stateless containerized API on Google Kubernetes Engine. Traffic is highly seasonal, spiking sharply during flash sales and dropping to near zero overnight. The operations team wants the cluster to add and remove nodes automatically based on pod demand while keeping costs low during idle periods. What should the architect recommend?

Easy
12

A team uses Cloud Build for CI/CD. The builds are taking longer than expected due to dependency downloads. What is the best practice to speed up builds?

Easy
13

A financial services firm runs batch risk calculations nightly using a large Compute Engine VM with a GPU. Jobs complete in 4 hours but are not time-sensitive. To reduce costs without sacrificing reliability, the firm enables preemptible VMs but finds that jobs are interrupted and restarting from scratch causes delays. What is the best approach to improve reliability while maintaining cost savings?

Hard
14

The firewall rule 'allow-ssh' was not created. According to the audit log, what is the most likely reason?

Hard
15

A financial services firm is designing a new payment processing system on Google Cloud. The system must expose a single global anycast IP address, terminate TLS at the edge, and route requests to the nearest healthy backend across three regions. The backend services run on Compute Engine and must be protected from volumetric DDoS attacks. Which product should you place in front of the backends?

Hard
16

A startup is deploying a new web application on Google Cloud. The application runs in containers on Google Kubernetes Engine (GKE) and uses a Cloud SQL for MySQL instance. The team wants to follow the principle of least privilege for the application's access to Cloud SQL. Which method should the architect recommend for authenticating the application to Cloud SQL?

Easy
17

A company wants to deploy a containerized application on Google Cloud and needs persistent storage that can be accessed by multiple pods in a GKE cluster concurrently. Which storage solution should they use?

Easy
18

A financial services company runs a multi-tier application on Compute Engine. They need to restrict network access so that only the web tier can communicate with the application tier, and only the application tier can access the database tier. All VMs are in the same VPC network. What is the most secure way to implement this?

Medium
19

A startup is deploying a new web application on Google Kubernetes Engine (GKE). They want to expose the application to the internet with a single global IP address and automatically route users to the closest regional cluster. They also want to minimize operational overhead. Which GKE feature should they use?

Easy
20

A company has set up an external HTTP(S) load balancer with a backend service pointing to a managed instance group. Some instances are failing health checks. Which TWO actions should the company take to troubleshoot the issue?

Hard
21

A media company stores millions of video files in a Cloud Storage bucket and serves them to users worldwide. Users in Asia report slow download speeds, while users in North America are satisfied. The files are immutable after upload and are read frequently for the first 30 days, then almost never. You want to improve global performance while minimizing cost. What should you do?

Medium
22

A company wants to grant a service account in Project A the ability to push containers to Artifact Registry in Project B. They want to follow the principle of least privilege. Which IAM roles should they assign?

Medium
23

An online learning platform runs its API on a regional managed instance group behind an external Application Load Balancer. The operations team wants to release new versions with the ability to shift a small percentage of user traffic to the new version first, then increase it gradually, and roll back instantly if error rates rise. What should they implement?

Easy
24

An e-commerce company is experiencing traffic spikes during flash sales. Their application runs on Compute Engine instances behind a TCP load balancer. They want to automatically scale the number of instances based on CPU utilization. Which configuration is required?

Medium
25

An organization runs a stateful application on GKE that must not lose data during cluster upgrades or node repairs. The application uses persistent volumes with ReadWriteOnce access mode. The team wants to ensure pods are not evicted simultaneously. Which Kubernetes resource should they configure?

Medium
26

You need to create a private GKE cluster with Workload Identity enabled to allow pods to access Google Cloud APIs without static service account keys. What must you configure for the cluster?

Medium
27

A company is deploying a web application on Compute Engine. They want to automatically scale the number of instances based on CPU utilization. Which two components are required to set up autoscaling? (Choose two.)

Easy
28

A company wants to monitor the health of their Cloud Run services. Which THREE metrics should they use to define a comprehensive health SLI? (Choose 3)

Easy
29

An organization wants to connect their on-premises data center to Google Cloud with a dedicated 10 Gbps link. They require high availability and have budget for two physically diverse connections. Which solution should they choose?

Easy
30

A media company runs a video transcoding service on GKE Standard. The service experiences sudden traffic spikes, and the operations team wants to ensure that the cluster can scale nodes automatically and that pods are rescheduled quickly when a node fails. The team also wants to monitor and alert on resource saturation. Which two actions should the cloud architect take to meet these requirements? (Choose two.)

Medium
31

Your company runs a critical application on Compute Engine instances in us-central1. The application requires low latency between instances that are all in the same region. You notice that network latency between instances varies and sometimes spikes. You want to ensure consistent low-latency communication. You currently use external IP addresses for communication between instances. What should you do?

Easy
32

Which Google Cloud service provides a fully managed, serverless data warehouse for petabyte-scale analytics using SQL?

Easy
33

An engineer runs the command above. A few days later, the instance becomes unresponsive. Upon investigation, you find that the boot disk is 100 GB and 95% full. The data disk is 500 GB and only 20% full. What is the most likely cause of the unresponsiveness?

Hard
34

A company runs a multi-tier web application on Google Kubernetes Engine (GKE) with a frontend service, a backend service, and a Cloud SQL for PostgreSQL database. During peak hours, the frontend pod CPU usage is high (consistently above 80%), while the backend service shows moderate CPU usage (around 50%). Response times for user requests increase significantly, often exceeding the 200ms p99 latency target. Cloud SQL metrics show low query latency and no contention. The team wants to improve performance in a cost-effective manner. Which initial step should they take?

Medium
35

A global logistics company runs a three-tier application on Compute Engine in a single region. The database tier must survive the loss of an entire zone without data loss, and the application tier must continue serving traffic with minimal disruption during a zonal failure. The architect wants the smallest operational change that satisfies both requirements. Which design should the architect implement?

Hard
36

A security team wants to prevent data exfiltration from a GKE cluster to external storage. They need to restrict access to Cloud Storage buckets from the cluster without using private IPs. Which solution should they implement?

Medium
37

A financial services firm runs a regulated workload on Compute Engine. Auditors require that all data at rest on persistent disks be encrypted with keys the firm controls and can revoke, and that key usage be logged independently of the project's Cloud Audit Logs. The firm's security policy forbids storing key material in the same project as the workload. Which approach meets these requirements?

Hard
38

A company uses Cloud Armor to protect their HTTP load balancer. They need to block traffic from a specific set of IP addresses and also prevent SQL injection attacks. Which two configurations should they use? (Choose TWO.)

Hard
39

A media company is designing a new content delivery architecture on Google Cloud. Users worldwide download large video files, and the company wants to serve them from a global edge cache while keeping the origin bucket private. They also want to reduce egress cost by caching at the edge. Which Google Cloud service should you recommend as the front end for this architecture?

Easy
40

Your company uses Cloud SQL for PostgreSQL to support a web application. During peak hours, the database experiences high read load, causing slow query responses. You need to improve read performance while ensuring data consistency. What should you do?

Medium
41

A developer wants to store a database password that is used by a Cloud Function. The password must be automatically rotated every 30 days and accessed securely without storing it in the source code. Which GCP service should they use?

Easy
42

An engineer needs to grant a user the ability to create and manage service accounts in a project. Which predefined IAM role provides these permissions?

Easy
43

An organization uses Active Directory (AD) on-premises and wants to synchronize user identities to Google Cloud Identity so that users can access G Suite and GCP resources with their existing credentials. Which service should they use?

Medium
44

A company's BigQuery costs are higher than expected. They run many ad-hoc queries with filters on the 'transaction_date' column and 'customer_id' column. They also have a materialized view that is rarely used. Which combination of actions will MOST effectively reduce query costs?

Hard
45

An organization uses Cloud Deployment Manager to manage infrastructure as code. They need to ensure that changes to production resources are reviewed and approved before deployment. What should they do?

Medium
46

You need to monitor the performance of a production Cloud Run service and set an alert when the p99 latency exceeds 500 ms over a 5-minute window. Which combination of Cloud Monitoring resources should you use?

Medium
47

A startup is deploying a containerized application on Google Kubernetes Engine (GKE). The development team wants to minimize operational overhead for managing the Kubernetes control plane and nodes. They also want to ensure that nodes are automatically upgraded and repaired. Which GKE mode should they use?

Easy
48

A small startup is deploying a new application on Google Cloud. They want to ensure that they can monitor the application's performance and receive alerts when certain thresholds are exceeded. They have limited operational staff and want a managed solution that requires minimal configuration. Which Google Cloud service should they use?

Easy
49

A company is migrating its on-premises data warehouse to BigQuery. The data is currently stored in several CSV files on a Compute Engine instance. The company needs to load the data into BigQuery once and then perform complex analytical queries. The data volume is about 10 TB, and the company wants to minimize cost and loading time. Which approach should the architect recommend?

Medium
50

Which two GCP audit log types are available by default? (Choose TWO).

Easy
51

A startup wants to deploy a containerised web application that auto-scales based on HTTP request traffic, with no infrastructure management. They expect unpredictable traffic spikes. Which compute service is most suitable?

Easy
52

Drag and drop the steps to implement a disaster recovery plan using Cloud Storage and Cloud Functions in the correct order.

Medium
53

Which THREE are best practices for managing secrets (e.g., API keys, passwords) in Google Cloud? (Select exactly 3.)

Hard
54

A healthcare company stores patient records in Cloud Storage and BigQuery. Auditors require that cryptographic keys used to protect this data are generated and stored on hardware security modules, that key material never leaves Google's infrastructure, and that the company retains the ability to control key rotation and revocation. The security team wants the least operational overhead while meeting these requirements. Which key management approach should the architect select?

Medium
55

A company wants to analyze their Google Cloud spending and receive recommendations for rightsizing resources. Which tool provides this functionality?

Easy
56

A company deploys a Kubernetes workload in GKE that needs to access Cloud Storage. They want to avoid managing service account keys. What is the recommended approach?

Hard
57

A developer is migrating a stateful application to GKE. The application requires persistent storage with high IOPS for a database. Which storage option is most suitable?

Easy
58

A company is migrating its on-premises Hadoop cluster to Google Cloud. They want to use a fully managed service that supports HDFS, Hive, and Spark, and allows them to run ephemeral clusters that can be created and deleted on demand. They also want to minimize infrastructure management. Which Google Cloud service should they use?

Easy
59

A media company runs a monthly batch pipeline that transcodes video uploads stored in Cloud Storage. The pipeline runs on a Managed Instance Group of Compute Engine VMs and typically completes in 6 hours. The VMs are only needed during this window, but the team wants to minimise the operational effort of stopping and starting the group. Which approach best optimises both cost and operational overhead?

Medium
60

Your organization requires all container images deployed to GKE to be signed by an approved authority. Which service enforces that only signed images are allowed to run?

Medium
61

Your company runs a stateful application on Compute Engine instances in a managed instance group (MIG). The application writes data to a persistent disk attached to each instance. You need to ensure that the application can automatically recover from a zone failure by recreating instances in another zone with their persistent disks. You also want to minimize data loss. Which configuration should you implement?

Medium
62

Drag and drop the steps to configure IAM roles for a service account to access Cloud Storage from a Compute Engine instance into the correct order.

Medium
63

A company uses Cloud SQL for PostgreSQL. They want to minimize downtime during maintenance. Which feature should they enable?

Easy
64

Your company runs a critical application on Google Kubernetes Engine (GKE) with 5 nodes. The application experiences intermittent high latency every Friday afternoon. The team has ruled out infrastructure issues and suspects the application logic. You need to instrument the application to identify the root cause. Which approach should you take?

Easy
65

A company needs a relational database that can scale horizontally across multiple regions, supports ACID transactions, and provides strong global consistency. Which Google Cloud database should they choose?

Easy
66

Match each IAM role type to its description.

Medium
67

Which THREE are required to configure Workload Identity for a GKE cluster? (Choose 3)

Hard
68

A company runs a service on Cloud Run that needs to access a Cloud SQL instance via private IP. Both are in the same VPC network. The service cannot connect to the database. What is the most likely cause?

Hard
69

An organization is using Cloud Interconnect to connect their on-premises network to Google Cloud. They need to ensure 99.99% availability for their connection. Which configuration meets this requirement?

Medium
70

After executing the command, a security review reveals that the service account sa-bucket-reader can also list buckets in the project, which was not intended. What is the most likely cause?

Easy
71

A software company wants to give a third-party analytics vendor read access to a specific BigQuery dataset containing aggregated, non-sensitive sales data, without creating service account keys that the vendor must store and rotate. The security team also wants to be able to revoke access quickly and to see which vendor identities accessed the data. The vendor already uses its own identity provider that supports OpenID Connect. Which TWO approaches together meet these requirements? (Choose two.)

Hard
72

A logistics company is planning to migrate a batch ETL pipeline from on-premises Hadoop to Google Cloud. The pipeline processes several terabytes nightly, and the team wants to minimize infrastructure management while keeping the ability to tune the cluster for cost and performance. The data currently resides in an on-premises HDFS cluster. Which combination of services should the architect recommend?

Medium
73

A company wants to implement blameless postmortems as part of their SRE practices. Which THREE principles should they follow?

Medium
74

A company wants to migrate an on-premises Oracle database to Google Cloud. They need high availability and want to minimize application changes. Which service should they use?

Medium
75

A financial services firm runs a latency-sensitive trading API on Google Kubernetes Engine (GKE). During peak market hours, the API occasionally returns errors because pods are evicted when nodes run out of memory. The team wants the workload to be protected from node-level resource pressure and to receive a graceful termination window when the node must be drained. Which configuration should they apply to the Deployment?

Hard
76

A small e-commerce team wants to deploy a containerized storefront to Google Cloud with minimal operational overhead. Traffic is steady, the team has no Kubernetes expertise, and they want to pay only for what they use while the service scales automatically. Which compute option should the architect recommend?

Easy
77

A company has deployed a critical application on Google Kubernetes Engine (GKE) with a Regional cluster (us-central1). The application uses a Cloud SQL for PostgreSQL database with a cross-region replica for disaster recovery. The SRE team needs to ensure that the application can survive a regional outage with minimal data loss. Which TWO actions should the team take to improve the reliability of the solution?

Medium
78

A company commits to using Compute Engine for 3 years and wants the maximum discount. Which purchasing option should they use?

Easy
79

A healthcare company runs a critical patient portal on Compute Engine. The portal uses a Cloud SQL for PostgreSQL database. The company needs to perform a major version upgrade of the database with minimal downtime and wants to minimize the risk of data loss. They also want to be able to roll back quickly if issues arise. Which approach should they take?

Hard
80

Your company runs a stateful application on Compute Engine instances in a managed instance group. The application requires that each instance maintains a unique identity and persistent storage. You need to ensure that instances can be recreated without data loss and that they retain their identities. What should you do?

Hard
81

A company has two VPC networks in the same project: 'vpc-prod' and 'vpc-dev'. They want to allow communication between instances in both VPCs. What is the simplest method?

Medium
82

A company runs a web application on Compute Engine behind a HTTP(S) Load Balancer. They want to reduce latency for users worldwide. Which Google Cloud service should they use?

Medium
83

Which TWO statements about Google Cloud VPC networks are true? (Choose two.)

Easy
84

A company runs a microservices application on Google Kubernetes Engine (GKE). Each service is deployed as a Deployment with resource requests and limits. After deploying a new version of a service, the pods start crashing with OOMKilled. The team increased the memory limits in the Deployment manifest, but the pods still crash after a few minutes. The cluster has cluster autoscaling enabled. The node pool has sufficient capacity. What is the most likely cause of the issue?

Medium
85

A financial analytics firm is deploying a new batch reporting platform on Google Cloud. The platform runs on a Managed Instance Group (MIG) of Compute Engine VMs and reads source data from a single Cloud Storage bucket. The security team requires that the VMs access the bucket without using long-lived service account keys, and that the identity be scoped specifically to this workload. They also want the permission to be automatically revoked when the VMs are deleted. Which approach should you recommend?

Medium
86

A company is using Cloud Load Balancing to distribute traffic to a managed instance group (MIG) of web servers. The web servers are currently running in us-central1. To improve availability, the company plans to add a second MIG in us-west1. What must be done to ensure traffic is automatically routed to the closest healthy backend?

Medium
87

A global e-commerce platform is experiencing intermittent latency spikes during flash sales. The application is deployed on Google Kubernetes Engine (GKE) with a regional cluster. The architecture includes a frontend service, a product catalog service using Cloud Spanner, and an order processing service using Cloud Pub/Sub. During high load, the catalog service shows increased query latency, and some requests time out. What should the architect prioritize to address the issue?

Hard
88

Your team runs a stateful analytics workload on a Managed Instance Group (MIG) of Compute Engine VMs. The VMs write intermediate results to local SSD scratch disks. During a recent incident, an autoscaling event terminated VMs and the intermediate data was lost, causing hours of recomputation. You need to change the deployment so that when a VM is terminated by the autoscaler, a shutdown script has enough time to flush the intermediate results to a Cloud Storage bucket before the VM is deleted. What should you do?

Medium
89

During a load test, an application running on GKE experiences high latency and errors. You suspect the issue is due to insufficient cluster resources. Which gcloud command should you use to quickly check the current resource utilization of all nodes in the cluster?

Hard
90

A healthcare company runs a patient portal on Google Kubernetes Engine (GKE). Auditors require that all container images be scanned for vulnerabilities before deployment and that only images from a trusted registry be admitted to the cluster. You are configuring Binary Authorization. Which TWO actions should you take to meet these requirements? (Choose two.)

Hard
91

A developer needs to programmatically create and manage Compute Engine instances. Which Google Cloud service should they use to authenticate and authorize service accounts?

Easy
92

An organization wants to enforce that all container images deployed to Google Kubernetes Engine (GKE) clusters are signed by an authorized authority and only those images are allowed to run. Which GCP service should they use?

Easy
93

A company is planning to deploy a global web application on Google Cloud. They expect low latency for users worldwide and need to serve static content (images, CSS) as well as dynamic API responses. Which architecture should they use?

Easy
94

A company wants to set a monthly spending limit for their Compute Engine usage and receive alerts when spending exceeds a threshold. Which tool should they use?

Easy
95

A media company's analytics team runs a nightly Apache Spark ETL job on a Dataproc cluster with 20 worker nodes. The job processes raw logs from Cloud Storage and writes Parquet files back to Cloud Storage. The cluster is created before the job starts and deleted after the job finishes, taking about 90 minutes total. The team wants to reduce the cost of this workload without changing the Spark code or increasing job runtime. What should they do?

Medium
96

A developer needs to securely store a database password that will be used by a Compute Engine instance. The password must be rotated automatically every 30 days. Which service should they use?

Medium
97

A company wants to implement a CI/CD pipeline for a Java application that will be deployed to Cloud Run. They use Cloud Build and Artifact Registry. The pipeline must compile the Java code, run unit tests, build a container image, and deploy to Cloud Run. Which THREE steps are required in the cloudbuild.yaml? (Choose 3)

Hard
98

A company stores sensitive customer data in Cloud Storage buckets. They want to ensure that access to these buckets is only allowed from within their VPC network. Which configuration should they use?

Medium
99

An organization has multiple projects in Google Cloud and wants to centralize logging and monitoring for all projects. They need to aggregate logs from all projects into a single project for analysis. Which approach should they use?

Hard
100

A global e-commerce company is designing a multi-region architecture on Google Cloud to ensure high availability and low latency for users worldwide. They want to use a global load balancer that can route traffic to the closest healthy backend and support HTTP(S) and TCP traffic. Which Google Cloud load balancing option should they use?

Medium
101

A healthcare organization uses Cloud Storage to store protected health information (PHI). They have a compliance requirement to ensure that all objects in the bucket are encrypted with a customer-managed key (CMK) that is rotated every 90 days. They also need to log all access to the bucket and detect anomalous access patterns. Which combination of Google Cloud services should they use?

Hard
102

A company monitors their application with Cloud Monitoring. They set up an alerting policy to notify the on-call team when the 99th percentile latency exceeds 500 ms for 5 minutes. However, they receive false positive alerts due to short bursts. How should they refine the policy?

Medium
103

A financial services firm runs a global trading platform on Google Cloud. The architecture must survive the loss of an entire region with a recovery point objective of zero and a recovery time objective of under one minute, and it must keep strong consistency for order records. Which design should the architect recommend?

Hard
104

A startup wants to deploy a web application on Google Cloud with a MySQL database. They anticipate low traffic initially but want the ability to scale seamlessly. They also want to minimize operational overhead. Which combination of services should they choose?

Easy
105

A startup wants to deploy a containerized application with minimal operational overhead. They expect variable traffic. Which compute option should they choose?

Easy
106

You are responsible for ensuring the reliability of a high-traffic web application running on Google Kubernetes Engine (GKE). You need to implement a monitoring strategy that alerts you when the application's error rate exceeds 1% over a 5-minute window. You want to minimize false positives and ensure alerts are actionable. What should you do?

Hard
107

To achieve a 99.999% availability SLA for a globally distributed application using Cloud Spanner, which configuration is required?

Easy
108

A company runs batch analytics workloads on Compute Engine that can tolerate interruptions. They want to reduce compute costs by up to 60-90%. Which compute option is the most cost-effective?

Medium
109

An organization needs to implement a change management process for a mission-critical application on GKE. They want to validate performance before full rollout and be able to roll back quickly. Which THREE practices should they adopt? (Choose THREE.)

Medium
110

Which Google Cloud service provides a fully managed, auto-scaling environment for running stateless HTTP(S) web applications using a variety of supported programming languages?

Easy
111

Refer to the exhibit. A developer is trying to connect to the Kubernetes API server from their workstation using the master IP (34.67.89.12) but receives a timeout. The developer can reach other external IPs. What is the most likely reason for the timeout?

Hard
112

A company is planning a phased migration of their on-premises database to Cloud SQL. They want to minimize downtime and ensure data consistency. Which approach should they use?

Medium
113

A healthcare analytics company stores protected health information in Cloud Storage buckets. Auditors require that data be encrypted with customer-managed encryption keys (CMEK) and that key usage be logged separately from data access. The security team wants the ability to revoke access to the data by disabling a single key without deleting the data. Which configuration should the architect recommend?

Hard
114

A company has a global user base and wants to serve static content (images, videos, CSS) with low latency from edge locations. They also want to protect their origin server from traffic spikes. Which combination of services should they use?

Medium
115

A company is using Cloud NAT to allow private instances to access the internet. They notice that outbound connections are failing intermittently. What is the most likely cause?

Easy
116

A company uses Cloud Storage for analytics data with lifecycle policies to move objects from Standard to Coldline after 30 days and delete after 365 days. They notice that objects are being deleted after 30 days instead of 365. What is the most likely cause?

Hard
117

Your company runs a containerized microservices application on Google Kubernetes Engine (GKE) with a regional cluster. The application consists of a frontend service, a backend API service, and a background worker service that processes messages from Cloud Pub/Sub. The worker service uses a Deployment with 3 replicas. Recently, the team noticed that the worker service is frequently failing with 'ContainerCreating' errors. The error message in the pod events is: 'Failed to pull image "gcr.io/my-project/my-worker:latest": rpc error: code = DeadlineExceeded desc = context deadline exceeded'. The image is stored in Container Registry in the same project. The cluster nodes are n1-standard-2 VMs with 10 GB of disk space. The team has confirmed that the image exists and that the nodes have internet access. What is the most likely cause of the issue?

Hard
118

A company uses Cloud Storage for backup data. They want to protect against accidental deletion. Which option is best?

Easy
119

A team is deploying a microservice on Cloud Run that needs to access a Cloud SQL database securely. They want to avoid using public IPs and ensure traffic stays within Google's network. Which configuration should they use?

Medium
120

A company runs a global e-commerce site on GKE. They want to ensure disaster recovery with multi-region deployment. What is the best practice for configuring GKE clusters?

Easy
121

A logistics company runs a Cloud Run service that processes shipment events. They want to be notified and to trigger an automated rollback when the error rate of a new revision exceeds a threshold shortly after deployment. Which Google Cloud feature should they use?

Easy
122

A company is designing a data pipeline to ingest streaming data from IoT devices and store it in BigQuery for analysis. They need to minimize latency and operational overhead. Which two Google Cloud services should they use? (Choose two.)

Easy
123

Your company runs a stateless web application on Compute Engine. You want to ensure that if a zone fails, the application continues to serve traffic with minimal manual intervention. What should you do?

Easy
124

A company uses Cloud Storage to store user-uploaded content. They want to ensure that the data is highly durable and protected against accidental deletion. Which two features should they enable? (Choose two.)

Easy
125

A developer needs to deploy a Python script that processes images uploaded to a Cloud Storage bucket. The script should run only when new objects are created, and should scale automatically with no idle costs. Which GCP service is most appropriate?

Easy
126

A financial services company requires that all audit logs be retained for 7 years in a cost-effective, immutable storage. They also need to run ad-hoc SQL queries on the logs. Which configuration should they use?

Hard
127

A startup is deploying a new web application on Google Cloud. They want to minimize infrastructure management and focus on writing code. The application consists of a frontend and a backend API, and they expect variable traffic. They also want to pay only for what they use. Which Google Cloud service should the solutions architect recommend for deploying the application?

Easy
128

Your team is deploying a new internal web application on Compute Engine. The security team requires that all outbound internet traffic from the instances be inspected by a third-party firewall appliance running on a separate VM. You need to implement this with minimal changes to the application instances. What should you do?

Medium
129

An engineering team is deploying a microservices application on Google Cloud. They want to use a service mesh for observability, traffic management, and security. They are considering Anthos Service Mesh (ASM). Which THREE components are part of ASM? (Choose THREE.)

Hard
130

Your company runs a microservices application on Google Kubernetes Engine (GKE). The development team complains that they lack visibility into which service is causing latency spikes during peak hours. You need to implement a solution that provides distributed tracing and service-level metrics without modifying application code. Which approach should you use?

Medium
131

Your team is deploying a new three-tier application to Google Cloud. The security team requires that the application's Compute Engine instances never receive public IP addresses, yet the instances must still download OS patches from the public internet and reach a third-party REST API over HTTPS. You need to implement this with the least operational overhead. What should you do?

Medium
132

Your organization is using Google Cloud to host a web application that experiences unpredictable traffic spikes. You need to ensure the application scales automatically and maintains high availability across multiple zones. The application runs on Compute Engine instances behind a load balancer. What should you do?

Easy
133

An organization wants to enforce that all container images deployed to Google Kubernetes Engine (GKE) are signed and approved via an attestation authority. Which GCP service should they use?

Easy
134

A developer is using Cloud Build to automate deployments. The build fails with an error: 'Permission 'iam.serviceAccounts.actAs' denied.' What is the most likely cause?

Medium
135

A developer needs to cache session state for a web application to reduce latency. The cache must be highly available and support sub-millisecond access times. Which Google Cloud service should they use?

Easy
136

An application running on Compute Engine is experiencing increased latency. You suspect a network bottleneck due to high egress traffic. Which gcloud command can you use to quickly check the network egress traffic for a specific VM instance?

Hard
137

Drag and drop the steps to set up a VPC network peering between two projects in Google Cloud into the correct order.

Medium
138

A company is deploying a global web application on Google Cloud. The application serves static content from a Cloud Storage bucket and dynamic content from a managed instance group backend. They want to use a single global IP address and provide low latency to users worldwide. They also want to protect the application from DDoS attacks. Which solution should they implement?

Hard
139

An organization is implementing a data loss prevention (DLP) strategy for sensitive data stored in Cloud Storage. They want to automatically detect and redact credit card numbers in CSV files uploaded to a specific bucket. Which TWO Google Cloud services should they combine to achieve this?

Hard
140

Your organization operates a multi-project Google Cloud environment. A security team requires that any new Compute Engine instance created in the production folder must have OS Login enabled and must not use project-wide SSH keys. You want to enforce this centrally with the least operational overhead and ensure that non-compliant creation attempts are denied. What should you do?

Hard
141

A multinational retailer is planning its Google Cloud landing zone. Each of the company's business units must be able to create projects and manage billing independently, but the central platform team must retain the ability to enforce network and security guardrails across everything. The company also wants to minimize the number of distinct IAM policy bindings it maintains at the top of the hierarchy. Which two design choices should the architect make? (Choose two.)

Hard
142

You are deploying a new version of a microservice to Google Kubernetes Engine (GKE). The service must remain available during the rollout, and you need to minimize the risk of exposing bugs to all users at once. You want to gradually shift traffic to the new version while monitoring key metrics. Which strategy should you use?

Hard
143

A company has a Shared VPC with a service project hosting GKE clusters. The GKE nodes need to access Cloud SQL instances in the host project. The team wants to avoid public IP and use Private Service Access. They have configured a VPC peering between the host VPC and the service producer VPC for Cloud SQL. However, the GKE pods cannot reach the Cloud SQL instance. What is the most likely cause?

Hard
144

A company is migrating its on-premises MongoDB database to Google Cloud. They want a fully managed, highly available NoSQL database that is compatible with MongoDB drivers. Which Google Cloud service should they choose?

Hard
145

An organization uses Active Directory (AD) on-premises. They want to synchronize user accounts and groups to Google Cloud Identity so that users can sign in with their existing AD credentials. Which service should they use?

Medium
146

Drag and drop the steps to set up a Cloud VPN tunnel between Google Cloud and an on-premises network into the correct order.

Medium
147

A company is running a web application on Compute Engine instances that average 20% CPU utilization. They want to reduce costs without impacting performance. What is the most effective action?

Easy
148

A company hosts a web application on Compute Engine behind a global HTTP(S) load balancer. They notice that some users experience high latency from certain regions. They want to improve performance without adding complexity. What should they do?

Medium
149

A company is migrating a legacy e-commerce platform to GKE. The application consists of several stateless microservices and a stateful database. They want to minimize operational overhead for the database while ensuring high availability across zones. Which database option should they choose?

Hard
150

A company is migrating a monolithic application to Google Cloud. The application consists of a stateful service that writes to local disk and a stateless web server. They want to minimize changes to the code. Which architecture should they use?

Hard
151

A financial services company must run a PostgreSQL database with strong consistency across three regions. They need to support high write throughput and require automatic failover with zero data loss. Which database service should they choose?

Medium
152

A company is planning to migrate a batch processing workload to Google Cloud. The workload runs nightly and can be interrupted without impacting the business. The company wants to minimize compute costs. Which Google Cloud service should they use?

Easy
153

A developer runs the command above. The instance is created successfully, but cannot be reached via HTTP from the internet. What is the most likely cause?

Medium
154

A company has a legacy application that runs on a single Compute Engine VM and expects to use a fixed IP address. They want to migrate the VM to a different region with minimal downtime. Which TWO actions should they take?

Medium
155

A company is migrating 50 on-premises VMs to Compute Engine. They need to minimise downtime and want an automated lift-and-shift migration that replicates disks incrementally. Which Google Cloud service should be used?

Medium
156

Drag and drop the steps to deploy a containerized application to Google Kubernetes Engine (GKE) using a Deployment into the correct order.

Medium
157

A startup wants to deploy a containerized web application that must scale automatically based on incoming HTTP request volume and must be reachable at a stable HTTPS endpoint. The team has no Kubernetes experience and wants to minimize infrastructure management. Which Google Cloud service should they use?

Easy
158

A company wants to give a new employee read-only access to all projects in their GCP organization. Which IAM role should they assign at the organization level to grant this access?

Easy
159

A company wants to run containerized applications on Google Cloud with minimal operational overhead. They prefer to use a serverless container platform. Which TWO compute options should they consider? (Choose 2.)

Medium
160

A company wants to monitor their Cloud Run services for errors and latency. Which Google Cloud product should they use?

Easy
161

Your service has a 99.99% uptime SLO (monthly error budget ~ 4 minutes). Which TWO monitoring practices best support this SLO? (Choose 2)

Hard
162

A company wants to migrate its on-premises monolithic application to Google Cloud with minimal changes. They plan to run it on a virtual machine with a predictable workload that runs 24/7 for a one-year commitment. Which compute option is MOST cost-effective?

Easy
163

A startup runs a batch analytics job on a single Compute Engine instance that takes about nine hours and reads 2 TB from a Cloud Storage bucket each run. The team wants to reduce cost without changing the application code, and the job can be interrupted and resumed from checkpoints. Which machine configuration should the architect recommend?

Easy
164

A GKE cluster has a Horizontal Pod Autoscaler (HPA) configured for CPU utilization. The pods are not scaling up even though CPU usage is high. What could be the reason?

Hard
165

A logistics company has a BigQuery dataset that is queried heavily by scheduled reports each morning. Finance wants predictable monthly spend and the ability to attribute query cost to each department. Analysts currently run ad hoc queries against on-demand pricing, and costs vary widely month to month. What should the architect recommend?

Medium
166

An engineer needs to share a VPC network across multiple projects in an organization while maintaining centralized network administration. Which approach should they use?

Medium
167

An e-commerce platform uses Cloud SQL (MySQL) for its transactional database. They are experiencing performance degradation during peak hours due to high read traffic. They need to improve read throughput without modifying the application code. Which TWO actions should they take? (Choose 2)

Medium
168

A startup is building a serverless application that processes events from Cloud Storage buckets. Each event triggers a Python function that resizes images. Which GCP compute service is MOST suitable for this event-driven workload?

Easy
169

A media company stores 400 TB of video assets in a Cloud Storage bucket in the europe-west1 region. Editors in Tokyo and São Paulo complain about slow first-byte times when previewing assets. The architect must improve read latency for these global users while keeping a single canonical copy of each object and avoiding application changes that rewrite object paths. Which approach best meets these requirements?

Hard
170

A security engineer is configuring VPC Service Controls to protect a project containing BigQuery datasets with PII. They want to prevent data exfiltration while allowing authorized users to query the data from outside the perimeter. Which configuration meets these requirements?

Hard
171

Which THREE of the following are recommended practices when designing a highly available architecture on Google Cloud using multiple regions?

Hard
172

A Cloud Spanner instance is experiencing high latency for point reads. The instance has 5 nodes and the read throughput is moderate. The table has a primary key with monotonically increasing values. What is the most likely cause and optimization?

Hard
173

A retail company runs a batch analytics workload on Compute Engine. Jobs run nightly, are fault-tolerant, and can be preempted. Finance wants to minimize compute cost while ensuring the jobs still complete each night. The jobs are managed by a Managed Instance Group (MIG) template that must stay within a single zone for data locality compliance. Which configuration should you recommend?

Medium
174

A company wants to use Binary Authorization to enforce that only images signed by their internal CI/CD pipeline can be deployed to their GKE clusters. They have set up Cloud Build to sign images. Which THREE steps are required to configure this? (Choose 3)

Hard
175

A company uses Cloud Storage to store sensitive customer data. They must ensure that data at rest is encrypted with a customer-managed key that is automatically rotated every 90 days. Which Cloud Storage configuration should they use?

Medium
176

A retail company is planning to move its on-premises data warehouse to Google Cloud. They need a fully managed, petabyte-scale analytics database that supports standard SQL and can ingest data in real time from Pub/Sub. They also want to minimize administration and cost. Which Google Cloud service should they choose?

Easy
177

Refer to the exhibit. A subnet was created with the `--enable-private-ip-google-access` flag. What does this flag enable for instances in this subnet?

Hard
178

An organization wants to enforce that all container images deployed to their Google Kubernetes Engine (GKE) clusters are signed and have passed a vulnerability scan. Which GCP service should they use to enforce this policy?

Easy
179

A company runs batch processing jobs nightly that can tolerate interruptions. They want to minimize compute costs for these jobs. Which Compute Engine machine type and provisioning model is most cost-effective?

Medium
180

A developer wants to allow a Compute Engine VM to authenticate to Google Cloud APIs without embedding service account keys in the VM image. What is the recommended approach?

Easy
181

A company wants to reduce costs for a batch analytics job that runs nightly for 4 hours on Compute Engine VMs. The job is fault-tolerant and can handle instance restarts. Which Compute Engine VM pricing model is MOST cost-effective?

Easy
182

A DevOps team wants to automate the deployment of infrastructure on Google Cloud using a declarative configuration language. They need to support Python and Jinja templates for reusable modules. Which service should they use?

Easy
183

A startup is deploying a new web application on Compute Engine. The application runs on a managed instance group and must be accessible from the internet over HTTP and HTTPS. The security team requires that the application be protected against common web attacks such as SQL injection and cross-site scripting. Which Google Cloud service should the architect use to meet these requirements?

Easy
184

Your team is deploying a new version of a microservices application on Google Kubernetes Engine (GKE). You want to gradually shift traffic to the new version while monitoring key performance indicators (KPIs) such as error rate and latency. If KPIs degrade, you need to automatically roll back. Which approach should you use?

Medium
185

A retail company runs a stateless web front end on a managed instance group of Compute Engine VMs behind an external Application Load Balancer. Traffic has grown, and the operations team wants to reduce the cost of idle capacity while still absorbing sharp, unpredictable spikes in user requests. They also want to avoid managing a separate autoscaling policy for each instance group. Which provisioning approach should the architect recommend?

Medium
186

A company runs a stateful application on GKE using StatefulSets. Which THREE practices improve reliability?

Hard
187

Your company runs a stateful web application on Compute Engine instances in a managed instance group (MIG) with autoscaling based on CPU utilization. The application maintains session state in memory on each instance. Recently, users have been experiencing session timeouts and data loss during scaling events. Additionally, the application's performance degrades under load due to frequent database queries for session data. You need to design a solution that ensures session persistence, improves performance, and minimizes application changes. The application is written in Java and uses Tomcat. Which of the following should you do?

Hard
188

A startup is setting up a CI/CD pipeline for their web application using Cloud Build and Cloud Deploy. They have configured a Cloud Build trigger that executes on pushes to the main branch of a Cloud Source Repositories repository. The trigger runs a build step that builds a Docker image and pushes it to Artifact Registry, then creates a release using Cloud Deploy. The pipeline fails with an error message indicating that the Cloud Build service account does not have permission to create releases. What should the architect do to resolve the issue?

Easy
189

A company runs a Kubernetes cluster on GKE. They need to ensure that pods cannot access Google Cloud APIs unless explicitly allowed through a service account. Which GKE feature should they use?

Medium
190

Refer to the exhibit. A Cloud Deployment Manager deployment fails with the error 'Resource 'my-firewall' already exists'. What is the most likely cause?

Hard
191

An e-commerce company uses Cloud SQL for MySQL to handle user sessions. During Black Friday sales, the database experiences high read latency and connection timeouts. The traffic pattern shows 95% read operations and 5% write operations. They need to improve read performance without significant architectural changes. Which action should they take?

Hard
192

You are responsible for operations reliability of a production service running on Google Cloud. The service is deployed on GKE and exposes an external HTTPS endpoint through an external Application Load Balancer. You need to implement monitoring that detects when the service is unhealthy from the user's perspective and alerts the on-call team. (Choose two.)

Medium
193

A startup runs a customer-facing web application on Cloud Run. The operations team needs to know when the service's request latency exceeds a threshold so they can respond before users complain. They want to be notified by email and also want a record of the incident for later review. Which Google Cloud service should they use to define the alerting policy?

Easy
194

Your company runs a multi-region Cloud Spanner instance for a global financial application. The SLA requirement is 99.999% availability. You need to ensure that the database remains available during a regional outage. What configuration should you use?

Medium
195

You are running a Kubernetes cluster in GKE with the default node pool configuration shown in the exhibit. Your application requires high disk I/O performance. You notice that the application is experiencing high latency for disk operations. What is the most likely cause?

Hard
196

Your company has a service running on Google Kubernetes Engine (GKE) that experiences occasional spikes in traffic. You need to ensure that the service remains available during these spikes by automatically scaling the number of pods based on CPU utilization. You also want to minimize cost by scaling down when traffic decreases. Which Kubernetes resource should you configure?

Easy
197

A startup runs a stateless web front end on a managed instance group in a single zone. Traffic is unpredictable, and the team wants the instance group to add or remove instances automatically based on CPU utilization without manual intervention. The architect must choose the simplest managed approach. Which option should the architect configure?

Easy
198

A media company runs a public web application behind a global external Application Load Balancer. They need to block traffic from specific countries subject to sanctions and rate-limit abusive clients, all without changing application code. Which Google Cloud service should the architect configure?

Easy
199

A startup is deploying a new web application on Google Cloud. They want to minimize operational overhead and ensure the application scales automatically based on traffic. They also want to pay only for what they use. Which Google Cloud service should the architect recommend?

Easy
200

A gaming company needs to store player session data that is frequently updated and requires strong consistency within a single region. The data model is simple key-value with few attributes. They expect up to 1 million concurrent players, each performing 10 writes per second. Which database is most suitable?

Medium
201

Your company runs a critical multi-tier application: a global HTTP(S) load balancer, multiple regional managed instance groups (MIGs) for the web tier, and Cloud Spanner for the data tier. You need to design for zone-level and region-level failures. What architecture ensures the highest availability?

Hard
202

A company has a fleet of Compute Engine instances that need to access a Cloud Storage bucket. The security team requires that only instances in specific VPC networks can access the bucket, and that the data is encrypted in transit. How can this be achieved?

Medium
203

A company runs a microservices application on Google Kubernetes Engine (GKE). They want to ensure that each service can only communicate with the services it explicitly depends on, and they need to enforce this at the network layer without modifying application code. They also want to monitor allowed and denied traffic. What should they do?

Hard
204

A financial services firm stores sensitive customer transaction data in Cloud Storage buckets. The security team wants to ensure that the data is encrypted at rest with a key that the firm controls, and that the key is automatically rotated every 90 days. They also need to be able to revoke access to the data immediately by disabling the key. Which Google Cloud service and configuration should they use?

Medium
205

A company wants to use Cloud Deploy to automate deployments to GKE. They need to configure an approval gate that requires manual approval before promoting a release to a production cluster. Where is this approval gate defined?

Medium
206

Your company is deploying a multi-tier application on Google Cloud. The application consists of a web frontend running on Compute Engine instances, a backend API running on Google Kubernetes Engine (GKE), and a Cloud SQL for MySQL database. You need to design the network architecture to ensure that the web frontend can communicate with the backend API, and the backend API can access the Cloud SQL database, while minimizing exposure to the public internet. Which two design choices should you implement? (Choose two.)

Hard
207

A company has a production database running on Cloud SQL. They need to ensure high availability with automatic failover in the event of a zone outage. What should they do?

Hard
208

An organization wants to manage Google Cloud infrastructure as code using declarative configuration files. They need a solution that supports Python and Jinja templating languages. Which service should they choose?

Easy
209

A company wants to allow users to authenticate to a web application running on Compute Engine using their existing corporate Active Directory credentials without exposing the application to the public internet. Which approach should they use?

Medium
210

Your organization runs a critical application on Compute Engine. The monthly bill shows sustained use discounts but the finance team wants to reduce costs further. The workload runs 24/7 with predictable usage for at least the next 12 months. You need to achieve the maximum possible discount without affecting performance or availability. What should you do?

Medium
211

A company is migrating a stateful application to Google Cloud. The application requires persistent disks with low latency and high IOPS for database workloads. They plan to use Compute Engine instances with SSD persistent disks. However, the database performance is lower than expected. Which action should the company take to improve disk performance?

Medium
212

Your team is responsible for a production service running on Google Cloud. You need to define Service Level Objectives (SLOs) and monitor them using Cloud Monitoring. You want to be alerted when the service's error budget is being consumed too quickly. Which approach should you take?

Medium
213

Which TWO are recommended practices for securing a Kubernetes Engine (GKE) cluster?

Medium
214

A company is using Cloud Load Balancing to expose a web application. They want to protect against common web attacks like SQL injection and cross-site scripting. Which Google Cloud service should they configure?

Medium
215

A developer wants to deploy a containerized web application on Google Cloud that can scale to zero when not in use and charges only for resources consumed during request processing. Which compute service should they choose?

Easy
216

A media streaming company wants to serve video content globally with low latency. They plan to cache static objects (thumbnails, manifest files) at edge locations, while dynamic API requests are handled by a backend in a single region. Which combination should they use?

Hard
217

Your organization runs a microservices application on Google Kubernetes Engine (GKE). Each microservice has its own deployment and horizontal pod autoscaler. You want to implement a robust cost governance process that provides chargeback to each team and prevents budget overruns. You need to attribute costs accurately without modifying application code. What should you do?

Hard
218

A startup wants to grant a contractor limited access to a single Cloud Storage bucket. The contractor should be able to view and download objects, but not delete or overwrite them. Which IAM role should be assigned?

Easy
219

A Cloud Run service needs to connect to a Cloud SQL MySQL instance privately without using public IP. What must be configured?

Medium
220

A company is designing a disaster recovery (DR) plan for their Cloud SQL for PostgreSQL instance. They need to recover the database to a specific point in time within the last 7 days, with a Recovery Point Objective (RPO) of less than 1 hour. Which feature should they use?

Medium
221

Which THREE of the following are best practices when using Deployment Manager to manage infrastructure? (Choose three.)

Medium
222

A Cloud Function fails to connect to a Cloud SQL instance. The Cloud SQL instance has a private IP. What should the developer check?

Medium
223

A media company runs a stateless web application on Compute Engine behind an HTTP(S) load balancer. They want to automatically replace unhealthy VMs and maintain a fixed number of running instances across two zones. What should they use?

Medium
224

Your company runs a production microservices application on GKE Standard. The operations team wants to be notified when any pod in the cluster is repeatedly restarting, indicating a potential CrashLoopBackOff. They want to use Cloud Monitoring to create an alert that fires when a container restarts more than 5 times in a 10-minute window. Which metric should they use as the basis for the alerting policy?

Medium
225

A team uses Cloud CDN to cache static assets. They update assets by deploying new versions with new URLs. However, sometimes they need to invalidate the cache for a critical fix immediately without changing the URL. What should they do?

Medium
226

A retail company runs a Black Friday promotion and expects a burst of read traffic against a product-catalog database. The application is read-heavy, tolerates slightly stale data, and the team wants to scale reads horizontally without changing application code. They are using Cloud SQL for MySQL. Which design should the architect recommend?

Easy
227

A security engineer wants to prevent data exfiltration from a project 'prod-data' by ensuring that only approved VPC networks can access BigQuery datasets. Which GCP service should be used?

Medium
228

Your company uses a CI/CD pipeline that builds container images and stores them in Artifact Registry. The images are deployed to Google Kubernetes Engine (GKE). You need to ensure that only images that have been scanned for vulnerabilities and approved by a security team can be deployed to the production GKE cluster. You want to enforce this policy automatically without modifying the CI/CD pipeline. What should you do?

Hard
229

A company uses Terraform to manage Google Cloud infrastructure. They want to store the Terraform state file in a remote backend with state locking to prevent concurrent modifications. Which Google Cloud service supports this natively?

Medium
230

A retail company runs a web application on Compute Engine instances behind an external HTTP(S) load balancer. During a flash sale, the operations team notices that the load balancer is returning HTTP 502 errors for a subset of requests. The backend service health checks are passing, and the instances are not under heavy CPU load. The team wants to identify the root cause quickly and prevent recurrence. Which action should they take first?

Medium
231

Your team is deploying a stateful web application on Google Kubernetes Engine (GKE). The application requires each replica to have a stable network identity and its own persistent disk that survives pod restarts. You also need to ensure that the persistent disk is automatically provisioned and attached. Which GKE feature should you use?

Medium
232

Which GCP service can be used to detect and redact sensitive data such as credit card numbers in text files stored in Cloud Storage?

Easy
233

A healthcare company is designing a system to process sensitive patient records on Google Cloud. They need to ensure that data is encrypted at rest with keys they control and can rotate on demand. They also require that the encryption keys are stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 validated. Which Google Cloud service should they use?

Hard
234

Your company is deploying a new application on Google Cloud and needs to ensure that it can meet a 99.9% availability SLA. You are designing the architecture for high availability. Which two practices should you implement? (Choose two.)

Medium
235

Which TWO of the following are valid methods to control access to Google Cloud resources using Identity and Access Management (IAM)?

Hard
236

A team is running a GKE cluster with a workload that has variable CPU and memory usage. They want to automatically adjust pod resource requests and limits based on historical usage to improve resource efficiency. Which feature should they use?

Hard
237

A media company stores large video files that are accessed infrequently (once a quarter) and must be retained for 10 years for compliance. They want to minimize storage cost. Which Cloud Storage class should they use?

Medium
238

A company is migrating its on-premises data warehouse to BigQuery. The security team requires that all data at rest in BigQuery is encrypted with keys that the company controls, and that key usage is logged for auditing. They also need to be able to revoke access to the data by disabling the key. Which configuration should they implement?

Medium
239

A media company runs a batch transcoding job on Compute Engine. The job pulls source files from a Cloud Storage bucket in the same project. Security policy forbids assigning external IP addresses to any VM. The VMs must reach the Cloud Storage API without traversing the public internet. What should the architect configure?

Medium
240

A company needs to encrypt data at rest in Cloud Storage using their own keys. They require that the keys are stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 certified. Which key management option should they choose?

Medium
241

A retail company uses a Cloud SQL for MySQL instance with a single zone. The database is critical for order processing, and the company wants to minimize downtime if the zone hosting the instance fails. They also want to ensure that the application can continue to write data during a zonal failure without manual intervention. What should they do?

Medium
242

A company wants to migrate an on-premises MySQL database to GCP with minimal downtime and support for automated failover in case of a zone outage. Which GCP service should they use?

Easy
243

An organization wants to enforce a policy that prohibits the creation of Cloud Storage buckets with uniform bucket-level access disabled. What should they use?

Hard
244

Which GCP service provides distributed tracing to help analyze latency in microservices applications?

Easy
245

A security engineer needs to restrict access to a Google Cloud project so that only a specific set of IP addresses can reach Cloud Storage buckets. Which feature should be configured?

Easy
246

A company stores large amounts of data in Cloud Storage and wants to reduce costs. Which two actions should they take? (Choose two.)

Medium
247

A company wants to allow a Kubernetes pod in GKE to authenticate to Google Cloud APIs without storing service account keys in the cluster. Which three components need to be configured to enable Workload Identity? (Choose three.)

Hard
248

A user runs the gsutil command shown in the exhibit and gets an AccessDenied error. The user is not authenticated with gcloud. What should the user do first?

Easy
249

A financial services company is designing a multi-region application on Google Kubernetes Engine (GKE) for high availability. They need to serve user requests from the closest region and automatically failover if a region becomes unavailable. Which architecture should they use?

Hard
250

An organization wants to protect an HTTPS load-balanced web application from common web attacks, such as SQL injection and cross-site scripting (XSS), as well as rate-limit traffic from specific IPs. Which three capabilities should they use together? (Choose three.)

Medium
251

A large enterprise is migrating their on-premises data center to Google Cloud. They have hundreds of VMs and need to minimize network latency between on-prem and cloud during migration. They have high bandwidth requirements. Which connectivity solution should they use?

Hard
252

An organization wants to manage DNS records for a domain they own (e.g., example.com) and use Google Cloud for authoritative DNS. They also need to resolve internal hostnames for resources within their VPC. Which Cloud DNS configuration should they use?

Easy
253

A financial services company runs a PCI-DSS regulated workload on Compute Engine. Auditors require that all administrative access to the VMs is brokered through a single, auditable control plane with short-lived credentials, and that no external IP addresses are assigned to the VMs. Which Google Cloud feature should the architect implement to meet these requirements?

Medium
254

An organization needs to store API keys and database passwords securely in Google Cloud. They want to automatically rotate secrets every 30 days. Which service should they use?

Medium
255

A logistics company is planning its first Google Cloud landing zone. It has three business units that must be billed separately, a central network team that manages shared VPCs, and a security team that needs to apply guardrails across everything. Which resource hierarchy design should the architect recommend?

Easy
256

A security team wants to audit all IAM role assignments in an organization. They need a historical record of changes. Which tool should they use?

Hard
257

An organization needs to encrypt data at rest in BigQuery using keys that are rotated every 90 days. They want to manage the keys themselves but cannot store keys on-premises. Which encryption approach should they use?

Hard
258

A company wants to allow a Kubernetes pod in GKE to access a Cloud Storage bucket using a specific service account without storing long-lived credentials. Which method should be used?

Medium
259

Your team manages a production web application on Compute Engine behind an external Application Load Balancer. During a recent incident, the load balancer's backend service marked all instances as unhealthy because the health check endpoint returned HTTP 200 but the application was actually in a degraded state. You need Cloud Monitoring to alert the operations team when the application's error rate exceeds 5% over a 5-minute window. You also need to ensure that the alert does not fire during planned maintenance windows. Which approach should you take?

Medium
260

A company is migrating an on-premises Oracle database to Google Cloud. They want to minimize application changes and need a fully managed, PostgreSQL-compatible database with high performance for OLTP workloads. Which service is MOST suitable?

Medium
261

Your company runs a production application on Compute Engine instances behind a managed instance group (MIG). You need to perform a rolling update with canary testing, gradually shifting traffic to the new version only if performance metrics are healthy. Which approach should you use?

Hard
262

A company wants to run batch processing workloads that can be interrupted and resumed, at the lowest possible cost. The jobs are fault-tolerant and can handle preemption. They also need predictable pricing for a baseline amount of compute. Which combination of compute options should they use?

Medium
263

Which THREE steps can reduce processing costs in a Dataflow streaming pipeline? (Choose three.)

Hard
264

A company wants to connect their on-premises network to Google Cloud with a dedicated, high-bandwidth, low-latency connection that supports Service Level Agreements (SLAs) up to 99.99% availability. Which connectivity option should they choose?

Easy
265

A company has Compute Engine instances that need to access the internet for updates but should not be reachable from the internet. They also need to access Google APIs and services like Cloud Storage. Which configuration meets these requirements?

Hard
266

A Cloud Run service frequently fails with 502 errors when making requests to a backend service running on Compute Engine. The two services are in the same VPC network. The Cloud Run service is configured with a VPC connector. What is the most likely cause?

Medium
267

A company operates a critical application on Google Cloud and wants to define a Service Level Objective (SLO) for its latency. They need to measure the proportion of requests that complete within 200 ms over a 28-day rolling window. They also want to alert when the error budget is being consumed too quickly. What should they use?

Medium
268

A company uses Shared VPC. A project admin in a service project tries to create a subnet in the shared VPC network but receives a permission denied error. What is the most likely cause?

Hard
269

A team runs periodic BigQuery queries on a large dataset. They notice high costs due to full table scans. They want to reduce costs and improve query performance. Which two actions should they take? (Choose two options that best fit the scenario.)

Medium
270

Your organization is deploying a global e-commerce platform on Google Cloud. The platform uses a microservices architecture running on GKE, and you need to route external HTTP(S) traffic to different services based on URL paths and also provide global load balancing with low latency. You also want to offload SSL/TLS termination and protect against DDoS attacks. Which Google Cloud service should you use?

Hard
271

A company is designing a highly available architecture for a web application using Google Cloud. They need to ensure that the application remains available even if an entire Google Cloud region experiences an outage. Which THREE components should they include in their architecture? (Choose THREE.)

Hard
272

A healthcare company runs a three-tier application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier. All tiers are in the same VPC in project prod-apps. The security team requires that rules be evaluated by source identity rather than IP ranges, and that no instance can reach the database unless explicitly allowed. Which configuration should the architect use?

Hard
273

Match each GCP monitoring/logging tool to its purpose.

Medium
274

A company runs a critical application on Compute Engine instances. They want to automatically patch the operating system on a weekly schedule to meet compliance requirements. Which Google Cloud service should they use?

Medium
275

A financial services company runs a critical application on a managed instance group (MIG) of Compute Engine instances. The application must be highly available and able to survive a zone failure without manual intervention. The company wants to ensure that the MIG automatically recovers from zone failures and maintains capacity. They also want to minimize latency for users across the United States. Which configuration should they use?

Hard
276

A healthcare company runs a patient portal on Cloud Run services in the us-central1 region. The compliance team requires that the portal remain readable during a regional outage and that failover to a secondary region occur without changing the public hostname. The portal's data is stored in Cloud SQL for PostgreSQL. Which design should the architect recommend?

Hard
277

A company wants to deploy a web application behind an HTTPS Load Balancer and only allow authenticated users from their corporate Active Directory. Which two services should they use together? (Choose two.)

Medium
278

A company is migrating its on-premises data center to Google Cloud. They need a dedicated, low-latency, high-bandwidth connection between their on-premises network and VPC. They anticipate consistent traffic above 10 Gbps. Which connectivity option should they choose?

Medium
279

A retail company is planning to migrate its on-premises data warehouse to Google Cloud. They want a fully managed, petabyte-scale, and highly scalable analytics data warehouse that supports ANSI SQL and integrates with their existing BI tools. Which Google Cloud service should they choose?

Easy
280

A data analytics company runs nightly batch jobs using Compute Engine instances. The jobs can tolerate interruptions, and the company wants to minimize costs. What should they do?

Medium
281

Your organization runs a customer-facing web application on a managed instance group of Compute Engine VMs behind an HTTP(S) load balancer. The monthly bill shows that the VMs are running at only 15% average CPU utilization, yet the team insists they need the current number of VMs to handle peak traffic. You want to reduce compute costs without risking performance during traffic spikes. What should you do?

Medium
282

A retail company runs a customer-facing API on GKE Autopilot in a single region. During a quarterly sales event, traffic triples for six hours and then returns to baseline. The SRE team wants to keep the API responsive during the spike, control spend, and avoid manual intervention. They have already configured a Horizontal Pod Autoscaler based on CPU utilization with a target of 60%. Which additional action best addresses the remaining scaling bottleneck?

Hard
283

An organization needs to audit all changes to network firewall rules in a GCP project. Which service should be used to capture these changes?

Hard
284

A security team wants to monitor and audit all changes to IAM policies in a Google Cloud organization. They need to set up real-time alerts when a new binding is added. Which THREE services should they combine to achieve this?

Hard
285

A company runs a batch processing workload on Compute Engine instances in a managed instance group (MIG). The job is CPU-intensive and takes approximately 4 hours to complete. The company wants to reduce costs without sacrificing performance. Which action should they take?

Easy
286

A company wants to connect their on-premises network to Google Cloud with a 99.99% SLA using encrypted tunnels over the public internet. Which connectivity solution should they choose?

Easy
287

A developer needs to secure secrets (API keys, passwords) used in a Cloud Function. What is the recommended approach?

Easy
288

You are the lead cloud architect for a startup that runs a web application on Google Kubernetes Engine (GKE) with a standard (zonal) cluster. The application is deployed with 3 replicas of a stateless frontend service. During a recent incident, a zone outage caused all GKE nodes to become unavailable, leading to application downtime of 45 minutes. You need to redesign the cluster to tolerate a single zone failure with no more than 5 minutes of downtime. Your budget allows for at most a 20% increase in compute costs. Which approach should you take?

Easy
289

A financial services company is migrating a sensitive customer data application to Google Cloud. The application runs on Compute Engine VMs in a VPC. The security team requires that all data at rest in Cloud Storage and BigQuery must be encrypted with customer-managed encryption keys (CMEK). Additionally, the keys must be stored in a different project than the data, and access to the keys must be audited. The operations team has set up a CMEK key in Cloud KMS in a separate project, assigned the Cloud KMS CryptoKey Encrypter/Decrypter role to the data project's Compute Engine service account, and enabled Cloud Storage and BigQuery to use CMEK. However, when the application tries to read from Cloud Storage, it fails with 'Access Denied.' The Cloud KMS key is in project 'kms-proj' and the data is in project 'data-proj'. What is the most likely cause?

Easy
290

A global SaaS company wants to reduce the latency of its API for users in Asia, Europe, and North America. The API is stateless and runs on GKE in a single region. The company wants a solution that improves latency for all users without changing the application code. Which approach should the architect recommend?

Hard
291

A financial services company must comply with PCI DSS. They use Cloud SQL for MySQL for transaction processing. They need to ensure that all data at rest is encrypted with keys generated and stored in a Hardware Security Module (HSM) and that key rotation occurs every 90 days. Which configuration should they use?

Hard
292

A retail company is designing a new order-processing system on Google Cloud. The system must expose a REST API that is reachable from the public internet over a custom hostname, must terminate TLS at the edge, and must route requests to different backend services based on URL path prefixes such as /orders and /inventory. The platform team wants a fully managed, globally distributed solution that scales automatically and does not require managing reverse-proxy VMs. Which Google Cloud component should they place in front of the backends?

Medium
293

A healthcare analytics team must run a stateless containerized API on Google Cloud. The platform must scale to zero when there is no traffic, expose an HTTPS endpoint with a managed certificate, and require no cluster or node management by the team. The architect is choosing among Google Cloud container platforms. Which two characteristics make Cloud Run the appropriate choice here? (Choose two.)

Medium
294

A company runs a web application on App Engine Standard environment. The application experiences downtime during deployments due to traffic shifting. Which two strategies should they implement to improve reliability? (Choose two.)

Hard
295

A company wants to centrally manage firewall rules for all projects in an organization using hierarchical firewall policies. Which three resources can be used in conjunction with hierarchical firewall policies? (Choose three.)

Hard
296

A startup is migrating a monolithic application to Google Cloud. They want to minimize operational overhead and auto-scale based on HTTP request load. Which compute solution should they choose?

Easy
297

A retail company is designing a Google Cloud landing zone for a regulated workload. They must ensure that encryption keys for Cloud Storage and BigQuery are generated and stored outside Google's infrastructure, with the ability to revoke access immediately. They also must retain detailed records of who accessed the data and when, for seven years. Which TWO configurations should the architect include? (Choose two.)

Medium
298

Match each GCP compute service to its characteristic.

Medium
299

Match each GCP migration term to its description.

Medium
300

A company is deploying a new application on Compute Engine. They need to ensure that the application can automatically recover from a zone failure. What is the best approach?

Medium
301

A company is performing a TCO analysis to compare on-premises costs with Google Cloud. Which cost should they include as a hidden operational cost on-premises?

Medium
302

Which THREE are best practices for designing a highly available application on Compute Engine?

Hard
303

You are the architect for a company that runs a three-tier web application on Compute Engine. The CTO wants to reduce the monthly cloud bill without impacting performance or availability. You review the billing export in BigQuery and notice that the VMs are sized for peak load, but CPU utilization rarely exceeds 20% on weekdays and 5% on weekends. The application is stateless and uses an external Cloud SQL database. Which cost optimization strategy should you implement first?

Medium
304

Your organization is adopting a multi-cloud strategy and wants to ensure consistent security policies across Google Cloud and another cloud provider. You need to centrally manage and enforce security policies, such as preventing public access to storage buckets, across both environments. What should you do?

Medium
305

Drag and drop the steps to recover a Cloud SQL instance from a backup into the correct order.

Medium
306

An organization wants to reduce costs for a batch data processing job that runs nightly and is resilient to interruptions. The job can be restarted from checkpoints. Which Compute Engine VM pricing model should be used?

Easy
307

A startup deploys a containerized web application on Cloud Run. They want to release a new revision to a small percentage of users before promoting it to all traffic, and they need the ability to roll back instantly if errors increase. Which Cloud Run feature should they use?

Easy
308

A company is deploying a multi-tier web application on Google Cloud. The application must comply with PCI DSS. Which combination of Google Cloud services should be used to restrict access to the database tier to only the application tier, while also encrypting data at rest and in transit?

Medium
309

A company is migrating a legacy on-premises application to Google Cloud. The application has strict low-latency requirements between its components and requires stateful TCP sessions. Which TWO design decisions should the architect recommend?

Hard
310

A healthcare analytics company is designing a BigQuery-based data warehouse that ingests patient records from multiple hospitals. Regulatory requirements mandate that queries never move data across regional boundaries and that only authorized analysts can access patient-identifiable columns. The architects want to enforce these controls at the platform level rather than relying on application code. Which combination of Google Cloud features should they design into the solution?

Hard
311

A startup wants to deploy a stateless containerized API that must scale automatically from zero and be billed only when requests are processed. The team has no Kubernetes expertise and wants minimal operational overhead. Which Google Cloud service should the architect recommend?

Easy
312

A company is migrating its on-premises workloads to Google Cloud. They have strict compliance requirements that all data at rest must be encrypted with customer-managed encryption keys (CMEK). Which Google Cloud service should they use to manage the lifecycle of these keys?

Medium
313

A financial services company runs a regulated trading platform in a single Google Cloud region. Regulators require that the platform survive the loss of an entire region with a recovery point objective of zero and a recovery time objective of under one minute. The database is Cloud Spanner, and the application tier runs on Google Kubernetes Engine. Which design should the architect choose?

Hard
314

A company is migrating an on-premises PostgreSQL database (5 TB) to Cloud SQL. They need minimal downtime and automated schema conversion if needed. Which GCP service should they use?

Medium
315

An engineer wants to migrate an on-premises MySQL database (5.6) to Cloud SQL for MySQL with minimal downtime. Which service should they use?

Easy
316

A company stores backup data in Cloud Storage. They observe high egress costs when clients download backups. Additionally, they must retain backups for 7 years for compliance. Which optimization should they implement first?

Medium
317

A company is migrating a monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single Compute Engine instance and stores session state in local memory. The migration must support horizontal scaling and high availability. What should the company do to manage session state in the new architecture?

Medium
318

You are designing a multi-region deployment for a critical application on GKE. The application must withstand a regional outage and automatically redirect traffic to the healthy region. Which THREE components must be configured? (Choose 3)

Hard
319

A DevOps team uses Cloud Build to deploy Docker images to GKE. They want to ensure that only images that have passed a vulnerability scan and been signed by a trusted authority can be deployed. Which service should they integrate with Cloud Build and GKE?

Medium
320

A company uses Cloud KMS to encrypt sensitive data. They need to ensure that encryption key usage is audited and that keys are rotated automatically every 30 days. Which two actions should they take? (Choose two.)

Hard
321

Refer to the exhibit. A Cloud Storage bucket has this IAM policy. What security recommendation should be made?

Medium
322

Which TWO statements are true about Google Cloud VPC networks? (Select exactly 2.)

Medium
323

A small startup wants to deploy a containerized web application that scales automatically and only charges for resources used. They have limited operational experience. Which compute solution should they choose?

Easy
324

The exhibit shows a managed instance group configuration. What is the primary purpose of the 'autoHealingPolicies' section?

Hard
325

A company is migrating a legacy monolithic application to Google Cloud. They want to minimise changes while taking advantage of cloud benefits. Which TWO migration strategies are most appropriate? (Choose TWO.)

Medium
326

A retail company runs its e-commerce checkout service on a single Compute Engine instance in us-central1. The service must survive a zonal outage with minimal data loss and automatic failover, but the operations team is small and does not want to manage replication or failover scripts themselves. Which design should the architect recommend?

Medium
327

A healthcare company must store patient records on Google Cloud. Regulatory requirements mandate that the data encryption keys be generated and stored outside Google Cloud, that the company control key rotation, and that access to the data be denied if the external key is unavailable. The data will be stored in Cloud Storage and BigQuery. Which approach should the architect recommend?

Hard
328

Your company has a Service Level Objective (SLO) of 99.9% availability for a web application running on Google Cloud. You want to create an alert that notifies the on-call team when the error budget is being consumed too quickly. Which Google Cloud service should you use?

Easy
329

A company uses Cloud Armor to protect an HTTPS Load Balancer. They want to allow traffic only from users who have passed a reCAPTCHA challenge. Cloud Armor supports which feature for this?

Hard
330

A financial services company needs a globally distributed relational database that supports strong consistency across regions, with multi-region writes and sub-10ms latency for most queries. The database must also support SQL and ACID transactions. Which database should they choose?

Hard
331

A financial services firm is designing a new payment-processing platform on Google Cloud. Regulatory requirements mandate that data never leaves the European Union, that encryption keys are generated and stored on hardware the firm controls inside its own data center, and that the firm can revoke key access instantly. The security team wants to use Cloud KMS but is unsure it meets all three requirements. Which combination of services should the architect recommend?

Hard
332

A financial services company is designing a new application on Google Cloud. The application must comply with PCI DSS and internal policies that require strict separation of duties and least privilege. The security team wants to ensure that developers cannot modify production resources, but they need to deploy code frequently. Which approach should the cloud architect recommend to meet these requirements while supporting continuous deployment?

Hard
333

Refer to the exhibit. The output is from `gcloud compute instances describe instance-1 --format=json`. What can you conclude from this output?

Easy
334

A healthcare company stores sensitive patient data in Cloud Storage buckets. The company must ensure that data is encrypted at rest with keys that are automatically rotated every 90 days and that the keys are managed by the company itself, not by Google. The company also needs to maintain full control over key lifecycle and access policies. Which encryption option should the architect recommend?

Hard
335

A company uses Cloud Composer to manage Apache Airflow workflows. They want to optimize costs. Which practice is most effective?

Medium
336

A company runs batch analytics workloads each night on Compute Engine VMs. The workloads are fault-tolerant and can be interrupted. The finance team wants to reduce compute costs. Which Compute Engine pricing model should they use?

Medium
337

Which TWO are best practices when designing a VPC network for a multi-tier application in Google Cloud?

Medium
338

An organization wants to ensure that only container images signed by an authorized CI/CD pipeline can be deployed to their GKE clusters. Which GCP service should they use?

Easy
339

A company wants to set up monitoring and alerting for their application running on GKE. They need to receive alerts via email and also trigger an automated remediation workflow. Which TWO components should they use? (Choose two.)

Medium
340

A startup is deploying a new web application on Google Cloud. They want to use a fully managed, serverless platform that automatically scales and requires no infrastructure management. The application is containerized and listens on HTTP. Which Google Cloud service should they use?

Easy
341

A financial services company runs a payment API on Compute Engine behind an internal passthrough Network Load Balancer. The compliance team requires that all administrative actions on the project be attributable to a named human, that production changes be reviewed before taking effect, and that no single engineer can delete the production database. Which combination of Google Cloud controls should the cloud architect implement?

Hard
342

A healthcare company is deploying a new patient portal on Google Cloud. The portal must be accessible globally with low latency, must survive a single region failure, and must use a single anycast IP address. The backend runs on managed instance groups in two regions. Which Google Cloud product should the architect use to expose the service?

Medium
343

A logistics company runs a latency-sensitive inventory service on Compute Engine in us-central1. The service writes to a Cloud SQL for MySQL instance and reads from a Memorystore for Redis cache. The architect must design for a zone failure in us-central1 with minimal data loss and automatic failover, without changing the application's connection strings. Which design should the architect choose?

Medium
344

You are designing a disaster recovery plan for a critical application running on GKE. You need to back up the cluster's state and application data. Which TWO services should you use together? (Choose 2)

Medium
345

A financial services firm must design a data residency solution. Regulators require that customer personal data never leaves the country of origin, but the firm wants to use a single centralized analytics project for aggregated, non-personal reporting. Which Google Cloud architecture best satisfies both requirements?

Hard
346

A developer notices that web-server-1 is preemptible. They want to ensure their application remains available even if this instance is terminated. What should they do?

Medium
347

A company needs to ensure that all data stored in Cloud Storage is encrypted at rest with keys that they control and can rotate on demand. They also need to maintain an audit trail of key usage. Which Google Cloud service should they use?

Easy
348

A company wants to migrate a large on-premises relational database to Cloud SQL for PostgreSQL with minimal downtime. They need to ensure data consistency during the migration. Which THREE steps should they take?

Medium
349

A company runs a stateful workload on Compute Engine with regional persistent disks (PD). They need to implement a disaster recovery (DR) plan with a Recovery Point Objective (RPO) of less than 1 hour and Recovery Time Objective (RTO) of less than 4 hours. Which THREE steps should they include in their DR plan? (Choose three.)

Medium
350

A startup wants to grant a new employee read-only access to view all Compute Engine instances in a project. What is the minimum IAM role they should assign?

Easy
351

An organization requires that only container images signed by a trusted authority can be deployed on Google Kubernetes Engine (GKE). Which Google Cloud service should they implement?

Easy
352

An organization uses Cloud Functions (2nd gen) for event-driven processing. They notice that some functions fail with 'memory limit exceeded' errors during peak load. The function processes messages from Pub/Sub and writes to Firestore. What should they do to improve reliability without sacrificing throughput?

Hard
353

A healthcare organization is storing sensitive patient data in Cloud Storage. They need to ensure that all objects are encrypted with a key managed by their on-premises HSM. Which encryption approach should they use?

Hard
354

A company is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that each microservice can only communicate with specific other microservices, and they need to enforce this at the network level. They also want to minimize operational overhead. Which approach should they use?

Hard
355

A media company stores video files in Cloud Storage for streaming. Infrequently accessed videos older than 90 days are currently in Standard storage. To reduce costs, they want to automatically move these files to a lower-cost storage class and delete them after 3 years. Which configuration should they use?

Medium
356

A company uses Cloud Spanner for a global financial application. They experience increased latency and transaction aborts during peak hours. Which measure should they take first to improve reliability?

Easy
357

A developer wants to monitor a custom application metric from their application running on GKE. What should they use?

Easy
358

Your company plans to connect an on-premises data center to Google Cloud with a Dedicated Interconnect. You need to ensure high availability for the connection. What is the minimum configuration required to meet a 99.99% SLA for Dedicated Interconnect?

Medium
359

Which TWO of the following are benefits of using a VPC Service Controls perimeter?

Easy
360

You are deploying a new version of a microservices application to a GKE cluster. The deployment must be released to a small subset of users first, and if errors occur, traffic must automatically revert to the previous version. You also need to monitor the error rate and latency of the new version. Which approach should you use?

Medium
361

A company wants to restrict network access to Cloud SQL instances such that only applications running in a specific VPC can connect. Which GCP feature should they use?

Medium
362

Which TWO options are valid ways to connect an on-premises network to a VPC in Google Cloud? (Choose two.)

Medium
363

A company wants to connect their on-premises data center to Google Cloud with a dedicated private connection that provides 99.99% availability and supports up to 100 Gbps bandwidth. They have a colocation facility near a Google Cloud region. Which connectivity option should they choose?

Medium
364

A company runs a global SaaS application on Google Cloud using Cloud Spanner. They need to ensure disaster recovery with a Recovery Time Objective (RTO) of less than 5 seconds and a Recovery Point Objective (RPO) of zero. Which configuration should they use?

Hard
365

An organization is planning to move 500 TB of archival data from on-premises to Cloud Storage. The data is not frequently accessed, and the network bandwidth is limited to 100 Mbps. What is the most efficient migration approach?

Easy
366

A company migrated their on-premises database to Cloud SQL and now experiences high latency for read-heavy workloads. How can they optimize performance?

Medium
367

Your company is using Cloud Storage to store sensitive customer data. The security team requires that all objects be encrypted with a customer-managed encryption key (CMEK) and that the key be automatically rotated every 90 days. You need to implement this without changing the application code. You have created a Cloud KMS key ring and a key with rotation period set to 90 days. What additional configuration is required?

Medium
368

The exhibit shows a command to create a Compute Engine instance. The instance is intended to run a web server that needs to access Cloud Storage buckets using its service account. However, the web server fails to read from a storage bucket. What is the most likely cause?

Hard
369

A healthcare company runs a critical patient portal on Google Kubernetes Engine. The security team requires that all container images be scanned for vulnerabilities before deployment, that only images from a trusted registry be admitted to the cluster, and that any attempt to deploy an untrusted image be blocked and logged. Which Google Cloud feature should the cloud architect implement to enforce these admission requirements?

Hard
370

A company uses Cloud Logging to capture application logs. They need to alert when the number of errors exceeds 100 in a 5-minute window. Which type of alert should they create?

Easy
371

A media company stores millions of video master files in a Cloud Storage bucket in the us-central1 region. Files are written once, accessed frequently for the first 30 days during editing and publishing, and then almost never accessed again, though they must remain retrievable for seven years. The company wants to minimize storage cost without changing the objects' names or the way applications read them. Which approach should the architect recommend?

Easy
372

A company runs a batch processing job that runs daily and can handle interruptions. The job runs on a single Compute Engine instance. Which machine configuration is the most cost-effective?

Easy
373

A multinational enterprise is designing its Google Cloud resource hierarchy. They want to enforce centrally managed policies, delegate administration to regional business units, and isolate billing. Which two design choices should the architects make? (Choose two.)

Medium
374

A company needs to ensure that only applications running in a specific GKE namespace can access a Cloud Storage bucket. Which approach should they use?

Medium
375

A healthcare company is designing a new patient portal on Google Cloud. Regulatory requirements mandate that all data at rest be encrypted with keys the company controls and can rotate on its own schedule, and that the keys never leave a hardware security module (HSM). The security team also wants to retain the ability to revoke Google's access to the data if the external key becomes unavailable. Which key management design should you recommend?

Hard
376

A company has a Cloud Run service that processes images uploaded by users. The service reads the images from a Cloud Storage bucket and writes processed images to another bucket. The team recently updated the service to use a custom service account named 'image-processor-sa' with minimal permissions. After the update, the service fails with permission errors when trying to read from the source bucket. The team verified that the service account has the Storage Object Viewer role on the source bucket and Storage Object Creator role on the destination bucket. What should the architect do to resolve the issue?

Easy
377

A data scientist needs read-only access to a Cloud Storage bucket containing training data. What is the least privileged IAM role to grant at the bucket level?

Easy
378

A company is migrating a monolithic application to microservices on Google Cloud. They need to manage service-to-service authentication and authorization. Which service should they use?

Hard
379

Your company runs a customer-facing API on Cloud Run with a concurrency setting of 80. The API calls a backend Cloud Function that performs a heavy computation (2–5 seconds). During peak hours, the API experiences increased latency and some requests time out after 60 seconds. Monitoring shows that the Cloud Run max instances is set to 100, and the Cloud Function max instances is set to 10. The timeout for Cloud Run is set to 300 seconds. The Cloud Function's timeout is set to 540 seconds. You need to reduce end-to-end latency and prevent timeouts while minimizing cost. Which action is most effective?

Medium
380

A financial services company must store customer data in a GCP region that is certified for FedRAMP High. They also need to ensure that only authorized personnel can access the data, and that access logs are kept for 10 years. Which combination of services meets these requirements?

Hard
381

A company is deploying a new application on Compute Engine and wants to automate the installation of a custom agent on every newly created VM in a specific project. Which Google Cloud service should they use?

Medium
382

A company is deploying a web application on Compute Engine. They want to ensure that only authenticated users can access the application. Which Google Cloud service should they use?

Easy
383

A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that pods can only pull container images from a private Artifact Registry repository and that images are scanned for vulnerabilities before deployment. They also want to prevent pods from being scheduled if they use images from public registries. What should they do?

Medium
384

A healthcare company runs a critical application on Google Kubernetes Engine (GKE) that processes patient data. The compliance team requires that all container images be scanned for vulnerabilities before deployment, and that only images from a trusted registry be allowed. The security team wants to enforce this policy across all clusters in the organization. They also need to audit any attempts to deploy untrusted images. Which combination of Google Cloud services should they use?

Hard
385

An application running on GKE Autopilot is experiencing intermittent failures due to resource limits. The team wants to ensure that the application always has enough CPU and memory without manual node management. What should they do?

Hard
386

Which Google Cloud service allows you to create alerting policies based on log entries?

Easy
387

A healthcare company is planning to store sensitive patient records in Cloud Storage. They need to ensure that the data is encrypted at rest with keys that they control and can rotate on demand. They also want to maintain an audit trail of key usage. Which Google Cloud service should they use?

Easy
388

A company has a Cloud SQL for PostgreSQL instance that experiences high connection overhead. Developers frequently open and close connections. Which solution reduces connection overhead without code changes?

Easy
389

A company has a VPC Service Perimeter that protects a project containing BigQuery datasets. They want to allow an external customer's BigQuery job to query data across the perimeter boundary using a private connection. Which configuration is required?

Hard
390

A developer wants to store a database password securely and have it automatically rotated every 30 days. The password is used by a Compute Engine instance. Which Google Cloud service should they use?

Medium
391

An engineer needs to create a custom dashboard in Cloud Monitoring to track the 99th percentile latency of their application over the last 7 days. Which type of metric should they use?

Easy
392

A financial services company runs a critical PostgreSQL database on Cloud SQL. They need to ensure automatic failover to a replica in another zone within the same region with minimal data loss. What configuration should they choose?

Hard
393

When creating a Compute Engine instance from a custom image stored in another project, which gcloud flag is required?

Easy
394

A developer ran the above command to create a health check for a backend service. Which of the following should they do to resolve the error?

Medium
395

A company wants to use BigQuery with a predictable monthly cost, regardless of query volume. They have a steady state of around 500 concurrent slots. Which pricing model should they choose?

Medium
396

Your company runs a data pipeline on Google Cloud using Cloud Dataflow for streaming processing from Pub/Sub to BigQuery. The pipeline writes to a BigQuery table partitioned by day. The data is used for real-time dashboards. Recently, a spike in traffic caused the Dataflow pipeline to fall behind, and the dashboard displayed stale data. You need to design the pipeline to handle traffic spikes without data loss or long delays. The pipeline must be cost-efficient and use defaults where possible. Which solution should you implement?

Hard
397

A healthcare analytics company ingests HL7 messages into Pub/Sub and processes them with a Dataflow streaming pipeline that writes results to BigQuery. During a regional outage, the pipeline stopped and the team discovered that unacknowledged messages were lost after the retention window expired. The company needs a design where a single-region failure does not cause message loss and the pipeline can resume with minimal manual intervention. What should the architect recommend?

Hard
398

A company uses Cloud SQL for MySQL for its transactional database. They need to ensure automatic failover in case of a zonal outage with minimal data loss. What configuration should they use?

Medium
399

A company runs a stateful application on Google Kubernetes Engine (GKE) that requires persistent storage and low-latency access across multiple zones. The application needs to perform well even during zonal failures. Which storage solution should they use?

Hard
400

A healthcare analytics firm processes patient records in a Dataflow streaming pipeline that writes enriched events to BigQuery. The pipeline currently uses a fixed number of workers sized for peak load, and utilization is low for most of the day. The team wants the pipeline to scale with incoming volume while keeping late-arriving events correct and bounded in cost. What should they do?

Hard
401

A company needs to retain object versions in Cloud Storage for 90 days to protect against accidental deletion or modification. After 90 days, versions should be deleted. What feature should they enable?

Easy
402

An organization wants to use VPC Service Controls to protect a Cloud Storage bucket and a BigQuery dataset from data exfiltration. They want to allow access from a specific on-premises network via a Cloud VPN. Which TWO components are required? (Choose 2)

Medium
403

A financial services company needs to ensure that all outbound traffic from its Compute Engine instances to the internet goes through a dedicated IP address for allowlisting by a partner. The instances are in a private subnet with no external IP addresses. The company wants to minimize management overhead and avoid single points of failure. Which solution should the architect implement?

Hard
404

A healthcare company is migrating a legacy on-premises Oracle database to Google Cloud. The database is used for a patient records application that requires strong consistency, ACID transactions, and a relational schema with complex joins. The company wants a fully managed, highly available relational database service that minimizes administrative overhead while supporting their existing SQL workloads. Which Google Cloud service should they choose?

Medium
405

A company wants to provision multiple similar environments (dev, test, prod) with consistent networking configurations. Which approach is a best practice for infrastructure as code?

Easy
406

A financial services firm runs a regulated workload in a Google Cloud organization. Compliance requires that no resource in any project can be created outside a defined set of approved regions, and that violations are blocked before resource creation rather than reported afterward. The organization has many projects and new projects are created frequently. Which approach should the architect implement?

Hard
407

A financial services company runs a latency-sensitive trading application on GKE. The platform team must guarantee that the application can be recovered within a 15-minute recovery time objective (RTO) and a 5-minute recovery point objective (RPO) after a regional failure. They use a multi-region Cloud Storage bucket for configuration and a regional GKE cluster. Which additional design element is required to meet both objectives?

Hard
408

A company has a Cloud SQL for PostgreSQL instance in a single zone. To achieve high availability, they want to ensure automatic failover with zero data loss and minimal downtime. Which configuration should they use?

Medium
409

A data engineer needs to automatically detect and redact sensitive data such as credit card numbers from text files uploaded to Cloud Storage before the data is loaded into BigQuery. Which GCP service should be used?

Hard
410

An organization requires that all Compute Engine instances in a project must have a specific tag for firewall rule compliance. How can they enforce this?

Hard
411

A healthcare company stores patient records in Cloud Storage buckets across multiple projects. An audit reveals that several buckets containing protected health information are publicly accessible. The security team wants a centralized, automated way to detect and remediate public access across all current and future projects, with minimal operational effort. Which solution should the architect recommend?

Hard
412

Which Google Cloud service automatically computes the optimal size or tier for underutilized Compute Engine instances and generates recommendations to reduce cost?

Easy
413

An e-commerce platform uses Cloud Spanner in a multi-region configuration. They want to achieve the highest possible availability SLA. Which deployment configuration should they choose?

Hard
414

Your company uses Cloud Monitoring to track the performance of a microservices application. The SRE team wants to define an SLO for the latency of a critical API. They need to measure the proportion of requests that complete within 200 ms over a rolling 30-day window. Which approach should they use to implement this SLO?

Hard
415

Your team uses Cloud SQL for PostgreSQL for an e-commerce application. You want to perform point-in-time recovery (PITR) to recover from a logical error that occurred 10 minutes ago. Which prerequisites are required?

Medium
416

A logistics company runs a latency-sensitive order-tracking service on Compute Engine instances spread across three zones in one region. They need the architecture to survive the loss of an entire zone while keeping inter-instance latency low, and they want automatic failover without manual intervention. Which design should the architects implement?

Hard
417

The exhibit shows the output of a 'gcloud compute instances describe' command for an instance. What is the most likely impact on reliability if the host machine needs maintenance?

Medium
418

A security team needs to detect and redact personally identifiable information (PII) from documents uploaded to Cloud Storage before they are stored. Which GCP service should they use?

Medium
419

A retail company runs a stateless web tier on a managed instance group (MIG) of Compute Engine VMs behind an external Application Load Balancer. Traffic spikes every evening and the operations team currently resizes the MIG manually. They want the group to add and remove VMs automatically based on CPU utilization without changing the instance template. What should the architect configure?

Easy
420

An engineer is troubleshooting a Cloud Build trigger that fails with the error 'PERMISSION_DENIED: Cloud Build service account does not have permission to access Artifact Registry'. The build needs to push a Docker image to Artifact Registry. What is the correct IAM role to assign to the Cloud Build service account?

Hard
421

Which TWO actions are required to allow a private GKE cluster to pull container images from Artifact Registry in the same project?

Medium
422

A company needs to connect their on-premises data center to Google Cloud with a dedicated, low-latency, and highly available connection. They require at least 10 Gbps throughput and want to avoid internet-based VPN. Which connectivity option should they choose?

Medium
423

A company runs a web application on GKE and wants to expose it to the internet using a global HTTP(S) load balancer with Cloud CDN. Which TWO GCP resources are required to configure this setup? (Choose TWO.)

Medium
424

An organization has multiple GCP projects managed by a central operations team. They want to define a common VPC configuration in a host project and allow service projects to use it. Which networking feature should they use?

Medium
425

A team is deploying a stateful application on GKE. They want to ensure that the application's pods are distributed across different zones for high availability and that during cluster upgrades, at least one pod remains available. Which THREE features should they configure?

Medium
426

A financial services company runs a regulated workload on Compute Engine in a single project. Auditors require that all data written to persistent disks, including boot disks, is encrypted with keys the company controls and can revoke on demand, without the company operating its own key management infrastructure. The security lead must choose an encryption approach that satisfies this requirement with the least operational overhead. What should the security lead do?

Medium
427

A company is migrating its on-premises Oracle database to Cloud SQL for PostgreSQL. The database team wants to minimize downtime during migration. Which approach should they use?

Medium
428

A financial services company uses VPC Service Controls to protect their project containing BigQuery datasets and Cloud Storage buckets. They have a perimeter that includes the BigQuery service. Users report that they cannot export data from BigQuery to Cloud Storage using the web console. The export job fails with an access denied error. The team needs to allow exports while maintaining data exfiltration prevention. The users have the necessary IAM permissions (BigQuery Data Editor, Storage Object Admin) on the appropriate resources. What should the architect do?

Hard
429

A healthcare company needs to run a stateful, containerized electronic medical records application that requires a stable network identity and persistent disk storage per replica. The operations team is already fluent with Kubernetes. Which Google Cloud service should they choose?

Easy
430

Which IAM role should be granted to a user who needs to view but not modify resources in a project?

Easy
431

Which THREE factors should be considered when choosing a Google Cloud region for deploying a low-latency application serving global users? (Choose three.)

Hard
432

An organization has a VPC with two subnets: subnet-a (10.0.1.0/24) and subnet-b (10.0.2.0/24). They launched a Compute Engine instance in subnet-a with an internal IP 10.0.1.2 and a public IP. They want the instance to only allow HTTPS traffic from the internet. Which firewall rule should they create?

Hard
433

A developer accidentally deleted a bucket in Cloud Storage. The bucket had object versioning enabled. How can the bucket and its objects be restored?

Easy
434

Match each GCP data processing service to its use case.

Medium
435

A small development team is deploying a stateless containerized API on Google Cloud. They want the simplest possible way to run containers without managing servers or Kubernetes clusters, and they want the service to scale to zero when there is no traffic to minimize cost. The API receives HTTP requests from external clients. Which Google Cloud service should the architect recommend?

Easy
436

A developer needs to store a database password securely and access it from a Cloud Run service. Which Google Cloud service should they use?

Easy
437

A global gaming company deploys a leaderboard service using Cloud Spanner with a single-region configuration. They need a Recovery Point Objective (RPO) of 5 seconds and a Recovery Time Objective (RTO) of 1 minute in the event of a regional outage. What should they do?

Hard
438

A company needs to store secrets such as API keys and database passwords securely and access them from Compute Engine instances. Which service provides secret storage with built-in IAM integration and automatic rotation?

Easy
439

An engineer is designing a Bigtable schema for time-series data consisting of sensor readings. Each sensor emits a reading every second. The access pattern is to retrieve all readings for a specific sensor within a time range. Which row key design will provide the best performance?

Hard
440

An online retailer is deploying a new order-processing system on Google Cloud. The system consists of a regional managed instance group (MIG) of Compute Engine VMs that read from and write to a Cloud SQL for MySQL instance. The database must tolerate the loss of an entire zone within the region with minimal downtime and no manual failover steps, while keeping costs predictable. Which Cloud SQL configuration should the architect recommend?

Medium
441

A company is using Cloud SQL for PostgreSQL and needs to run a one-time heavy analytical query that takes over 30 minutes and uses 100% CPU. The production database is serving user traffic with high QPS. What should the company do to run the query without impacting production?

Medium
442

Your company runs a critical application on Compute Engine instances in a managed instance group across three zones. The application writes logs to local disk. You are asked to improve the reliability of log retention and ensure logs are available in case of instance failure. You have already configured a health check that automatically recreates instances. However, after a recent zonal outage, logs from the affected instances were lost. You need to implement a solution that preserves logs even when instances are terminated. What should you do?

Easy
443

A startup is deploying a new web application on Compute Engine. The architect needs to ensure that the application can automatically recover from a zone failure and that the instances are distributed across multiple zones within a region. The application must also scale automatically based on traffic. Which Compute Engine feature should the architect use?

Easy
444

You want to create a log-based alert in Cloud Logging that triggers when a specific error message appears in application logs. What is the first step?

Easy
445

A company runs a web application on Google Kubernetes Engine (GKE) with Cluster Autoscaler enabled. During a traffic spike, the application becomes slow and some requests timeout. The cluster has sufficient CPU and memory headroom. What is the most likely cause and solution?

Medium
446

Your organization is moving a legacy monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single virtual machine with a local MySQL database. You need to design a cloud-native architecture that improves scalability and reliability. Which two actions should you take? (Choose TWO.)

Medium
447

A company runs a critical application on Compute Engine. The operations team wants to improve the mean time to recovery (MTTR) for incidents. They currently use manual runbooks stored in a wiki. You need to recommend a solution that automates incident response and integrates with existing monitoring. What should you do?

Medium
448

A media company stores millions of small image files in a Cloud Storage bucket in the us-central1 region. Users in Europe and Asia report slow image load times. The company wants to improve read latency globally while keeping write operations in us-central1 for cost and simplicity. Which storage configuration should you recommend?

Hard
449

A multinational retailer must comply with a regulation stating that customer personal data collected in the European Union may not be stored or processed outside the EU, including by support staff. The company uses Google Cloud and wants a platform-level mechanism that enforces this at the data-residency level while still allowing the global analytics team to query aggregated, non-personal results. Which Google Cloud capability should the architect use as the foundation?

Easy
450

A company uses Cloud Armor to protect their HTTP Load Balancer from DDoS attacks. Recently, they experienced a targeted attack that bypassed Cloud Armor's predefined rules. The attack involved a high rate of legitimate-looking requests from a small set of IPs that made the application unresponsive. The team needs to block the attack quickly without affecting legitimate users. What should they do?

Hard
451

A company is deploying a web application on Compute Engine behind a global HTTP(S) load balancer. They want to restrict access to only traffic from specific IP ranges. Which load balancer feature should they use?

Medium
452

A team is using Cloud Build to deploy a microservice to Cloud Run. They want to ensure that only containers built from a specific trusted branch in their source repository are deployed to production. Which Cloud Build feature should they use?

Medium
453

A company wants to restrict access to a Cloud Storage bucket so that only a specific service account can read objects. The bucket contains sensitive data. Which identity and access management (IAM) approach should the architect use?

Easy
454

A developer wants to store and retrieve non-relational data with flexible schema and automatic scaling. Which Google Cloud service should they use?

Easy
455

A media company uses Cloud CDN with an HTTP(S) Load Balancer to serve video content from Cloud Storage. After a month, they notice increased costs due to high cache miss rates. Analysis shows that many requests include a unique query parameter for analytics tracking. What is the most effective way to improve cache hit ratio while preserving analytics data?

Hard
456

A company runs a monolithic application on Compute Engine. They want to modernize by moving to microservices on Google Kubernetes Engine (GKE) to improve deployment frequency and resource utilization. However, they are concerned about the increased operational complexity. Which approach best balances modernization benefits with operational overhead?

Medium
457

A multinational manufacturer is planning its first Google Cloud landing zone. The security team requires that no data be stored outside approved European regions, that all workloads authenticate using short-lived credentials tied to their Google identities, and that network egress to the public internet be centrally inspected and logged. The platform team wants to minimize per-project configuration. Which two design elements should the architect include in the landing zone? (Choose two.)

Hard
458

A company wants to monitor the performance of their microservices deployed on Cloud Run. They need to capture request latencies and error rates, and also trace requests across services. Which TWO services should they use?

Medium
459

A data engineer needs to scan a Cloud Storage bucket for personally identifiable information (PII) and de-identify the data before loading it into BigQuery. Which Google Cloud service should they use?

Medium
460

Refer to the exhibit. A DevOps engineer created this Terraform configuration to deploy a Compute Engine instance. After applying, they notice the instance is not accessible from the internet. What is the most likely cause?

Easy
461

A company needs to store petabytes of time-series IoT sensor data and query it with single-digit millisecond latency at millions of reads per second. The data has a simple key-value structure with timestamps. Which Google Cloud database is MOST appropriate?

Medium
462

A financial services firm is designing the network for a new payment processing platform on Google Cloud. Regulatory rules require that no workload can reach the public internet, that all egress to an on-premises fraud-detection system stay off the public internet, and that Google APIs such as Cloud Storage and BigQuery remain reachable without exposing the workloads. The platform runs on Compute Engine VMs in a single VPC. Which two design elements must the architect include? (Choose two.)

Hard
463

A company wants to implement an event-driven architecture where uploads to a Cloud Storage bucket trigger processing in a serverless function. The function must process each object within a few seconds and handle bursts of thousands of uploads. Which service should they use?

Medium
464

Your organization runs a global e-commerce platform on Google Kubernetes Engine (GKE). The security team requires that all container images deployed to the cluster are scanned for vulnerabilities and that deployments are blocked if critical vulnerabilities are found. They also want to minimize operational overhead. What should you do?

Medium
465

A company wants to connect their on-premises data center to Google Cloud with a dedicated, low-latency, and highly available connection. They need bandwidth of 10 Gbps. Which option should they choose?

Easy
466

A company is migrating an on-premises application to Google Cloud. The application consists of a web front end and a backend that uses a relational database. The company wants to minimize downtime during the migration and ensure that the database remains consistent. They plan to use a phased approach. Which TWO steps should they take to achieve a successful migration? (Choose two.)

Medium
467

A company deploys a web application on Compute Engine behind a Global HTTPS Load Balancer. They need to restrict access to the application based on the client's IP address. Which Google Cloud service should they use?

Medium
468

An engineer needs to troubleshoot a production issue on a Compute Engine instance. They suspect the instance is running out of memory. Which THREE actions should they take to diagnose the problem? (Choose THREE.)

Easy
469

A company runs a web application on Compute Engine behind a Global HTTPS Load Balancer. Users report slow page loads, especially for static assets. The development team wants to cache content closer to users without modifying code. Which GCP service should they enable?

Medium
470

A company uses preemptible VMs for batch processing. They notice that during peak hours, many instances are terminated before finishing their tasks. The operations team observes the output shown in the exhibit. Which action would best improve job completion rates without significantly increasing costs?

Medium
471

A DevOps engineer needs to grant a CI/CD pipeline (running in a different Google Cloud project) the ability to deploy resources into a target project. The pipeline uses a service account. What is the best way to grant this access?

Medium
472

A company runs a latency-sensitive web application on Compute Engine with a managed instance group (MIG) behind an HTTP load balancer. They want to reduce latency for users in Europe and Asia. Which THREE actions should they take?

Medium
473

A company wants to restrict data exfiltration from its Google Cloud projects by preventing resources from copying data to external IP addresses. Which service should they use?

Easy
474

A company wants to encrypt data at rest in Cloud Storage using a key that they generate and manage themselves, not stored in Google Cloud. Which encryption type should they use?

Medium
475

A company is designing a data processing pipeline in Google Cloud that must be HIPAA compliant. Which three security features should they implement? (Choose three.)

Easy
476

A company stores infrequently accessed data in Cloud Storage Standard class. To reduce costs, they want to automatically move objects older than 90 days to a lower-cost storage class. Which approach should they use?

Medium
477

A company uses Assured Workloads to meet FedRAMP compliance. They need to ensure that only authorized personnel can access data access audit logs for their projects. Which IAM role should they grant to the security team?

Hard
478

A company is migrating a legacy monolithic application to Google Cloud. The application currently runs on a single on-premises server and uses a local MySQL database. The company wants to minimize changes to the application code while improving scalability and reliability. Which migration strategy should the architect recommend?

Easy
479

A healthcare company stores PHI in BigQuery. Compliance requires that analysts see masked values for patient names and MRNs, while a small data-engineering group must see unmasked values for pipeline troubleshooting. The policy must be enforced by BigQuery itself, independent of any application code. Which approach should the architect implement?

Hard
480

An organization wants to enforce that all Compute Engine VMs are created with specific disk encryption keys. Which policy mechanism should they use?

Hard
481

An organization uses Cloud SQL for MySQL in a production environment. They need to ensure high availability with automatic failover in case of a zonal failure. Which configuration should they use?

Hard
482

A company wants to enforce that all API calls to GCP services from outside their corporate network come through a specific Cloud VPN tunnel. Which GCP service can enforce this policy?

Medium
483

A team is designing a disaster recovery plan for a critical application. They need to ensure RPO of less than 1 hour and RTO of less than 4 hours. The application runs on Compute Engine with persistent disks and uses Cloud SQL for MySQL. Which THREE actions should they take? (Choose 3.)

Medium
484

A company is migrating an on-premises PostgreSQL database to Cloud SQL with minimal downtime. The database is 1 TB and the network link has 500 Mbps bandwidth. Which migration approach is most appropriate?

Medium
485

A multinational corporation needs to ensure that data stored in Cloud Storage buckets in their Google Cloud organization cannot be accessed from outside their corporate network, even if IAM policies are misconfigured. They want to enforce this at the organization level with minimal administrative overhead. What should they do?

Hard
486

An IoT company ingests telemetry from 40,000 devices spread across three continents. The architecture team wants a single logical endpoint that automatically routes each device's writes to the nearest healthy Google Cloud region, and they want to avoid managing per-region DNS records or load-balancer IPs. Which design should the architect choose?

Hard
487

A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that the application can automatically scale based on custom metrics, such as the number of pending requests in a queue. They also want to minimize operational overhead. Which TWO actions should they take? (Choose two.)

Medium
488

A media company stores finished video masters in a Cloud Storage bucket. Legal requires that every object be retained for exactly seven years and that no user, including project owners, be able to delete or overwrite an object before that period ends. Which bucket configuration should the architect apply?

Easy
489

A developer wants to deploy a Cloud Function that is triggered whenever a new object is created in a Cloud Storage bucket. Which trigger type should they choose?

Medium
490

A media company streams video from a global user base. The architect must provision a load balancer that terminates TLS, routes requests by URL path to different backend services, and provides a single global anycast IP address. The backend services run on managed instance groups in three regions. Which Google Cloud load balancer should the architect deploy?

Hard
491

Which TWO services can be used to create a CI/CD pipeline for a containerized application on Google Cloud? (Choose 2)

Medium
492

A logistics company is planning a new order-tracking platform on Google Cloud. The platform must handle sudden, unpredictable spikes from holiday promotions, keep costs low during idle periods, and provide a relational store that scales reads without the team managing replication. The architect is choosing between fully managed services and self-managed alternatives. Which two design choices meet these requirements? (Choose two.)

Medium
493

An engineer needs to list all Compute Engine instances in a project using the command line. Which gcloud command should they use?

Easy
494

A development team wants to automate the process of building container images from their GitHub repository and storing them in Artifact Registry. Which Google Cloud service should they use to create a build trigger that runs on every push to the main branch?

Easy
495

A company is planning to migrate a large on-premises Oracle database (10 TB) to Cloud SQL for PostgreSQL. They need to minimise downtime and ensure data integrity. Which TWO services or tools should they use? (Choose TWO.)

Medium
496

Your company runs a multi-tier web application on Google Kubernetes Engine (GKE). The application consists of a frontend service, a backend API service, and a PostgreSQL database deployed using a StatefulSet with persistent volumes. The backend service exposes a gRPC endpoint. Recently, the team noticed that the backend service experiences intermittent high latency and occasional timeouts. The frontend service is stateless and scales well. The backend service is CPU-bound. The database is not the bottleneck. The cluster has three nodes of type n1-standard-4. The backend service is deployed with 10 replicas, each requesting 1 CPU and 2 Gi memory. Node utilization is around 70% CPU. The team suspects the network is the issue. However, after reviewing the GKE monitoring dashboard, they see that the network bytes sent/received per second for the backend pods is well below the node's network bandwidth limit. The latency spikes seem correlated with periods of high CPU throttling on the backend pods. The backend service's gRPC requests are small (under 1 KB), and the responses are also small. The team has already optimized the application code. What should the team do to reduce latency?

Hard
497

A company runs batch machine learning training jobs that can be interrupted. They want to reduce compute costs. Which Compute Engine VM pricing model is MOST cost-effective?

Easy
498

A healthcare company is designing a new patient-records API on Google Cloud. The API must serve read-heavy traffic globally with low latency, tolerate the failure of an entire region, and keep operational overhead low. The data is stored in Cloud Spanner. Which design should the architect recommend?

Hard
499

An application uses Cloud Bigtable and experiences high latency for reads. The row key is a timestamp prefix followed by a random ID. Queries often scan a range of timestamps for a specific ID. What design change would MOST improve read performance?

Medium
500

A company is migrating on-premises workloads to Google Cloud. They have a critical application that requires consistent low-latency access to a database, with read replicas in multiple regions for disaster recovery. The application is expected to grow by 10x over the next year. Which database service and configuration should the architect choose to meet these requirements?

Medium
501

A company wants to automatically apply security patches to Compute Engine instances running Windows Server. They need a solution that can schedule patch installations and report compliance. Which service should they use?

Easy
502

A healthcare analytics company must build a data platform on Google Cloud that stores patient records subject to strict privacy rules. The design must ensure that analysts can query aggregated data without being able to read individual patient identifiers, and that all access to the raw records is logged for audit. Which two design choices should the architect include? (Choose two.)

Medium
503

A government agency must retain Cloud Storage objects for seven years in a bucket that also serves live traffic. Regulators require that no user, including project owners, can delete or shorten retention during that period. The architect needs a control that satisfies this. Which should the architect configure?

Hard
504

A team is adopting a DevOps model and wants to reduce the risk of configuration drift between environments. They deploy the same application to development, staging, and production projects on Google Cloud. Which practice should they adopt to ensure consistent, repeatable deployments across all environments?

Easy
505

A company wants to ensure that their development teams follow best practices for cost optimization. They want to implement a process that reviews architecture decisions before deployment and provides recommendations. Which Google Cloud tool should they use to get automated cost recommendations for their existing resources?

Easy
506

A company is migrating to Google Cloud and needs to implement a least-privilege access model. Which THREE Google Cloud services or features support this goal? (Choose three.)

Medium
507

A media startup wants to give its data science team isolated environments for experimentation while keeping billing and user management under one organization. Each environment must have its own quotas and IAM boundary, and the team wants to add or remove environments quickly without renegotiating billing. Which Google Cloud resource hierarchy construct should the architect use for each environment?

Easy
508

An application uses Cloud SQL (PostgreSQL) and experiences high connection overhead, often exhausting the max connections limit. The team wants to maintain a pool of persistent connections without modifying application code. Which solution should they implement?

Hard
509

A company runs a batch analytics job every hour on BigQuery. The job processes terabytes of data and the results are stored in Cloud Storage. The job must complete within 30 minutes. Which TWO actions can reduce query execution time? (Choose 2)

Hard
510

Your team has deployed a microservices application on Google Kubernetes Engine (GKE) with multiple services communicating via internal ClusterIP services. You notice that some requests between services are failing intermittently with 'connection refused' errors. The services are defined with readiness probes. What is the most likely cause?

Medium
511

A startup is developing a real-time analytics dashboard that ingests data from IoT devices. The data volume is unpredictable but can spike to millions of events per second. The dashboard must display near real-time aggregations with sub-second latency. Which Google Cloud architecture should the architect recommend?

Medium
512

A company wants to automate the deployment of their infrastructure on Google Cloud using a declarative approach. They need to manage resources such as VPCs, subnets, and Compute Engine instances in a repeatable and version-controlled manner. They also want to preview changes before applying them. Which tool should they use?

Easy
513

An enterprise is migrating a latency-sensitive trading application from an on-premises data centre to Google Cloud. The application's components exchange hundreds of thousands of small messages per second and require sub-millisecond inter-process communication. The architect must choose a compute and networking design. What should the architect recommend?

Hard
514

Your organization runs a production Cloud SQL for PostgreSQL instance. You need to ensure that if the primary zone fails, the database automatically fails over to a standby with no data loss. Which configuration should you use?

Medium
515

You are designing a solution to store and serve static web content for a global audience. The content consists of HTML, CSS, JavaScript, and images. You need to ensure low latency and high availability. Which Google Cloud service should you use?

Easy
516

A healthcare company runs a regulated patient-portal application on Google Cloud. Auditors require evidence that infrastructure changes are reviewed before they reach production and that production access is limited. The platform team currently applies Terraform changes directly from engineer laptops using personal credentials. Which two practices should the team adopt to satisfy the auditors while keeping delivery efficient? (Choose two.)

Medium
517

Your company runs a stateful application on GKE that stores data in persistent volumes backed by Compute Engine persistent disks. You need to back up the application data and the Kubernetes resource configurations (deployments, services, etc.) for disaster recovery. Which tool should you use?

Medium
518

A healthcare analytics company ingests continuous streams of device telemetry that must be processed in near real time, enriched with reference data from a Cloud SQL for MySQL instance, and written into BigQuery for analyst queries. The team wants minimal operational overhead and wants to use managed Google Cloud services. Which combination should the architect select?

Medium
519

A healthcare company runs a multi-tenant SaaS platform on Google Cloud. Each tenant has a dedicated folder inside a single organization, with projects for each environment. A recent audit found that a compromised service account in one tenant's dev project could enumerate and read Cloud Storage buckets belonging to other tenants because the service account had been granted roles/storage.admin at the organization level by mistake. The security team wants a preventive control that blocks any future IAM binding that grants a role to a principal at a scope broader than a single project, unless the principal is part of a small break-glass group. They also want the control to apply automatically to all new projects. What should the architect implement?

Hard
520

A company wants to implement a disaster recovery (DR) strategy for their Cloud SQL for MySQL databases. They need to be able to recover to a specific point in time (within seconds) in case of accidental data deletion. Which TWO actions should they take? (Choose TWO.)

Medium
521

Your company uses Cloud Spanner in a multi-region configuration to achieve 99.999% availability. You need to understand the impact of a regional failure on read and write availability. Which statement is correct?

Hard
522

A retail company runs its order-processing system on Google Kubernetes Engine (GKE). The operations team wants to improve the reliability and cost efficiency of the cluster. They observe that several workloads have no resource requests or limits set, and some nodes are consistently underutilised while others are overcommitted. Which two actions should the architect recommend to address these issues? (Choose two.)

Medium
523

A financial services company runs a latency-sensitive trading application on Compute Engine. The operations team needs to detect performance regressions and correlate them with recent deployments without instrumenting application code. They want to use Cloud Monitoring and Cloud Logging features that work automatically for Compute Engine VMs. (Choose two.)

Hard
524

A finance company needs to ensure that all compute instances in their VPC can only communicate with Google APIs (e.g., Cloud Storage) over internal IPs. Additionally, instances without external IPs should be able to access the internet for updates. Which TWO configurations should they implement?

Hard
525

A company requires a globally distributed relational database with strong consistency across regions and automatic replication. They need to support SQL queries and have a write throughput of 100,000 writes per second. Which Google Cloud database meets these requirements?

Hard
526

A team wants to deploy a microservice on Cloud Run that needs to access a Cloud Memorystore for Redis instance in the same region. The Redis instance is in a VPC network. Which configuration is required for Cloud Run to reach the Redis instance?

Medium
527

Your organization has a policy that all Compute Engine instances must have specific labels (env, team, cost-center) applied. You want to enforce this automatically when instances are created. What should you do?

Medium
528

A company runs a three-tier web application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier on TCP port 8080. The company wants to enforce these requirements at the network level with minimal administrative overhead and without relying on instance-level firewall software. What should they do?

Medium
529

An enterprise is planning to migrate 200 on-premises VMs to Google Cloud. The CIO wants to ensure that the migration aligns with the business goal of reducing IT operational overhead by 30% while maintaining application performance. The team has already completed a technical assessment of the VMs. Which additional step should the cloud architect take to ensure the migration plan is aligned with the stated business goal?

Medium
530

A healthcare analytics company runs a stateless API on a regional managed instance group behind an external Application Load Balancer. The SRE team wants to improve reliability and reduce customer-visible errors during zonal and instance failures. (Choose two.)

Hard
531

You need to automatically roll back a GKE deployment if a new version causes a spike in 5xx errors. The deployment uses a canary strategy with Istio traffic splitting. What should you do?

Easy
532

Drag and drop the steps to set up a shared VPC in Google Cloud for a multi-project environment into the correct order.

Medium
533

Refer to the exhibit. An application running on a GCE instance (ID: 1234567890) is unable to connect to a database at 10.0.0.1:5432. The logs show repeated 'Connection refused' errors. What is the most likely cause?

Medium
534

A company is migrating to Google Cloud and needs to connect their on-premises network to a VPC. They require high bandwidth and a reliable connection with a Service Level Agreement (SLA). Which solution should they choose?

Easy
535

A healthcare organization is designing a Google Cloud environment to comply with HIPAA. They need to ensure that all access to sensitive data is logged and that only authorized personnel can access it. They plan to use Cloud Audit Logs and IAM. Which two configurations should they implement? (Choose two.)

Hard
536

Match each GCP storage service to its typical use case.

Medium
537

A company wants to use Customer-Managed Encryption Keys (CMEK) for data at rest in Cloud Storage, but also needs to ensure that the keys are stored in a hardware security module (HSM) to meet compliance requirements. Which Cloud KMS key type should they choose?

Medium
538

A retail company runs a public-facing API on Cloud Run in the europe-west1 region. During a marketing campaign, traffic tripled within minutes. The service remained available, but some requests returned HTTP 503 errors. The team wants to reduce the chance of 503 errors during future traffic spikes while keeping the deployment simple. What should they do?

Easy
539

The exhibit shows a Cloud Storage bucket IAM policy. A developer (admin@example.com) wants to upload a file to the bucket but gets a permission denied error. What is the most likely reason?

Medium
540

The exhibit shows a Cloud Storage bucket configuration. What does this configuration ensure?

Medium
541

A financial services firm runs a three-tier application on Google Cloud. The security team requires that all outbound traffic from the application tier to the internet be inspected by a centralised next-generation firewall appliance, and that the application tier have no public IP addresses. The network team wants to minimise changes to the existing VPC. Which design should the architect recommend?

Hard
542

A healthcare analytics company must store patient records in Cloud Storage. Compliance requires that the data be encrypted with keys the company generates and rotates itself, and that the company retain the ability to revoke access by disabling the key. The data must remain readable by authorized applications in the same project. What should the architect implement?

Medium
543

Refer to the exhibit. A Cloud Deploy pipeline has a release with two targets: staging and prod. The staging rollout succeeded, but the prod rollout failed with 'MANIFEST_INVALID'. What is the most likely cause of the failure?

Hard
544

A developer needs to pass a startup script to a Compute Engine instance during creation. Which method should be used to ensure the script runs on first boot?

Easy
545

A small company wants to store sensitive files in Cloud Storage and ensure they are encrypted with a key that they control and rotate automatically every 90 days. They are currently using the default encryption provided by Google Cloud. They need a solution that is easy to manage and does not require manual key rotation. What should they do?

Easy
546

A company deploys a microservices application on Google Kubernetes Engine (GKE). Pods in one deployment are frequently OOMKilled. The team sets memory requests and limits, but pods still crash. What is the most likely remaining cause?

Medium
547

A company with multiple projects must ensure that no data can be exfiltrated from a specific project's Cloud Storage buckets to unauthorized locations outside the organization. They also need to allow access only from a corporate VPN IP range. Which configuration meets these requirements?

Hard
548

A company wants to protect their web application hosted on Google Cloud HTTP(S) Load Balancer from common web attacks like SQL injection and cross-site scripting (XSS). Which GCP service should they use?

Easy
549

A Cloud Run service needs to access resources in a VPC network (e.g., a Cloud SQL instance). The service should be able to send requests to the VPC and receive responses. What is the correct configuration?

Medium
550

A company runs a global application that requires strong consistency across regions for financial transactions. Which database should they choose?

Medium
551

A company is planning a hybrid cloud architecture using Anthos to manage workloads across on-premises data centers and Google Cloud. They need to select two key components that enable consistent configuration, policy, and security across environments. Which two should they choose?

Hard
552

Refer to the exhibit. What is the primary benefit of the `--preemptible` flag in this command?

Easy
553

Your organization runs a batch analytics platform that ingests data from a Pub/Sub topic into Cloud Storage, then loads it into BigQuery using a Dataflow streaming pipeline. The pipeline must handle sudden bursty traffic during month-end reporting, and you want to minimize operational overhead while ensuring the pipeline scales automatically. Which architectural approach should you choose?

Medium
554

A company wants to deploy a microservice on Cloud Run that requires high throughput and low latency. The service processes requests that can spike unpredictably. The team wants to minimize cold starts and ensure availability during traffic bursts. Which combination of Cloud Run settings should they configure?

Hard
555

An engineering team runs workloads on Compute Engine instances in a single VPC. The security team wants the instances to reach Google APIs such as Cloud Storage and BigQuery without any traffic traversing the public internet, and without managing service account key files on disk. The architect must choose the configuration that meets both goals. Which approach should the architect recommend?

Medium
556

An organization is implementing a data loss prevention (DLP) strategy for Cloud Storage. They want to automatically scan new objects uploaded to a specific bucket and redact sensitive data. Which service and configuration should they use?

Medium
557

An organization wants to deploy a containerized microservices architecture on Google Kubernetes Engine (GKE) and minimize operational overhead. They do not need to manage the node infrastructure and are willing to accept some limitations on node configuration. Which GKE mode should they choose?

Hard
558

An organization wants to monitor and alert on custom application metrics from a GKE cluster. They also need to view logs in real-time and create metrics from log content. Which two GCP services should they use? (Choose two.)

Medium
559

A retail company operates a global e-commerce platform on Google Cloud. Their architects need to choose a load balancing solution that terminates TLS at the edge, provides a single global anycast IP address, and automatically routes users to the closest healthy backend. Which Google Cloud load balancing product should they select?

Medium
560

A company is migrating a monolithic application to Google Cloud. They want to minimize changes to the application code while taking advantage of Cloud Run for serverless containers. Which approach should they take?

Easy
561

A company runs a stateful application on a single Compute Engine instance with a persistent disk. They need to ensure that the application can recover quickly in case of a zone failure. The recovery point objective (RPO) is 5 minutes, and the recovery time objective (RTO) is 15 minutes. Which approach should they take?

Hard
562

A team is migrating a stateful application to GKE. The application requires persistent storage with ReadWriteMany (RWX) access across multiple pods. Which Kubernetes volume type should they use to meet this requirement on GKE?

Medium
563

A company is migrating a legacy application that uses a file server to GCP. The application requires a shared file system that supports the NFS protocol and can be mounted by multiple Compute Engine instances. The team also needs to use Cloud NAT to allow the instances to download updates. Which TWO services should they use? (Choose 2)

Medium
564

A company has a Cloud Run service that processes high-throughput requests. They want to reduce latency by keeping a baseline of warm instances always ready to handle traffic. Which Cloud Run configuration parameters should they adjust?

Medium
565

A healthcare company is designing a solution to ingest and process millions of patient records daily. The data must be stored in a way that supports SQL queries and also allows for real-time analytics. The company wants to minimize operational overhead and needs a fully managed, petabyte-scale data warehouse. Which Google Cloud service should the solutions architect recommend?

Hard
566

A company wants to store customer transaction logs for 7 years for compliance. The logs are accessed rarely but must be retrievable within 24 hours. Which storage option is most cost-effective?

Easy
567

A startup wants to deploy a containerized web application with zero server management and automatic scaling based on HTTP requests. They expect very low traffic initially but want to scale to thousands of requests per second without configuration changes. Which compute service is most appropriate?

Easy
568

A retail company is deploying a customer-facing API on Google Cloud. The API must survive the loss of an entire region with minimal data loss and must serve users in North America, Europe, and Asia with low latency. The database layer must support strongly consistent reads and writes. Which design should the architect choose for the data tier?

Medium
569

A company runs a streaming data pipeline using Dataflow to process real-time data and insert into BigQuery. Recently, workers are frequently failing with out-of-memory errors and the pipeline latency is increasing. What should they do to resolve the issue?

Hard
570

Drag and drop the steps to migrate a Compute Engine VM to a different region using a snapshot into the correct order.

Medium
571

What are two best practices for designing a scalable Kubernetes architecture on GKE?

Easy
572

A financial services firm is designing a new application on Google Cloud. The application must store sensitive customer data and comply with regulations that require encryption at rest with keys managed by the company. The company also needs to control key rotation and revocation. Which Google Cloud service should the solutions architect use to meet these requirements?

Easy
573

A startup is building a mobile app backend that requires real-time data synchronization across multiple users. They need a fully managed, serverless NoSQL database that scales automatically and supports offline persistence. Which database should they choose?

Easy
574

A company is using BigQuery for analytics and wants to optimize query costs. They have many ad-hoc queries that scan large tables. What is the best practice?

Hard
575

A company wants to use their existing Active Directory for authentication to Google Cloud. They need to sync user and group identities to Cloud Identity and allow users to log in with their corporate credentials. Which two services should they use together?

Medium
576

A company wants to enforce that only container images built and signed by their CI/CD pipeline can be deployed in their GKE cluster. Which Google Cloud service should they use?

Hard
577

A financial services company is designing a Google Cloud landing zone. Regulators require that production workloads be isolated from non-production workloads, that each business unit control its own billing and quotas, and that a central team enforce network and security policies across everything. The company wants to minimize the number of projects it must manage manually. Which structure should the architect propose?

Hard
578

A company runs a critical application on Compute Engine instances in a managed instance group (MIG) across three zones in us-central1. The application uses a Cloud Spanner database. Recently, the application experienced increased latency and timeouts during peak hours. The operations team noticed that the MIG's CPU utilization is consistently above 80% during peak hours, and the autoscaler is configured to scale based on CPU utilization with a target of 60%. However, the autoscaler is not adding new instances quickly enough, causing performance degradation. The team also observed that new instances take over 5 minutes to become healthy and serve traffic. The health check is a simple TCP check on port 8080. The application startup script downloads large configuration files from Cloud Storage. What should the team do to improve the autoscaling response time and reduce latency?

Hard
579

An organization has a security policy that prohibits the use of external IP addresses on Compute Engine instances to reduce attack surface. They want to enforce this policy across all new and existing projects. Which approach should they use?

Hard
580

A financial services company runs a three-tier web application on Compute Engine across three zones in us-central1. Their security team mandates that database traffic must never traverse the public internet, and that the database subnet must be reachable only from the application subnet. The network team has already created a custom VPC named fin-vpc with separate subnets for web, app, and db tiers. Which combination of controls should the architect implement to satisfy these requirements?

Medium
581

A security engineer wants to configure Identity-Aware Proxy (IAP) for an HTTPS load-balanced application to enforce zero-trust access. Users will authenticate with their Google accounts. What is the minimum set of IAM roles needed for a user to access the application behind IAP?

Medium
582

An organization wants to ensure that all Compute Engine instances in a project are patched with the latest security updates. They also want to enforce a custom configuration (e.g., disable root SSH login) across all instances. Which TWO Google Cloud services should they use together?

Medium
583

A retail company runs an e-commerce platform on GKE. The SRE team wants to measure the error budget for a service level objective (SLO) defined as the proportion of requests served with HTTP 2xx or 3xx status over a 28-day window. They need a monitoring configuration that computes the burn rate and alerts when the budget is being consumed too quickly, while avoiding noisy alerts during brief spikes. What should they do?

Medium
584

Which THREE actions can help reduce costs for a BigQuery workload that runs frequent, ad-hoc analytical queries on a large dataset?

Hard
585

A retail company runs a stateful PostgreSQL database on a Compute Engine VM in project prod-db. The database writes nightly backups to a regional Cloud Storage bucket in a separate project, backup-archive. The security team requires that the VM's service account can upload objects but must not be able to delete or overwrite existing backups. Which IAM configuration should the architect implement?

Medium
586

A startup is migrating its on-premises MySQL database (5 TB) to Cloud SQL. The database is mission-critical and downtime must be minimized. Which migration service should they use to reduce downtime?

Easy
587

A company is migrating a legacy application to Google Cloud. The application requires a shared file system that can be accessed by multiple Compute Engine instances simultaneously. The file system must be POSIX-compliant, highly available, and scalable. The company wants to minimize management overhead. Which solution should they use?

Hard
588

A company is using Cloud Load Balancing with backend services across multiple regions. They notice that traffic is not being evenly distributed and some backends are overloaded. Which configuration should they check?

Medium
589

A healthcare analytics company is designing the Google Cloud landing zone for a new HIPAA-regulated workload. The security team requires that no project in the organization can enable a public Cloud Storage bucket by accident, and that all data-at-rest in BigQuery is encrypted with keys the company rotates on its own schedule. Which two design decisions should the architect include? (Choose two.)

Medium
590

A media company wants to serve publicly available images and videos to a global audience with low latency. Which Google Cloud service should they primarily use?

Easy
591

A financial services company is migrating a monolithic Java application to Google Kubernetes Engine (GKE) for improved scalability and reliability. The application serves real-time trading data and has strict latency requirements. Post-migration, the team observes frequent pod restarts due to OutOfMemory (OOM) errors, increased latency during peak trading hours, and occasional database connection timeouts. The current setup uses a single GKE cluster with a node pool of n1-standard-4 machines, a stateless application deployed as a Deployment with resource requests and limits set to 512 Mi memory and 1 CPU. The database is a Cloud SQL PostgreSQL instance with 2 vCPUs and 7.5 GB memory, and applications connect using a hardcoded connection string. The team wants to ensure reliable operation under load and during node maintenance events. Which course of action best addresses the reliability issues?

Hard
592

Your team manages a service with a 99.9% uptime SLO over a 30-day window. The error budget for this period is 43 minutes. In the first week, outages consumed 30 minutes of the budget. You are planning a new release. What should you do?

Medium
593

A company is migrating a legacy monolithic application to Google Cloud. The application runs on a single VM and uses a local MySQL database. The goal is to minimize changes to the application code while improving availability. Which strategy should the company use?

Medium
594

A startup deploys a web application on Compute Engine instances behind an HTTP load balancer. They need to handle unpredictable spikes in traffic with minimal operational overhead. What is the simplest scaling approach?

Easy
595

A healthcare company stores sensitive patient data in Cloud Storage. They must ensure that data is encrypted at rest with a key that they manage, and that the key is automatically rotated every 90 days. They also need to be able to audit key usage. Which approach should they take?

Medium
596

A company wants to deploy a microservices architecture on Google Cloud. They need a service mesh to manage traffic, security, and observability across services. They also want to run workloads on both GKE and Compute Engine. Which solution should they use?

Hard
597

A company is migrating 500 TB of on-premises file server data to Cloud Storage. The on-premises network has a 1 Gbps link to Google Cloud, but the migration must complete within 30 days. What is the MOST cost-effective and reliable method?

Medium
598

An engineer wants to store a database password securely and allow a Cloud Run service to access it. Which GCP service should they use?

Easy
599

Your team is following an incident management process. After resolving a major incident, you are tasked with conducting a postmortem. What is the PRIMARY goal of the postmortem process in Google Cloud's recommended approach?

Hard
600

A company deploys a web application on Compute Engine behind an HTTP Load Balancer. They want to ensure only healthy instances receive traffic. What should they configure?

Easy
601

A healthcare analytics company stores sensitive patient datasets in a Cloud Storage bucket in the us-central1 region. A new regulation requires that the data never leave the United States and that access be restricted to a defined set of projects. The security team wants a guardrail that prevents any future project from reading the bucket unless it is explicitly authorized, while keeping administration simple. What should the architect implement?

Hard
602

A healthcare company is planning a Google Cloud landing zone for a new regulated workload. They must enforce organization-wide guardrails, centralize billing visibility, and give each business unit autonomy over its own projects. The security team needs to apply policies that cannot be overridden by project owners. Which two design choices should you recommend? (Choose two.)

Medium
603

A developer needs to build a serverless event-driven application that responds to Cloud Storage object uploads by processing the file and storing results in Firestore. Which compute service is the best fit?

Medium
604

A company needs to connect their on-premises data center to Google Cloud with a dedicated, low-latency connection that provides a Service Level Agreement (SLA) of 99.99% uptime. They anticipate high bandwidth usage (10 Gbps). Which connectivity option should they choose?

Medium
605

A company uses Cloud Build to deploy a Java application to Artifact Registry. They want to automatically trigger a build only when changes are pushed to the 'main' branch in their Cloud Source Repository. Which configuration should they use?

Medium
606

A team wants to define an SLO for a service that requires 99.9% availability over a 30-day window. They need to measure the ratio of successful requests to total requests. Which SLI should they use?

Easy
607

Which THREE practices are recommended for organizing projects in a Google Cloud organization?

Easy
608

A government agency must run sensitive analytics in BigQuery while ensuring that analysts can see aggregated results but never the raw values of specific personal data columns. Analysts use SQL and must not be able to bypass the restriction by writing their own queries. The agency also needs to record who queried which columns. Which combination should the architect use?

Hard
609

A company wants to improve the reliability of their microservices architecture on Google Cloud. Which TWO practices should they implement? (Choose 2)

Medium
610

A company wants to ensure that all access to their Cloud Storage bucket is logged for compliance purposes. Which type of audit log should they enable?

Easy
611

A healthcare company must store patient documents in Cloud Storage. Compliance requires that the data be encrypted with keys the company controls and that key usage be centrally audited and revocable. The architect plans to use Cloud KMS. Which two actions should the architect take to meet these requirements? (Choose two.)

Medium
612

A company runs a critical application on a managed instance group in a single zone. The application stores data on a zonal persistent disk. The company wants to ensure that the application can survive a zone failure with minimal data loss and automatic failover. They also want to minimize changes to the application. Which approach should they take?

Hard
613

A company is deploying a multi-tenant SaaS application on GKE. Each tenant's data must be isolated at the network level. They want to use a single GKE cluster but ensure that pods from different tenants cannot communicate with each other. Which GCP feature should they use?

Hard
614

A company runs a microservices-based application on Google Kubernetes Engine (GKE) with a Regional cluster. They want to improve reliability by implementing best practices for pod scheduling and resilience. Which TWO actions should they take? (Choose two.)

Hard
615

A financial services firm is designing a new analytics platform on Google Cloud. Regulatory requirements mandate that data must never be replicated or processed outside the European Union, and the company wants to prevent accidental resource creation in non-EU regions regardless of which engineer is deploying. Which mechanism should the architect use to enforce this constraint?

Easy
616

A company needs to store archival data that is accessed less than once a year, with retrieval times of up to 12 hours acceptable. The data must be kept for 10 years for compliance. What is the most cost-effective Cloud Storage solution?

Hard
617

A startup wants to encrypt data at rest in Cloud Storage using Customer-Managed Encryption Keys (CMEK). They have already created a Cloud KMS key ring and key. What additional step is required to enable CMEK for a new Cloud Storage bucket?

Easy
618

A company is deploying a new microservices application on Google Kubernetes Engine (GKE). They need to ensure that each microservice can be independently scaled and updated without affecting other services. They also want to minimize the blast radius of a failure in one microservice. Which design approach should they use?

Medium
619

A company uses Cloud KMS with CMEK to encrypt data stored in BigQuery. They need to audit who has used the encryption key and when. Which type of audit log should they enable?

Hard
620

Which GCP service should be used to automatically scale a GKE cluster's number of nodes based on pending pods?

Easy
621

Which THREE are valid methods to connect an on-premises network to a Google Cloud VPC?

Medium
622

A company runs a public-facing web application on Compute Engine instances behind an external HTTP(S) load balancer. They want to protect the application from common web attacks such as SQL injection and cross-site scripting, and they also want to restrict access to known IP ranges. Which Google Cloud service should they use?

Medium
623

A multinational corporation operates in multiple regions and must comply with GDPR. They use Cloud Load Balancing to distribute traffic across regional backends. Their security team wants to block traffic from specific countries (e.g., non-EU countries) at the edge. What should they use?

Hard
624

A company runs a web application on Compute Engine with an HTTP Load Balancer. Users report intermittent 502 Bad Gateway errors. What is the most likely cause?

Medium
625

A media company is preparing to migrate a batch reporting application to Google Cloud. The application currently runs on physical servers that are used at about 20 percent CPU on average, but it has two short month-end peaks each quarter when utilization reaches 90 percent for about six hours. The company wants to reduce infrastructure cost while guaranteeing the application always has enough capacity during the peaks. What should the architect recommend?

Easy
626

Your company has migrated its legacy web application from a single Compute Engine instance to a managed instance group (MIG) behind an HTTP(S) load balancer. The application was updated to a new version as part of the migration. After the migration, users report intermittent 502 Bad Gateway errors. The application logs show no errors, and the load balancer backend health checks are reported as healthy. On investigation, the developers discover that the new version requires a specific environment variable for authentication to a downstream service. This variable was set manually on the original instance but is missing from the MIG's instance template. The health check endpoint does not depend on this variable and always returns a 200 status even when the variable is absent. As a result, instances created from the template are considered healthy by the load balancer, but when they receive requests that require authentication, they fail and return a 502 error to the client. What is the most likely cause of the 502 errors?

Easy
627

A company wants to implement a zero-trust access model for internal web applications running on Compute Engine. They need to authenticate users using corporate credentials and enforce context-aware access based on device posture and IP address. Which TWO services should they use?

Medium
628

Your company runs a global e-commerce platform on Google Cloud. The application is deployed across multiple regions for low latency. You use Cloud SQL for transactional data and Cloud Spanner for global consistency of inventory. Recently, the operations team reported that the application is experiencing increased latency during peak hours, and the monthly cloud bill has risen significantly. Upon investigation, you find that the Cloud SQL instance is underutilized (CPU < 20%) while Cloud Spanner split utilization is over 80%. The application instances are fronted by a global external HTTPS load balancer. Network egress costs are high. Which course of action would best address both the latency and cost issues?

Easy
629

You need to create a Cloud Logging sink that exports logs to a BigQuery dataset for long-term analysis. Which destination type should you specify?

Easy
630

A financial services firm stores sensitive customer records in Cloud Storage and must ensure that only identities in its corporate domain can read the objects, that no object can ever be made publicly accessible, and that access decisions are evaluated centrally. The firm wants the least administrative overhead while keeping these guarantees across many buckets created by different teams. What should the architect implement?

Hard
631

A financial services company runs a payment processing platform on Compute Engine. Compliance requires that all data at rest be encrypted with keys the company controls and that key material never leave their on-premises HSM appliances. They must also minimize operational overhead for key rotation. Which Google Cloud solution should the architect recommend?

Medium
632

A company runs a batch processing application on Compute Engine that reads data from Cloud Storage and writes results to BigQuery. The application runs on a managed instance group (MIG) with autoscaling. Recently, job failures occurred because instances could not authenticate to BigQuery. You need to ensure that the instances have the necessary permissions without embedding credentials in the application. What should you do?

Hard
633

Your organization wants to use Cloud SQL for a MySQL database with automatic failover in the event of a zone outage. Which configuration should you choose?

Easy
634

An organization needs to comply with FedRAMP requirements and restrict data storage to specific regions. They also need to audit all admin activities and data access. Which three components should they implement? (Choose three.)

Hard
635

A healthcare company stores protected health information in Cloud Storage and BigQuery. Compliance requires that access to this data be auditable and that no single administrator can both modify data and erase the audit trail. The security architect is designing the logging and access model. Which two actions should the architect take? (Choose two.)

Medium
636

Match each GCP security service to its function.

Medium
637

A company has a global web application deployed across multiple regions. They use an external HTTPS Load Balancer with backend services in us-central1 and europe-west1. They want users to be routed to the closest healthy backend. Which load balancing configuration is required?

Hard
638

An organization needs to run a stateful application on Google Kubernetes Engine (GKE) where the nodes are fully managed by Google and the application workload SLAs are guaranteed. They want to minimize operational overhead. Which GKE mode should they use?

Medium
639

You want to monitor the latency of an application running on Compute Engine and create an alert if the 99th percentile latency exceeds 500ms for more than 5 minutes. Which approach should you use?

Medium
640

A company wants to enforce that all secrets used by applications running on Compute Engine are rotated automatically every 30 days. Which GCP service should they use to store and manage these secrets?

Medium
641

A team manages a GKE cluster with node pools using different machine types. They plan to upgrade the cluster to a new Kubernetes version. What is the safest upgrade strategy to minimize application downtime?

Medium
642

A company has a multi-region deployment of App Engine and wants to optimize request routing for latency and cost. Which GCP service should they use?

Hard
643

Refer to the exhibit. A user reports that the instance 'batch-vm' is unavailable. Based on the output, what is the most likely cause of the unavailability?

Medium
644

A financial services company runs a containerized trading platform on Google Kubernetes Engine (GKE). Compliance requires that all inter-pod traffic be encrypted without modifying application code, and that the encryption keys be managed by the company rather than Google. The security team wants to enforce this at the infrastructure level. Which approach should they take?

Medium
645

A company runs a stateful application on GKE that requires persistent storage. They want to ensure that during cluster upgrades, pods are not disrupted and storage is preserved. Which configuration should they use?

Medium
646

A retail company is designing a new microservices architecture on Google Cloud. They want to minimize operational overhead, enable independent deployment of services, and ensure that a failure in one service does not cascade to others. They also want to use managed services where possible. Which two design choices should the architect recommend? (Choose two.)

Medium
647

A startup is deploying a new containerized web application to Google Cloud. The team wants the simplest way to run containers without managing Kubernetes nodes, needs automatic scaling from zero, and wants to pay only when requests are being handled. Which Google Cloud service should the architect recommend?

Easy
648

A team wants to provide a consistent, low-latency experience for global users accessing static content (images, CSS, JS) hosted on Cloud Storage. They also need to be able to invalidate cached content quickly when updates occur. Which service should they use?

Medium
649

A company is designing a VPC Service Controls perimeter to protect data stored in Google Cloud. They need to allow access from their on-premises network via a Cloud VPN tunnel while blocking all internet-based access. What is the most secure and manageable approach?

Medium
650

A startup is deploying a new web application on Google Cloud. They want to ensure that their development, staging, and production environments are isolated from each other for security and billing purposes. They also want to apply different IAM policies per environment. Which Google Cloud resource hierarchy structure should the architect recommend?

Easy
651

A company runs a batch processing job that uses preemptible VMs. The job occasionally fails due to VM preemption. They want to improve reliability without significantly increasing cost. Which TWO actions should they take? (Choose TWO.)

Easy
652

A company is moving a legacy application to Compute Engine. The application has inconsistent resource usage and the team wants to optimise costs without performance degradation. They are evaluating committed use discounts (CUDs) and other discount types. Which THREE statements are correct about CUDs? (Choose 3)

Hard
653

A team is migrating a monolithic application to microservices on GKE. They want to gradually shift users to the new microservices version while keeping the old monolithic version running. They need to route a small percentage of users based on a cookie. Which traffic management approach should they use?

Medium
654

A company runs a stateful application on Compute Engine with persistent disks. They want to ensure data durability across a zone failure. What is the best approach?

Hard
655

A company uses Cloud Bigtable for time-series data. They experience high latency and uneven load distribution across nodes. What is the most likely cause?

Hard
656

A company is migrating its on-premises data warehouse to BigQuery. They want to minimize the cost of storing large amounts of historical data that is rarely queried. The data must remain available for queries but can tolerate slightly longer query times. What should they do?

Easy
657

A company runs multiple microservices on Cloud Run. Each service uses a Serverless VPC Access connector to connect to a shared Cloud Memorystore for Redis instance (standard tier) in a VPC network. The Redis instance is configured with a firewall rule that allows TCP connections on port 6379 from the VPC connector's subnet (10.8.0.0/28). After a recent code update, the order-service fails to connect to Redis, while the user-service continues to work. The error logs in order-service show 'connection refused'. The engineer verifies that both services use the same VPC connector, the same Redis instance IP, and the same service account. The VPC connector's metrics show no errors. What is the most likely cause?

Hard
658

A data engineer needs to analyze data in BigQuery but must mask personally identifiable information (PII) based on user roles. Which service should they use?

Medium
659

A developer is writing a Cloud Function that processes files uploaded to a Cloud Storage bucket. Which trigger should they use?

Easy
660

Your organization is implementing a Disaster Recovery plan for a critical database. Which THREE components are essential for a robust DR strategy? (Choose 3)

Medium
661

A startup runs a public API on Compute Engine behind an external HTTP(S) load balancer. The security team wants to block common web attacks such as SQL injection and cross-site scripting at the edge, with minimal changes to the application, and they want the protection rules to be managed centrally and updated as new signatures are released. What should the architect recommend?

Easy
662

A startup wants to deploy a containerized web application that must scale automatically based on incoming request concurrency. The team wants to avoid managing Kubernetes nodes or clusters and prefers a fully managed serverless platform with per-request billing. Which Google Cloud service should the architect recommend?

Easy
663

Which Google Cloud service allows organizations to define perimeters that protect resources and data from exfiltration to other VPCs or networks?

Easy
664

A healthcare company stores patient records in a Cloud Storage bucket. Compliance requires that all data be encrypted with customer-managed keys, and that the company can revoke access to the data by disabling the key. They also need to audit every key usage. Which approach should they take?

Hard
665

An organization is migrating a legacy monolithic application to Google Cloud. The application currently runs on a single server with an on-premises database. The application is stateful and requires low-latency access to the database. The migration must minimize downtime and ensure high availability. Which architecture should the company adopt?

Hard
666

A company is designing a hybrid cloud architecture where on-premises applications need to access data stored in a Cloud Storage bucket. The company requires that traffic between on-premises and Google Cloud does not traverse the public internet and must be encrypted. They also need dedicated bandwidth. Which Google Cloud service should the solutions architect use?

Medium
667

A company is deploying a critical application on GKE and wants to ensure high availability during node upgrades and failures. Which TWO configurations should they implement? (Choose 2.)

Medium
668

A small development team is prototyping a containerized application on Google Cloud. They want the least operational overhead for running containers, automatic scaling based on incoming requests, and the ability to scale to zero when there is no traffic. They do not need Kubernetes APIs or custom networking. Which compute option should the architect recommend?

Easy
669

A company has Compute Engine instances in us-east1-a and us-east1-b zones. They want to allow communication between these instances with minimal latency and no additional cost. What is the best networking approach?

Medium
670

A company runs a critical application on Compute Engine instances in a managed instance group (MIG) with autoscaling. During a traffic spike, some instances become unhealthy but are not automatically replaced. What is the most likely cause?

Medium
671

A company is moving a legacy monolithic application to a microservices architecture on Google Cloud. They want to minimize operational overhead and automatically scale each service independently. Which TWO compute services should they consider? (Choose two.)

Medium
672

A company wants to improve the performance of their Cloud SQL for PostgreSQL instance. They notice many idle connections and slow queries. Which THREE actions could help? (Choose 3)

Medium
673

A healthcare company stores patient documents in Cloud Storage. Compliance requires that documents be retained for seven years and that no user, including administrators, can delete or overwrite them during that period. The company wants the simplest configuration that enforces this. What should the architect implement?

Easy
674

Which THREE options are valid strategies for disaster recovery (DR) in Google Cloud?

Hard
675

A retail company is building a new application on Google Cloud. The security team requires that all data at rest be encrypted with keys the company manages, that key usage be auditable, and that the application on Compute Engine never store long-lived credentials on disk. The architect is selecting controls for the design. (Choose two.)

Medium
676

A security team wants to receive alerts when a user attempts to grant the 'roles/owner' role to a member outside of the organization's domain. Which log filter should they use to create a log-based metric?

Easy
677

Your company is designing a new application on Google Cloud. The security team requires that all data at rest be encrypted with customer-managed encryption keys (CMEK) and that access to these keys be audited. You need to implement a solution that meets these requirements. (Choose two.)

Medium
678

A company is designing a disaster recovery strategy for a critical application running on Compute Engine with a regional managed instance group (MIG) and an HTTP load balancer. They require an RTO of 10 minutes and RPO of 1 hour. The application state is stored in Cloud SQL for PostgreSQL. What is the most cost-effective approach?

Hard
679

A retail company runs a monolithic Java application on Compute Engine instances in a single managed instance group behind an external Application Load Balancer. During a flash sale, the application becomes unresponsive, and the operations team observes that the CPU utilization of all instances reaches 100%. The team wants to ensure that the application remains available during similar events. They need a solution that automatically adjusts capacity based on demand and minimizes manual intervention. Which approach should they take?

Medium
680

An e-commerce company runs its order-processing service on Cloud Run. During flash sales, the service experiences sudden traffic spikes, and the operations team observes that new instances take too long to start, causing elevated latency and some request failures. The service has a large container image and initializes database connection pools at startup. Which configuration change should the team make to reduce cold-start impact while controlling cost?

Hard
681

A retail company runs a legacy order-processing system on a single Compute Engine VM with a local SSD. The system is business-critical and must be migrated to Google Cloud with minimal downtime and no data loss. The database is PostgreSQL, and the company wants to move to a managed service. The cutover window is only 30 minutes. Which migration approach should the architect recommend?

Hard
682

A financial services firm is deploying a three-tier application on Google Cloud. The web tier runs on managed instance groups behind an external HTTP(S) load balancer, the application tier runs on GKE, and the database tier runs on Cloud SQL. Security requires that the database tier accept connections only from the application tier and that no component be reachable from the public internet except the web tier. The architect must design the network and firewall configuration. (Choose two.)

Hard
683

A financial services company is designing a hybrid cloud architecture. They have an on-premises data center and want to extend their VPC network to Google Cloud. They require a dedicated, high-bandwidth, low-latency connection with a SLA, and they need to encrypt traffic in transit. They also want to avoid using the public internet. Which connectivity option should they choose?

Medium
684

What is the purpose of a Pod Disruption Budget (PDB) in GKE?

Easy
685

A multinational corporation must comply with GDPR and requires that all customer data stored in BigQuery be encrypted using customer-managed encryption keys (CMEK) and that the keys are stored in a specific region. Which combination of steps should they take?

Hard
686

An organization is migrating a MySQL database to Cloud SQL. They require automatic failover with zero data loss in the event of a zone outage. Which configuration should they use?

Medium
687

A healthcare company stores patient records in Cloud Storage buckets across several projects. Compliance auditors require that no object can ever be made publicly readable, even by a project Owner, and that any attempt to do so must be blocked centrally. The security team must enforce this without breaking existing application access. What should they do?

Medium
688

A company is designing a VPC architecture for a multi-tenant SaaS platform. Each tenant has isolated workloads that must not communicate with each other. They also need centralized network security and logging. Which VPC design meets these requirements?

Hard
689

A company runs a critical application on Compute Engine instances in a managed instance group (MIG) with autoscaling. Users report intermittent 503 errors during traffic spikes. Which action should the company take to improve reliability?

Easy
690

A company is building a web application on GKE. They want to automatically scale the number of pods based on HTTP request rate. Which TWO resources should they configure?

Easy
691

Your organization requires that all production changes to Google Cloud resources be auditable and that you can identify who made a change and when. You need to configure logging to meet this requirement. What should you do?

Easy
692

A company is using Cloud Storage for backups and wants to minimize costs. The backups are accessed infrequently and can tolerate retrieval delays. Which storage class is most appropriate?

Easy
693

An e-commerce company exposes a public API through an external HTTP(S) load balancer on Google Cloud. The security team wants to block traffic from known malicious IP ranges and apply rate limiting per client IP, while keeping legitimate customers unaffected. They want the least operational overhead and no changes to backend applications. What should they do?

Medium
694

A company is migrating sensitive customer data to Google Cloud. They need to ensure data is encrypted at rest and in transit. Which Google Cloud service provides a centralized way to manage encryption keys used by Google Cloud services?

Easy
695

Which TWO are required to allow on-premises hosts to access Google APIs using internal IP addresses (Private Google Access)? (Choose 2)

Medium
696

A company wants to store backup data that is accessed rarely but must be available for retrieval within minutes. Which Cloud Storage class is appropriate?

Easy
697

A company wants to run a legacy application on Google Cloud that requires a specific operating system version and kernel tuning. The application is not containerised and cannot be easily modified. Which compute service should they use?

Easy
698

Refer to the exhibit. An engineer deploys this Terraform configuration. After deployment, they can SSH into the VM using its public IP. However, they want to restrict SSH access to only a specific IP range (203.0.113.0/24). What change is required?

Medium
699

A retail company runs a stateful batch application on a managed instance group. The application writes intermediate results to the boot disk of each VM and takes several hours to complete. The operations team wants rolling updates that replace instances with a new image, but must guarantee that no in-flight job is interrupted. Which configuration should you recommend?

Hard
700

An e-commerce company uses Cloud SQL for MySQL for their transactional database. During a recent load test, the database experienced high latency under write-heavy workloads. The team needs to improve write performance without changing the application. Which action is most effective?

Medium
701

A DevOps team is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that the pods can securely access Google Cloud APIs (e.g., Cloud Storage) without managing service account keys. Which TWO steps should they take? (Choose two.)

Easy
702

A security admin wants to audit all 'create' and 'delete' operations on Compute Engine instances in a project for the last 90 days. Which type of audit log should they query?

Medium
703

Refer to the exhibit. An engineer deployed this Terraform configuration and can SSH to the instance using the external IP. However, they notice that the instance has a public IP address even though they intended to have no public IP. What change should be made to the configuration to ensure the instance does not get a public IP?

Medium
704

A company runs a large-scale data processing pipeline using Dataflow with streaming data from Pub/Sub. They notice increasing costs due to high data shuffle operations. They want to optimize the pipeline performance and cost. Which approach should they take?

Hard
705

A security team wants to enforce that only container images signed by their internal CI/CD pipeline can run on GKE clusters. They also need to ensure that unsigned images are rejected at admission time. Which combination of services and configurations should they use?

Hard
706

A company is using Cloud Storage to store sensitive data. They need to enforce that objects are deleted exactly 30 days after creation. Which object lifecycle rule should they configure?

Hard
707

An organization wants to monitor network traffic between VMs in a VPC for troubleshooting. Which TWO services can provide this?

Medium
708

Your company uses Cloud VPN (HA VPN) to connect to Google Cloud. You need to achieve a 99.99% SLA for the VPN connection. What configuration is required?

Medium
709

A company needs to protect an HTTPS load-balanced web application from OWASP Top 10 attacks, including SQL injection and cross-site scripting. Which GCP service should they enable?

Medium
710

A developer wants to deploy a stateless web application that automatically scales based on HTTP traffic. The application should be cost-effective and require minimal configuration. Which compute option is best?

Easy
711

A financial services company runs workloads on GKE and wants to ensure only container images that have been approved by the security team can be deployed. The approval process involves signing images after vulnerability scanning. Which GCP service should be integrated with GKE to enforce this policy?

Hard
712

Your organization runs a critical application on Google Cloud that uses Cloud SQL for PostgreSQL. The database is in us-central1. The business requires a recovery point objective (RPO) of 5 minutes and a recovery time objective (RTO) of 1 hour in case of a regional failure. What should you do?

Hard
713

A financial services company stores regulated data in BigQuery datasets. Auditors require that all data access be logged with the identity of the user, the query text, and the timestamp, and that logs be retained for 365 days and be immutable. The security team wants to use Google Cloud-native tools with minimal operational overhead. What should they implement?

Hard
714

A financial services company runs a high-volume transaction processing system on Google Cloud. They need to ensure that the system can handle sudden spikes in traffic during market open and close. The system uses a managed instance group of Compute Engine VMs behind a load balancer. They want to optimize costs while maintaining performance during peak hours. Which approach should the architect recommend?

Hard
715

You are responsible for incident management for a production service. You want to reduce manual toil during the initial response to common issues like high latency. What is the best approach?

Hard
716

A cloud architect is designing a CI/CD pipeline for a microservices application. Each service is deployed to Cloud Run. They want to use Cloud Build to automate building and deploying services only when changes occur in their respective directories. Which Cloud Build feature should they configure?

Medium
717

A company is designing a microservices architecture on Google Kubernetes Engine (GKE) for a global user base. They require high availability across multiple zones, automatic scaling, and rolling updates without downtime. Which Kubernetes workload resource should they use for each service?

Medium
718

A company is designing a highly available web application on Google Cloud. The application consists of stateless compute instances behind a global HTTP(S) Load Balancer. The compute instances must be able to handle sudden spikes in traffic. Which TWO strategies should the company implement? (Choose two.)

Hard
719

A company wants to automatically move data from Cloud Storage Standard to Nearline after 30 days and to Archive after 90 days. Which approach should they use?

Medium
720

Your organization uses Cloud Spanner for a customer database with a 99.999% availability SLA. You need a Disaster Recovery plan that ensures data consistency with zero RPO in case of a region failure. What should you do?

Medium
721

Drag and drop the steps to configure a Cloud Load Balancer with a backend service consisting of Compute Engine instances into the correct order.

Medium
722

An organization wants to receive alerts when their Cloud SQL instance's CPU utilization exceeds 80% for 5 minutes. They want to send the alert to both email and a Pub/Sub topic for further processing. What should they do?

Medium
723

A developer needs to deploy a containerized application on Google Kubernetes Engine (GKE) with minimal operational overhead. They want to automatically scale the number of pods based on CPU utilization. Which GKE feature should they use?

Easy
724

A retail company runs a customer-facing API on a managed instance group (MIG) of Compute Engine VMs behind an external Application Load Balancer. The SRE team wants the load balancer to stop sending traffic to a VM as soon as the local application health endpoint starts returning HTTP 500, even before the VM is fully unresponsive. Which load balancer component must be configured to achieve this?

Medium
725

A company uses BigQuery for analytics. They have a large partitioned table that is queried frequently. The query performance has degraded over time. Which optimization should they try first?

Medium
726

A developer needs to deploy a stateful application that requires persistent storage across pod restarts in Google Kubernetes Engine. Which resource should they use?

Easy
727

A global e-commerce site uses an external HTTPS load balancer with a backend service pointing to a managed instance group. Some users report 503 errors during peak traffic. The backend instances are healthy and not overloaded. What is the most likely cause?

Hard
728

A team wants to collect and analyze logs from multiple projects into a centralized BigQuery dataset for long-term retention and SQL querying. They want to exclude health check logs to reduce costs. Which approach should they use?

Medium
729

A company wants to minimize egress costs for data transferred between Compute Engine instances in the same region but different zones. What is the best practice?

Easy
730

A retail company runs its order-processing platform on Compute Engine instances in a single managed instance group (MIG) spread across three zones in us-central1. During seasonal peaks, the application must handle up to 10x normal traffic while keeping median request latency under 200 ms. The architecture team wants to add a caching layer that can absorb repeated catalogue reads and survive the loss of an entire zone without manual intervention. Which design should they choose?

Medium
731

Your company runs a microservices application on GKE. The development team wants to adopt a progressive delivery strategy to reduce the risk of new releases. They need to route a small percentage of production traffic to a new version, monitor key metrics, and automatically roll back if errors increase. Which approach should you recommend?

Hard
732

A data engineering team wants to ingest streaming data from Pub/Sub, transform it using Apache Beam, and load it into BigQuery for real-time analytics. They need a fully managed solution that handles autoscaling and does not require managing servers. Which TWO Google Cloud services should they use?

Medium
733

A multinational corporation needs to comply with data residency requirements for EU customer data. They want to ensure that data stored in Cloud Storage, BigQuery, and Cloud SQL for EU customers never leaves the European Union, even by administrators. They also want to detect and remediate any configuration drift that could violate this policy. What should they implement?

Hard
734

You are responsible for a Cloud Run service that experiences occasional cold starts, causing increased latency. You want to minimize cold starts while keeping costs under control. What should you do?

Medium
735

A global e-commerce company is designing its application architecture on Google Cloud. The application must serve users from multiple regions with low latency and must be able to fail over between regions automatically in case of a regional outage. The company wants to minimize operational overhead and ensure that the database layer supports multi-region writes with strong consistency. Which database solution should they choose?

Hard
736

A media company uses a multi-project Google Cloud organization. They want to optimize their cloud spend across all projects without sacrificing performance or reliability. They have already implemented committed use discounts for Compute Engine. Which two additional actions should the architect recommend to reduce costs? (Choose two.)

Medium
737

A company has a Cloud SQL for MySQL instance with automated backups enabled. They need to recover the database to a specific point in time within the last hour. Which feature should they use?

Medium
738

An organization requires that all container images deployed to GKE be signed and verified before deployment. Which GCP service should be used?

Medium
739

A company runs a high-traffic web application on Google Kubernetes Engine (GKE). The application uses a Cloud SQL for MySQL instance as its backend. The operations team wants to optimize the cost of the GKE cluster and the Cloud SQL instance without sacrificing performance or availability. Which two actions should they take? (Choose two.)

Medium
740

A logistics company runs a batch route-optimization job that reads 50 TB from Cloud Storage, performs CPU-intensive computation, and writes results back to Cloud Storage. The job runs for about four hours each night and must finish before the morning dispatch window. The team wants the lowest cost while guaranteeing completion within the window. Which compute design should the architect choose?

Hard
741

A retail company is planning a Google Cloud organization structure for a new e-commerce platform. They want to isolate production from non-production, allow central network and security teams to apply guardrails across all projects, and give application teams self-service within their own boundaries. Which two design choices support these goals? (Choose two.)

Medium
742

A startup wants to run a containerized web application that scales to zero when not in use and charges only for request processing time. Which compute service is most appropriate?

Easy
743

Your organization is adopting Google Cloud and wants to establish a cost governance framework. You need to implement mechanisms that provide visibility into spending and allow proactive control over costs. (Choose two.)

Medium
744

An organization uses Cloud Storage to store critical documents. They want to protect against accidental deletion or overwriting of objects. Which feature should they enable?

Medium
745

A company wants to migrate a MySQL database running on-premises to Cloud SQL with minimal downtime. Which GCP service should they use?

Easy
746

A company wants to restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read. Which approach should they use?

Medium
747

A company is building a microservices architecture on Google Kubernetes Engine (GKE) and needs to ensure each microservice can only access specific Cloud Storage buckets. IAM permissions should be assigned at the pod level, not at the node level. What is the recommended approach?

Medium
748

Your company has a production Cloud SQL for PostgreSQL instance in us-central1 with automated backups enabled. You need to ensure that if the zone fails, the database automatically fails over to a standby in a different zone with minimal downtime. What should you do?

Medium
749

A retail company runs a Java-based order service on Compute Engine. The service currently reads its database credentials from a plaintext file on the boot disk. A security review requires that the credentials be removed from disk, be automatically rotated every 30 days, and be retrievable by the application through a single API call. You want the least operational overhead. What should you do?

Medium
750

A multinational e-commerce company needs a globally distributed database that provides strong consistency and transactional support for order processing. Which Google Cloud database service should they use?

Easy
751

A company uses Cloud Deploy for continuous delivery. They have a delivery pipeline with multiple targets: dev, staging, and prod. They want to require manual approval before deploying to prod. How should they configure this?

Medium
752

Your company has a complex legacy application that runs on a single large VM. The application is stateful and has a monolithic architecture. You are tasked with migrating it to Google Cloud with minimal changes, but you also want to improve its reliability and scalability over time. Which migration strategy should you initially recommend?

Medium
753

An administrator is configuring firewall rules in a VPC. Two rules apply to the same traffic: rule 1 allows ingress from 0.0.0.0/0 on TCP 80, rule 2 denies ingress from 10.0.0.0/8 on TCP 80. Rule 1 has priority 1000, rule 2 has priority 500. What is the effective behavior for traffic from 10.0.0.1?

Easy
754

You are investigating a Vertex AI Workbench instance (instance-2) that is showing UNHEALTHY status. Based on the exhibit, what is the most likely cause of the issue?

Hard
755

A company wants to control which resources can be accessed by a service account in a specific project. Which IAM policy binding approach should be used?

Easy
756

A company is designing a highly available architecture for a stateful application on Compute Engine. They need to protect against zonal failures. Which THREE steps should they take?

Hard
757

A developer is trying to deploy a Compute Engine instance from a Cloud Build step. The build fails with the above error. What is the problem?

Easy
758

A developer needs to grant a Compute Engine instance the ability to read from a Cloud Storage bucket. The instance does not have a service account attached. What should the developer do?

Easy
759

Your team operates a production e-commerce application on a managed instance group (MIG) that serves traffic through a global external Application Load Balancer. During a new release, the team wants to deploy the new version to a small subset of instances and then progressively increase traffic to it while monitoring error rates, with the ability to immediately roll back if errors spike. The new version is already built as a custom image. Which approach should you use?

Medium
760

An analytics team runs a batch pipeline that reads several terabytes of data from a Cloud Storage bucket in us-central1 every night. To reduce egress and improve throughput, they decide to run the pipeline on Compute Engine VMs in the same region and want the traffic to stay on Google's internal network without traversing the public internet. They also want the VMs to reach Google APIs such as Cloud Storage and BigQuery. Which configuration should the architect recommend?

Hard
761

Which THREE Google Cloud services can be used to implement a zero-trust architecture for network security? (Choose three.)

Hard
762

A company is designing a disaster recovery strategy for a Cloud SQL for PostgreSQL database with a Recovery Point Objective (RPO) of 1 hour and a Recovery Time Objective (RTO) of 2 hours. They are using the Regional Cloud SQL tier. Which TWO actions should they take? (Choose TWO.)

Medium
763

A service account needs to be able to start and stop Compute Engine instances in a specific project. Which IAM role should be assigned at the project level?

Easy
764

A development team uses BigQuery for analytical queries. They want to reduce query costs for a large table that is frequently filtered by a date column and a customer_id column. Which TWO table design strategies will reduce the amount of data scanned? (Choose 2)

Easy
765

A logistics company is deploying a new three-tier application on Google Cloud. The architecture team must choose a managed database for the order-processing tier that provides automatic failover across zones with no application connection string changes, and they must also ensure that the database can scale read traffic independently of writes. (Choose two.)

Medium
766

Your company wants to implement a canary deployment for a microservice running on GKE. You need to gradually shift traffic from the stable version to the canary version while monitoring error rates. Which THREE components or practices should you use? (Choose 3)

Hard
767

A company stores sensitive data in Cloud Storage and wants to enforce encryption at rest using customer-managed keys. Which Google Cloud service should they use to manage the keys?

Easy
768

An organization wants to export their Cloud Logging logs to a centralized BigQuery dataset for long-term analysis. They also need to exclude logs from a specific source (e.g., a test project) to reduce costs. How should they set this up?

Hard
769

Your organization runs a microservices application on Google Kubernetes Engine (GKE). You need to ensure that the application can be rolled back quickly if a new deployment causes errors. You want to use a deployment strategy that allows you to shift traffic back to the previous version with minimal downtime. Which approach should you use?

Medium
770

An application running on Compute Engine frequently makes connection requests to a Cloud SQL for PostgreSQL instance. The connections are short-lived and many are created per second. What should be implemented to reduce latency and connection overhead?

Medium
771

An e-commerce platform uses Cloud Spanner for order processing. Recently, latency spikes have occurred during flash sales. The team suspects hot spots due to monotonically increasing order IDs. Which table design change would best solve this?

Hard
772

An e-commerce application uses Firestore for product catalog. They need to run complex analytical queries on the catalog data, such as aggregations and joins, without impacting production performance. What is the best approach?

Medium
773

Your company is designing a secure architecture for a new application on Google Cloud. They need to ensure that service accounts used by the application have only the necessary permissions, and that any use of those service accounts is auditable. Which two actions should they take? (Choose two.)

Hard
774

A company uses Cloud Logging to monitor their application logs. They notice that some logs from their Compute Engine instances are missing. The instances have the required logging permission. What is the most likely cause?

Medium
775

A cloud architect needs to implement a CI/CD pipeline for a team developing a Python-based microservice. The team uses GitHub as their source repository. The pipeline should automatically run unit tests and deploy the service to Cloud Run when changes are pushed to the main branch. Which THREE Google Cloud services should they use?

Easy
776

An organization runs workloads in multiple Google Cloud projects and wants a single, consistent way to detect and respond to threats such as compromised service accounts and anomalous API calls across all of them. The security operations team needs findings aggregated in one place and wants to reduce the effort of correlating events from Cloud Audit Logs, VPC Flow Logs, and Cloud DNS logs. Which Google Cloud service should the architect recommend?

Hard
777

A company uses Cloud Deployment Manager to manage infrastructure. They want to roll back to a previous deployment state after a failed update. What is the recommended approach?

Medium
778

A company wants to migrate on-premises workloads to Google Cloud. They need to assess the existing infrastructure, plan the migration, and track progress. Which tool should they use?

Medium
779

An organization deploys a web application on Compute Engine behind a global HTTPS load balancer. They want to reduce latency for users worldwide and minimize load on backend instances. Which GCP service should they use?

Medium
780

An e-commerce company uses Cloud SQL for MySQL for its transactional database. They need to run complex analytical queries on the same data without impacting OLTP performance. The analytical queries should be run on a read replica with minimal lag. Which solution is BEST?

Medium
781

A company is migrating a 200 TB on-premises file server to Cloud Storage. The network bandwidth is limited to 100 Mbps. The migration must complete within 30 days. Which approach should they use?

Medium
782

A media company is designing a hybrid architecture that connects its on-premises data center to a Google Cloud VPC. The company needs high-bandwidth, low-latency, private connectivity that does not traverse the public internet, and it wants redundancy so that a single link failure does not interrupt traffic. The architect is evaluating interconnect options. Which two characteristics apply to Dedicated Interconnect in this scenario? (Choose two.)

Hard
783

A security engineer wants to ensure that all admin activity in their GCP organization is logged and retained for 3 years. They also need to be alerted if a new firewall rule is created. Which logs should they enable?

Medium
784

A web application running on Compute Engine behind a global HTTP(S) load balancer experiences high latency during traffic spikes. Which quick fix would best address this issue without changing the architecture?

Medium
785

A company is adopting Site Reliability Engineering (SRE) practices. After a major incident, they want to conduct a review to understand what went wrong and how to prevent recurrence, without blaming individuals. Which SRE practice should they follow?

Easy
786

A media company runs a batch transcoding pipeline on Google Kubernetes Engine. Jobs read input from a Cloud Storage bucket and write output to a second bucket. The team wants the pipeline to keep processing through transient Cloud Storage 429 and 503 errors without losing work, and they want the pods to stop being killed mid-job during node upgrades. Which combination should the architect implement?

Medium
787

A company needs to ensure that only approved container images can be deployed to a GKE cluster. They already use Binary Authorization. What additional step is required to enforce this policy?

Medium
788

A company wants to run a containerized web application that experiences unpredictable traffic spikes. They want to pay only for resources used during request processing, with no idle cost. Which compute service should they choose?

Easy
789

An organization needs to store secrets used by multiple GCP services. They require automatic rotation of secrets every 30 days and integration with Cloud Functions. Which service should they use?

Hard
790

A company runs a latency-sensitive web application on Compute Engine in us-east1. They want to improve response times for users in Europe and Asia without changing the application architecture. Which TWO actions should they take? (Choose 2.)

Hard
791

A company wants to use Cloud Armor to protect their HTTP load balancer from SQL injection attacks. Which rule action should they configure to block malicious requests?

Easy
792

A company runs a web application on Compute Engine instances behind a global HTTP(S) Load Balancer. The application uses Cloud SQL for MySQL for user data. Users report that during peak hours, the page load times increase significantly. The development team notices that the number of database connections exceeds the maximum allowed, causing some requests to fail. The application is designed to use connection pooling with a maximum pool size of 100 connections per instance. There are currently 10 instances. The Cloud SQL instance is configured with 4 vCPUs and 15 GB memory, and the maximum connections is set to 400. The application team wants to minimize cost while resolving the issue. What should the architect recommend?

Easy
793

An organization runs a Kubernetes cluster on GKE with cluster autoscaling enabled. They notice that pods are frequently in 'Pending' state due to insufficient CPU, but the cluster autoscaler does not add nodes quickly enough. What is the most likely cause?

Hard
794

A team is building a CI/CD pipeline for a Java application that will run on GKE. They want to automatically build the application, run unit tests, create a Docker image, push it to Artifact Registry, and deploy to GKE. Which two GCP services should be combined? (Choose two.)

Medium
795

Your organization stores critical financial data in Cloud Storage. You need to ensure that if an object is deleted or overwritten, you can recover it within 30 days. What feature should you enable?

Medium
796

A company needs to store archival data that is accessed less than once a year and must be retained for 10 years for compliance. The data retrieval time is not critical. Which Cloud Storage class is MOST cost-effective?

Easy
797

A team is designing a disaster recovery (DR) plan for a critical application. Which THREE components are essential for a robust DR plan? (Choose 3)

Hard
798

A financial services company requires a globally distributed relational database with strong consistency and horizontal scalability to serve a multi-region banking application. Write conflicts are rare. Which database should they choose?

Medium
799

A company wants to automatically rotate cryptographic keys on a schedule without manual intervention. Which service should they use?

Easy
800

A team needs to set up alerting for a production service. They want to receive notifications when the 99th percentile latency exceeds 500ms for 5 minutes. Which two Cloud Monitoring components are required? (Choose two.)

Medium
801

A user wants to store a database password that will be used by a Compute Engine instance. What is the most secure and manageable approach?

Easy
802

A company uses Google Cloud Armor to protect their HTTP load balancer from OWASP Top 10 attacks. After deploying a security policy with pre-configured WAF rules, they notice that some legitimate user requests are being blocked because they match a rule incorrectly. The security team wants to fine-tune the rules to reduce false positives while maintaining strong protection. They also want to evaluate the impact of changes before enforcing them. What should they do?

Medium
803

A company hosts a web application on Google Kubernetes Engine (GKE) and wants to protect against SQL injection attacks. Which service should they configure?

Medium
804

A financial services firm is planning its Google Cloud resource hierarchy before migrating production workloads. The architecture team wants to enforce separation between business units, centralize network administration, and apply consistent IAM and policy controls across many projects. Which two design choices should the architect recommend? (Choose two.)

Medium
805

A company wants to run a containerized application that scales down to zero when not in use and only incurs costs when requests are being processed. They do not want to manage infrastructure. Which compute service should they use?

Easy
806

A company runs a critical application on a managed instance group (MIG) with autoscaling enabled. The application experiences sudden traffic spikes, and the team wants to ensure that new instances are added quickly while maintaining cost efficiency. They also want to avoid over-provisioning. Which autoscaling metric should they use?

Hard
807

A developer wants to monitor the CPU usage of a single Compute Engine VM and receive alerts when it exceeds 80%. What is the simplest way to achieve this?

Easy

Frequently asked questions

What does the scenario questions domain cover on the PCA exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 807 scenario questions questions in the PCA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
google-pca GOOGLE-PCA scenario questions Practice Questions