PCA · domain
scenario questions
Practise Google Professional Cloud Architect scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (807)
Click any question to see the full explanation, or start a practice session above.
A company uses BigQuery for large-scale analytics. They have a fixed monthly budget and want to ensure predictable costs for query processing, even when many users run concurrent queries. Which BigQuery pricing model should they use?
Hard2Refer to the exhibit. A cloud administrator is attempting to grant the BigQuery Data Viewer role to an external user (user@example.com) but receives the error shown. What is the most likely cause?
Medium3A company needs to store archival data that is accessed less than once a year. They want the lowest storage cost possible, but they can accept a retrieval time of up to 24 hours. Which Cloud Storage class should they use?
Easy4A company is deploying a microservices application on Google Kubernetes Engine (GKE). The architect needs to ensure that the cluster can automatically scale nodes based on pod resource requests and that pods are scheduled efficiently across nodes. The company also wants to minimize costs by scaling down when demand is low. Which two configurations should the architect implement? (Choose two.)
Medium5A security team needs to detect and redact personally identifiable information (PII) in documents stored in Cloud Storage before sharing them with external partners. Which two Google Cloud services should they use together? (Choose two.)
Medium6An engineer needs to view the logs of a specific Compute Engine instance in near real-time from the command line. Which gcloud command should they use?
Easy7A healthcare organization stores Protected Health Information (PHI) in Cloud SQL. They have implemented encryption at rest using CMEK and enforce TLS for all connections. To meet HIPAA compliance, they need to ensure that PHI cannot be exfiltrated from the Cloud SQL instance even if an application is compromised. The Cloud SQL instance is accessed by Compute Engine instances in the same VPC using private IPs. The security team wants to add an additional layer of defense against data exfiltration. What should they do?
Hard8Your company's global e-commerce platform uses a managed instance group (MIG) in us-central1 and a Cloud Load Balancer. Traffic has grown, and you want to improve availability by distributing load across multiple regions. What should you do?
Medium9Refer to the exhibit. A user (ops@example.com) is unable to create a new VPC network in the project. What should the administrator verify first?
Easy10Refer to the exhibit. All five nginx pods are scheduled on the same node (default-pool-1). What is the most likely reason?
Hard11An online retailer runs a stateless containerized API on Google Kubernetes Engine. Traffic is highly seasonal, spiking sharply during flash sales and dropping to near zero overnight. The operations team wants the cluster to add and remove nodes automatically based on pod demand while keeping costs low during idle periods. What should the architect recommend?
Easy12A team uses Cloud Build for CI/CD. The builds are taking longer than expected due to dependency downloads. What is the best practice to speed up builds?
Easy13A financial services firm runs batch risk calculations nightly using a large Compute Engine VM with a GPU. Jobs complete in 4 hours but are not time-sensitive. To reduce costs without sacrificing reliability, the firm enables preemptible VMs but finds that jobs are interrupted and restarting from scratch causes delays. What is the best approach to improve reliability while maintaining cost savings?
Hard14The firewall rule 'allow-ssh' was not created. According to the audit log, what is the most likely reason?
Hard15A financial services firm is designing a new payment processing system on Google Cloud. The system must expose a single global anycast IP address, terminate TLS at the edge, and route requests to the nearest healthy backend across three regions. The backend services run on Compute Engine and must be protected from volumetric DDoS attacks. Which product should you place in front of the backends?
Hard16A startup is deploying a new web application on Google Cloud. The application runs in containers on Google Kubernetes Engine (GKE) and uses a Cloud SQL for MySQL instance. The team wants to follow the principle of least privilege for the application's access to Cloud SQL. Which method should the architect recommend for authenticating the application to Cloud SQL?
Easy17A company wants to deploy a containerized application on Google Cloud and needs persistent storage that can be accessed by multiple pods in a GKE cluster concurrently. Which storage solution should they use?
Easy18A financial services company runs a multi-tier application on Compute Engine. They need to restrict network access so that only the web tier can communicate with the application tier, and only the application tier can access the database tier. All VMs are in the same VPC network. What is the most secure way to implement this?
Medium19A startup is deploying a new web application on Google Kubernetes Engine (GKE). They want to expose the application to the internet with a single global IP address and automatically route users to the closest regional cluster. They also want to minimize operational overhead. Which GKE feature should they use?
Easy20A company has set up an external HTTP(S) load balancer with a backend service pointing to a managed instance group. Some instances are failing health checks. Which TWO actions should the company take to troubleshoot the issue?
Hard21A media company stores millions of video files in a Cloud Storage bucket and serves them to users worldwide. Users in Asia report slow download speeds, while users in North America are satisfied. The files are immutable after upload and are read frequently for the first 30 days, then almost never. You want to improve global performance while minimizing cost. What should you do?
Medium22A company wants to grant a service account in Project A the ability to push containers to Artifact Registry in Project B. They want to follow the principle of least privilege. Which IAM roles should they assign?
Medium23An online learning platform runs its API on a regional managed instance group behind an external Application Load Balancer. The operations team wants to release new versions with the ability to shift a small percentage of user traffic to the new version first, then increase it gradually, and roll back instantly if error rates rise. What should they implement?
Easy24An e-commerce company is experiencing traffic spikes during flash sales. Their application runs on Compute Engine instances behind a TCP load balancer. They want to automatically scale the number of instances based on CPU utilization. Which configuration is required?
Medium25An organization runs a stateful application on GKE that must not lose data during cluster upgrades or node repairs. The application uses persistent volumes with ReadWriteOnce access mode. The team wants to ensure pods are not evicted simultaneously. Which Kubernetes resource should they configure?
Medium26You need to create a private GKE cluster with Workload Identity enabled to allow pods to access Google Cloud APIs without static service account keys. What must you configure for the cluster?
Medium27A company is deploying a web application on Compute Engine. They want to automatically scale the number of instances based on CPU utilization. Which two components are required to set up autoscaling? (Choose two.)
Easy28A company wants to monitor the health of their Cloud Run services. Which THREE metrics should they use to define a comprehensive health SLI? (Choose 3)
Easy29An organization wants to connect their on-premises data center to Google Cloud with a dedicated 10 Gbps link. They require high availability and have budget for two physically diverse connections. Which solution should they choose?
Easy30A media company runs a video transcoding service on GKE Standard. The service experiences sudden traffic spikes, and the operations team wants to ensure that the cluster can scale nodes automatically and that pods are rescheduled quickly when a node fails. The team also wants to monitor and alert on resource saturation. Which two actions should the cloud architect take to meet these requirements? (Choose two.)
Medium31Your company runs a critical application on Compute Engine instances in us-central1. The application requires low latency between instances that are all in the same region. You notice that network latency between instances varies and sometimes spikes. You want to ensure consistent low-latency communication. You currently use external IP addresses for communication between instances. What should you do?
Easy32Which Google Cloud service provides a fully managed, serverless data warehouse for petabyte-scale analytics using SQL?
Easy33An engineer runs the command above. A few days later, the instance becomes unresponsive. Upon investigation, you find that the boot disk is 100 GB and 95% full. The data disk is 500 GB and only 20% full. What is the most likely cause of the unresponsiveness?
Hard34A company runs a multi-tier web application on Google Kubernetes Engine (GKE) with a frontend service, a backend service, and a Cloud SQL for PostgreSQL database. During peak hours, the frontend pod CPU usage is high (consistently above 80%), while the backend service shows moderate CPU usage (around 50%). Response times for user requests increase significantly, often exceeding the 200ms p99 latency target. Cloud SQL metrics show low query latency and no contention. The team wants to improve performance in a cost-effective manner. Which initial step should they take?
Medium35A global logistics company runs a three-tier application on Compute Engine in a single region. The database tier must survive the loss of an entire zone without data loss, and the application tier must continue serving traffic with minimal disruption during a zonal failure. The architect wants the smallest operational change that satisfies both requirements. Which design should the architect implement?
Hard36A security team wants to prevent data exfiltration from a GKE cluster to external storage. They need to restrict access to Cloud Storage buckets from the cluster without using private IPs. Which solution should they implement?
Medium37A financial services firm runs a regulated workload on Compute Engine. Auditors require that all data at rest on persistent disks be encrypted with keys the firm controls and can revoke, and that key usage be logged independently of the project's Cloud Audit Logs. The firm's security policy forbids storing key material in the same project as the workload. Which approach meets these requirements?
Hard38A company uses Cloud Armor to protect their HTTP load balancer. They need to block traffic from a specific set of IP addresses and also prevent SQL injection attacks. Which two configurations should they use? (Choose TWO.)
Hard39A media company is designing a new content delivery architecture on Google Cloud. Users worldwide download large video files, and the company wants to serve them from a global edge cache while keeping the origin bucket private. They also want to reduce egress cost by caching at the edge. Which Google Cloud service should you recommend as the front end for this architecture?
Easy40Your company uses Cloud SQL for PostgreSQL to support a web application. During peak hours, the database experiences high read load, causing slow query responses. You need to improve read performance while ensuring data consistency. What should you do?
Medium41A developer wants to store a database password that is used by a Cloud Function. The password must be automatically rotated every 30 days and accessed securely without storing it in the source code. Which GCP service should they use?
Easy42An engineer needs to grant a user the ability to create and manage service accounts in a project. Which predefined IAM role provides these permissions?
Easy43An organization uses Active Directory (AD) on-premises and wants to synchronize user identities to Google Cloud Identity so that users can access G Suite and GCP resources with their existing credentials. Which service should they use?
Medium44A company's BigQuery costs are higher than expected. They run many ad-hoc queries with filters on the 'transaction_date' column and 'customer_id' column. They also have a materialized view that is rarely used. Which combination of actions will MOST effectively reduce query costs?
Hard45An organization uses Cloud Deployment Manager to manage infrastructure as code. They need to ensure that changes to production resources are reviewed and approved before deployment. What should they do?
Medium46You need to monitor the performance of a production Cloud Run service and set an alert when the p99 latency exceeds 500 ms over a 5-minute window. Which combination of Cloud Monitoring resources should you use?
Medium47A startup is deploying a containerized application on Google Kubernetes Engine (GKE). The development team wants to minimize operational overhead for managing the Kubernetes control plane and nodes. They also want to ensure that nodes are automatically upgraded and repaired. Which GKE mode should they use?
Easy48A small startup is deploying a new application on Google Cloud. They want to ensure that they can monitor the application's performance and receive alerts when certain thresholds are exceeded. They have limited operational staff and want a managed solution that requires minimal configuration. Which Google Cloud service should they use?
Easy49A company is migrating its on-premises data warehouse to BigQuery. The data is currently stored in several CSV files on a Compute Engine instance. The company needs to load the data into BigQuery once and then perform complex analytical queries. The data volume is about 10 TB, and the company wants to minimize cost and loading time. Which approach should the architect recommend?
Medium50Which two GCP audit log types are available by default? (Choose TWO).
Easy51A startup wants to deploy a containerised web application that auto-scales based on HTTP request traffic, with no infrastructure management. They expect unpredictable traffic spikes. Which compute service is most suitable?
Easy52Drag and drop the steps to implement a disaster recovery plan using Cloud Storage and Cloud Functions in the correct order.
Medium53Which THREE are best practices for managing secrets (e.g., API keys, passwords) in Google Cloud? (Select exactly 3.)
Hard54A healthcare company stores patient records in Cloud Storage and BigQuery. Auditors require that cryptographic keys used to protect this data are generated and stored on hardware security modules, that key material never leaves Google's infrastructure, and that the company retains the ability to control key rotation and revocation. The security team wants the least operational overhead while meeting these requirements. Which key management approach should the architect select?
Medium55A company wants to analyze their Google Cloud spending and receive recommendations for rightsizing resources. Which tool provides this functionality?
Easy56A company deploys a Kubernetes workload in GKE that needs to access Cloud Storage. They want to avoid managing service account keys. What is the recommended approach?
Hard57A developer is migrating a stateful application to GKE. The application requires persistent storage with high IOPS for a database. Which storage option is most suitable?
Easy58A company is migrating its on-premises Hadoop cluster to Google Cloud. They want to use a fully managed service that supports HDFS, Hive, and Spark, and allows them to run ephemeral clusters that can be created and deleted on demand. They also want to minimize infrastructure management. Which Google Cloud service should they use?
Easy59A media company runs a monthly batch pipeline that transcodes video uploads stored in Cloud Storage. The pipeline runs on a Managed Instance Group of Compute Engine VMs and typically completes in 6 hours. The VMs are only needed during this window, but the team wants to minimise the operational effort of stopping and starting the group. Which approach best optimises both cost and operational overhead?
Medium60Your organization requires all container images deployed to GKE to be signed by an approved authority. Which service enforces that only signed images are allowed to run?
Medium61Your company runs a stateful application on Compute Engine instances in a managed instance group (MIG). The application writes data to a persistent disk attached to each instance. You need to ensure that the application can automatically recover from a zone failure by recreating instances in another zone with their persistent disks. You also want to minimize data loss. Which configuration should you implement?
Medium62Drag and drop the steps to configure IAM roles for a service account to access Cloud Storage from a Compute Engine instance into the correct order.
Medium63A company uses Cloud SQL for PostgreSQL. They want to minimize downtime during maintenance. Which feature should they enable?
Easy64Your company runs a critical application on Google Kubernetes Engine (GKE) with 5 nodes. The application experiences intermittent high latency every Friday afternoon. The team has ruled out infrastructure issues and suspects the application logic. You need to instrument the application to identify the root cause. Which approach should you take?
Easy65A company needs a relational database that can scale horizontally across multiple regions, supports ACID transactions, and provides strong global consistency. Which Google Cloud database should they choose?
Easy66Match each IAM role type to its description.
Medium67Which THREE are required to configure Workload Identity for a GKE cluster? (Choose 3)
Hard68A company runs a service on Cloud Run that needs to access a Cloud SQL instance via private IP. Both are in the same VPC network. The service cannot connect to the database. What is the most likely cause?
Hard69An organization is using Cloud Interconnect to connect their on-premises network to Google Cloud. They need to ensure 99.99% availability for their connection. Which configuration meets this requirement?
Medium70After executing the command, a security review reveals that the service account sa-bucket-reader can also list buckets in the project, which was not intended. What is the most likely cause?
Easy71A software company wants to give a third-party analytics vendor read access to a specific BigQuery dataset containing aggregated, non-sensitive sales data, without creating service account keys that the vendor must store and rotate. The security team also wants to be able to revoke access quickly and to see which vendor identities accessed the data. The vendor already uses its own identity provider that supports OpenID Connect. Which TWO approaches together meet these requirements? (Choose two.)
Hard72A logistics company is planning to migrate a batch ETL pipeline from on-premises Hadoop to Google Cloud. The pipeline processes several terabytes nightly, and the team wants to minimize infrastructure management while keeping the ability to tune the cluster for cost and performance. The data currently resides in an on-premises HDFS cluster. Which combination of services should the architect recommend?
Medium73A company wants to implement blameless postmortems as part of their SRE practices. Which THREE principles should they follow?
Medium74A company wants to migrate an on-premises Oracle database to Google Cloud. They need high availability and want to minimize application changes. Which service should they use?
Medium75A financial services firm runs a latency-sensitive trading API on Google Kubernetes Engine (GKE). During peak market hours, the API occasionally returns errors because pods are evicted when nodes run out of memory. The team wants the workload to be protected from node-level resource pressure and to receive a graceful termination window when the node must be drained. Which configuration should they apply to the Deployment?
Hard76A small e-commerce team wants to deploy a containerized storefront to Google Cloud with minimal operational overhead. Traffic is steady, the team has no Kubernetes expertise, and they want to pay only for what they use while the service scales automatically. Which compute option should the architect recommend?
Easy77A company has deployed a critical application on Google Kubernetes Engine (GKE) with a Regional cluster (us-central1). The application uses a Cloud SQL for PostgreSQL database with a cross-region replica for disaster recovery. The SRE team needs to ensure that the application can survive a regional outage with minimal data loss. Which TWO actions should the team take to improve the reliability of the solution?
Medium78A company commits to using Compute Engine for 3 years and wants the maximum discount. Which purchasing option should they use?
Easy79A healthcare company runs a critical patient portal on Compute Engine. The portal uses a Cloud SQL for PostgreSQL database. The company needs to perform a major version upgrade of the database with minimal downtime and wants to minimize the risk of data loss. They also want to be able to roll back quickly if issues arise. Which approach should they take?
Hard80Your company runs a stateful application on Compute Engine instances in a managed instance group. The application requires that each instance maintains a unique identity and persistent storage. You need to ensure that instances can be recreated without data loss and that they retain their identities. What should you do?
Hard81A company has two VPC networks in the same project: 'vpc-prod' and 'vpc-dev'. They want to allow communication between instances in both VPCs. What is the simplest method?
Medium82A company runs a web application on Compute Engine behind a HTTP(S) Load Balancer. They want to reduce latency for users worldwide. Which Google Cloud service should they use?
Medium83Which TWO statements about Google Cloud VPC networks are true? (Choose two.)
Easy84A company runs a microservices application on Google Kubernetes Engine (GKE). Each service is deployed as a Deployment with resource requests and limits. After deploying a new version of a service, the pods start crashing with OOMKilled. The team increased the memory limits in the Deployment manifest, but the pods still crash after a few minutes. The cluster has cluster autoscaling enabled. The node pool has sufficient capacity. What is the most likely cause of the issue?
Medium85A financial analytics firm is deploying a new batch reporting platform on Google Cloud. The platform runs on a Managed Instance Group (MIG) of Compute Engine VMs and reads source data from a single Cloud Storage bucket. The security team requires that the VMs access the bucket without using long-lived service account keys, and that the identity be scoped specifically to this workload. They also want the permission to be automatically revoked when the VMs are deleted. Which approach should you recommend?
Medium86A company is using Cloud Load Balancing to distribute traffic to a managed instance group (MIG) of web servers. The web servers are currently running in us-central1. To improve availability, the company plans to add a second MIG in us-west1. What must be done to ensure traffic is automatically routed to the closest healthy backend?
Medium87A global e-commerce platform is experiencing intermittent latency spikes during flash sales. The application is deployed on Google Kubernetes Engine (GKE) with a regional cluster. The architecture includes a frontend service, a product catalog service using Cloud Spanner, and an order processing service using Cloud Pub/Sub. During high load, the catalog service shows increased query latency, and some requests time out. What should the architect prioritize to address the issue?
Hard88Your team runs a stateful analytics workload on a Managed Instance Group (MIG) of Compute Engine VMs. The VMs write intermediate results to local SSD scratch disks. During a recent incident, an autoscaling event terminated VMs and the intermediate data was lost, causing hours of recomputation. You need to change the deployment so that when a VM is terminated by the autoscaler, a shutdown script has enough time to flush the intermediate results to a Cloud Storage bucket before the VM is deleted. What should you do?
Medium89During a load test, an application running on GKE experiences high latency and errors. You suspect the issue is due to insufficient cluster resources. Which gcloud command should you use to quickly check the current resource utilization of all nodes in the cluster?
Hard90A healthcare company runs a patient portal on Google Kubernetes Engine (GKE). Auditors require that all container images be scanned for vulnerabilities before deployment and that only images from a trusted registry be admitted to the cluster. You are configuring Binary Authorization. Which TWO actions should you take to meet these requirements? (Choose two.)
Hard91A developer needs to programmatically create and manage Compute Engine instances. Which Google Cloud service should they use to authenticate and authorize service accounts?
Easy92An organization wants to enforce that all container images deployed to Google Kubernetes Engine (GKE) clusters are signed by an authorized authority and only those images are allowed to run. Which GCP service should they use?
Easy93A company is planning to deploy a global web application on Google Cloud. They expect low latency for users worldwide and need to serve static content (images, CSS) as well as dynamic API responses. Which architecture should they use?
Easy94A company wants to set a monthly spending limit for their Compute Engine usage and receive alerts when spending exceeds a threshold. Which tool should they use?
Easy95A media company's analytics team runs a nightly Apache Spark ETL job on a Dataproc cluster with 20 worker nodes. The job processes raw logs from Cloud Storage and writes Parquet files back to Cloud Storage. The cluster is created before the job starts and deleted after the job finishes, taking about 90 minutes total. The team wants to reduce the cost of this workload without changing the Spark code or increasing job runtime. What should they do?
Medium96A developer needs to securely store a database password that will be used by a Compute Engine instance. The password must be rotated automatically every 30 days. Which service should they use?
Medium97A company wants to implement a CI/CD pipeline for a Java application that will be deployed to Cloud Run. They use Cloud Build and Artifact Registry. The pipeline must compile the Java code, run unit tests, build a container image, and deploy to Cloud Run. Which THREE steps are required in the cloudbuild.yaml? (Choose 3)
Hard98A company stores sensitive customer data in Cloud Storage buckets. They want to ensure that access to these buckets is only allowed from within their VPC network. Which configuration should they use?
Medium99An organization has multiple projects in Google Cloud and wants to centralize logging and monitoring for all projects. They need to aggregate logs from all projects into a single project for analysis. Which approach should they use?
Hard100A global e-commerce company is designing a multi-region architecture on Google Cloud to ensure high availability and low latency for users worldwide. They want to use a global load balancer that can route traffic to the closest healthy backend and support HTTP(S) and TCP traffic. Which Google Cloud load balancing option should they use?
Medium101A healthcare organization uses Cloud Storage to store protected health information (PHI). They have a compliance requirement to ensure that all objects in the bucket are encrypted with a customer-managed key (CMK) that is rotated every 90 days. They also need to log all access to the bucket and detect anomalous access patterns. Which combination of Google Cloud services should they use?
Hard102A company monitors their application with Cloud Monitoring. They set up an alerting policy to notify the on-call team when the 99th percentile latency exceeds 500 ms for 5 minutes. However, they receive false positive alerts due to short bursts. How should they refine the policy?
Medium103A financial services firm runs a global trading platform on Google Cloud. The architecture must survive the loss of an entire region with a recovery point objective of zero and a recovery time objective of under one minute, and it must keep strong consistency for order records. Which design should the architect recommend?
Hard104A startup wants to deploy a web application on Google Cloud with a MySQL database. They anticipate low traffic initially but want the ability to scale seamlessly. They also want to minimize operational overhead. Which combination of services should they choose?
Easy105A startup wants to deploy a containerized application with minimal operational overhead. They expect variable traffic. Which compute option should they choose?
Easy106You are responsible for ensuring the reliability of a high-traffic web application running on Google Kubernetes Engine (GKE). You need to implement a monitoring strategy that alerts you when the application's error rate exceeds 1% over a 5-minute window. You want to minimize false positives and ensure alerts are actionable. What should you do?
Hard107To achieve a 99.999% availability SLA for a globally distributed application using Cloud Spanner, which configuration is required?
Easy108A company runs batch analytics workloads on Compute Engine that can tolerate interruptions. They want to reduce compute costs by up to 60-90%. Which compute option is the most cost-effective?
Medium109An organization needs to implement a change management process for a mission-critical application on GKE. They want to validate performance before full rollout and be able to roll back quickly. Which THREE practices should they adopt? (Choose THREE.)
Medium110Which Google Cloud service provides a fully managed, auto-scaling environment for running stateless HTTP(S) web applications using a variety of supported programming languages?
Easy111Refer to the exhibit. A developer is trying to connect to the Kubernetes API server from their workstation using the master IP (34.67.89.12) but receives a timeout. The developer can reach other external IPs. What is the most likely reason for the timeout?
Hard112A company is planning a phased migration of their on-premises database to Cloud SQL. They want to minimize downtime and ensure data consistency. Which approach should they use?
Medium113A healthcare analytics company stores protected health information in Cloud Storage buckets. Auditors require that data be encrypted with customer-managed encryption keys (CMEK) and that key usage be logged separately from data access. The security team wants the ability to revoke access to the data by disabling a single key without deleting the data. Which configuration should the architect recommend?
Hard114A company has a global user base and wants to serve static content (images, videos, CSS) with low latency from edge locations. They also want to protect their origin server from traffic spikes. Which combination of services should they use?
Medium115A company is using Cloud NAT to allow private instances to access the internet. They notice that outbound connections are failing intermittently. What is the most likely cause?
Easy116A company uses Cloud Storage for analytics data with lifecycle policies to move objects from Standard to Coldline after 30 days and delete after 365 days. They notice that objects are being deleted after 30 days instead of 365. What is the most likely cause?
Hard117Your company runs a containerized microservices application on Google Kubernetes Engine (GKE) with a regional cluster. The application consists of a frontend service, a backend API service, and a background worker service that processes messages from Cloud Pub/Sub. The worker service uses a Deployment with 3 replicas. Recently, the team noticed that the worker service is frequently failing with 'ContainerCreating' errors. The error message in the pod events is: 'Failed to pull image "gcr.io/my-project/my-worker:latest": rpc error: code = DeadlineExceeded desc = context deadline exceeded'. The image is stored in Container Registry in the same project. The cluster nodes are n1-standard-2 VMs with 10 GB of disk space. The team has confirmed that the image exists and that the nodes have internet access. What is the most likely cause of the issue?
Hard118A company uses Cloud Storage for backup data. They want to protect against accidental deletion. Which option is best?
Easy119A team is deploying a microservice on Cloud Run that needs to access a Cloud SQL database securely. They want to avoid using public IPs and ensure traffic stays within Google's network. Which configuration should they use?
Medium120A company runs a global e-commerce site on GKE. They want to ensure disaster recovery with multi-region deployment. What is the best practice for configuring GKE clusters?
Easy121A logistics company runs a Cloud Run service that processes shipment events. They want to be notified and to trigger an automated rollback when the error rate of a new revision exceeds a threshold shortly after deployment. Which Google Cloud feature should they use?
Easy122A company is designing a data pipeline to ingest streaming data from IoT devices and store it in BigQuery for analysis. They need to minimize latency and operational overhead. Which two Google Cloud services should they use? (Choose two.)
Easy123Your company runs a stateless web application on Compute Engine. You want to ensure that if a zone fails, the application continues to serve traffic with minimal manual intervention. What should you do?
Easy124A company uses Cloud Storage to store user-uploaded content. They want to ensure that the data is highly durable and protected against accidental deletion. Which two features should they enable? (Choose two.)
Easy125A developer needs to deploy a Python script that processes images uploaded to a Cloud Storage bucket. The script should run only when new objects are created, and should scale automatically with no idle costs. Which GCP service is most appropriate?
Easy126A financial services company requires that all audit logs be retained for 7 years in a cost-effective, immutable storage. They also need to run ad-hoc SQL queries on the logs. Which configuration should they use?
Hard127A startup is deploying a new web application on Google Cloud. They want to minimize infrastructure management and focus on writing code. The application consists of a frontend and a backend API, and they expect variable traffic. They also want to pay only for what they use. Which Google Cloud service should the solutions architect recommend for deploying the application?
Easy128Your team is deploying a new internal web application on Compute Engine. The security team requires that all outbound internet traffic from the instances be inspected by a third-party firewall appliance running on a separate VM. You need to implement this with minimal changes to the application instances. What should you do?
Medium129An engineering team is deploying a microservices application on Google Cloud. They want to use a service mesh for observability, traffic management, and security. They are considering Anthos Service Mesh (ASM). Which THREE components are part of ASM? (Choose THREE.)
Hard130Your company runs a microservices application on Google Kubernetes Engine (GKE). The development team complains that they lack visibility into which service is causing latency spikes during peak hours. You need to implement a solution that provides distributed tracing and service-level metrics without modifying application code. Which approach should you use?
Medium131Your team is deploying a new three-tier application to Google Cloud. The security team requires that the application's Compute Engine instances never receive public IP addresses, yet the instances must still download OS patches from the public internet and reach a third-party REST API over HTTPS. You need to implement this with the least operational overhead. What should you do?
Medium132Your organization is using Google Cloud to host a web application that experiences unpredictable traffic spikes. You need to ensure the application scales automatically and maintains high availability across multiple zones. The application runs on Compute Engine instances behind a load balancer. What should you do?
Easy133An organization wants to enforce that all container images deployed to Google Kubernetes Engine (GKE) are signed and approved via an attestation authority. Which GCP service should they use?
Easy134A developer is using Cloud Build to automate deployments. The build fails with an error: 'Permission 'iam.serviceAccounts.actAs' denied.' What is the most likely cause?
Medium135A developer needs to cache session state for a web application to reduce latency. The cache must be highly available and support sub-millisecond access times. Which Google Cloud service should they use?
Easy136An application running on Compute Engine is experiencing increased latency. You suspect a network bottleneck due to high egress traffic. Which gcloud command can you use to quickly check the network egress traffic for a specific VM instance?
Hard137Drag and drop the steps to set up a VPC network peering between two projects in Google Cloud into the correct order.
Medium138A company is deploying a global web application on Google Cloud. The application serves static content from a Cloud Storage bucket and dynamic content from a managed instance group backend. They want to use a single global IP address and provide low latency to users worldwide. They also want to protect the application from DDoS attacks. Which solution should they implement?
Hard139An organization is implementing a data loss prevention (DLP) strategy for sensitive data stored in Cloud Storage. They want to automatically detect and redact credit card numbers in CSV files uploaded to a specific bucket. Which TWO Google Cloud services should they combine to achieve this?
Hard140Your organization operates a multi-project Google Cloud environment. A security team requires that any new Compute Engine instance created in the production folder must have OS Login enabled and must not use project-wide SSH keys. You want to enforce this centrally with the least operational overhead and ensure that non-compliant creation attempts are denied. What should you do?
Hard141A multinational retailer is planning its Google Cloud landing zone. Each of the company's business units must be able to create projects and manage billing independently, but the central platform team must retain the ability to enforce network and security guardrails across everything. The company also wants to minimize the number of distinct IAM policy bindings it maintains at the top of the hierarchy. Which two design choices should the architect make? (Choose two.)
Hard142You are deploying a new version of a microservice to Google Kubernetes Engine (GKE). The service must remain available during the rollout, and you need to minimize the risk of exposing bugs to all users at once. You want to gradually shift traffic to the new version while monitoring key metrics. Which strategy should you use?
Hard143A company has a Shared VPC with a service project hosting GKE clusters. The GKE nodes need to access Cloud SQL instances in the host project. The team wants to avoid public IP and use Private Service Access. They have configured a VPC peering between the host VPC and the service producer VPC for Cloud SQL. However, the GKE pods cannot reach the Cloud SQL instance. What is the most likely cause?
Hard144A company is migrating its on-premises MongoDB database to Google Cloud. They want a fully managed, highly available NoSQL database that is compatible with MongoDB drivers. Which Google Cloud service should they choose?
Hard145An organization uses Active Directory (AD) on-premises. They want to synchronize user accounts and groups to Google Cloud Identity so that users can sign in with their existing AD credentials. Which service should they use?
Medium146Drag and drop the steps to set up a Cloud VPN tunnel between Google Cloud and an on-premises network into the correct order.
Medium147A company is running a web application on Compute Engine instances that average 20% CPU utilization. They want to reduce costs without impacting performance. What is the most effective action?
Easy148A company hosts a web application on Compute Engine behind a global HTTP(S) load balancer. They notice that some users experience high latency from certain regions. They want to improve performance without adding complexity. What should they do?
Medium149A company is migrating a legacy e-commerce platform to GKE. The application consists of several stateless microservices and a stateful database. They want to minimize operational overhead for the database while ensuring high availability across zones. Which database option should they choose?
Hard150A company is migrating a monolithic application to Google Cloud. The application consists of a stateful service that writes to local disk and a stateless web server. They want to minimize changes to the code. Which architecture should they use?
Hard151A financial services company must run a PostgreSQL database with strong consistency across three regions. They need to support high write throughput and require automatic failover with zero data loss. Which database service should they choose?
Medium152A company is planning to migrate a batch processing workload to Google Cloud. The workload runs nightly and can be interrupted without impacting the business. The company wants to minimize compute costs. Which Google Cloud service should they use?
Easy153A developer runs the command above. The instance is created successfully, but cannot be reached via HTTP from the internet. What is the most likely cause?
Medium154A company has a legacy application that runs on a single Compute Engine VM and expects to use a fixed IP address. They want to migrate the VM to a different region with minimal downtime. Which TWO actions should they take?
Medium155A company is migrating 50 on-premises VMs to Compute Engine. They need to minimise downtime and want an automated lift-and-shift migration that replicates disks incrementally. Which Google Cloud service should be used?
Medium156Drag and drop the steps to deploy a containerized application to Google Kubernetes Engine (GKE) using a Deployment into the correct order.
Medium157A startup wants to deploy a containerized web application that must scale automatically based on incoming HTTP request volume and must be reachable at a stable HTTPS endpoint. The team has no Kubernetes experience and wants to minimize infrastructure management. Which Google Cloud service should they use?
Easy158A company wants to give a new employee read-only access to all projects in their GCP organization. Which IAM role should they assign at the organization level to grant this access?
Easy159A company wants to run containerized applications on Google Cloud with minimal operational overhead. They prefer to use a serverless container platform. Which TWO compute options should they consider? (Choose 2.)
Medium160A company wants to monitor their Cloud Run services for errors and latency. Which Google Cloud product should they use?
Easy161Your service has a 99.99% uptime SLO (monthly error budget ~ 4 minutes). Which TWO monitoring practices best support this SLO? (Choose 2)
Hard162A company wants to migrate its on-premises monolithic application to Google Cloud with minimal changes. They plan to run it on a virtual machine with a predictable workload that runs 24/7 for a one-year commitment. Which compute option is MOST cost-effective?
Easy163A startup runs a batch analytics job on a single Compute Engine instance that takes about nine hours and reads 2 TB from a Cloud Storage bucket each run. The team wants to reduce cost without changing the application code, and the job can be interrupted and resumed from checkpoints. Which machine configuration should the architect recommend?
Easy164A GKE cluster has a Horizontal Pod Autoscaler (HPA) configured for CPU utilization. The pods are not scaling up even though CPU usage is high. What could be the reason?
Hard165A logistics company has a BigQuery dataset that is queried heavily by scheduled reports each morning. Finance wants predictable monthly spend and the ability to attribute query cost to each department. Analysts currently run ad hoc queries against on-demand pricing, and costs vary widely month to month. What should the architect recommend?
Medium166An engineer needs to share a VPC network across multiple projects in an organization while maintaining centralized network administration. Which approach should they use?
Medium167An e-commerce platform uses Cloud SQL (MySQL) for its transactional database. They are experiencing performance degradation during peak hours due to high read traffic. They need to improve read throughput without modifying the application code. Which TWO actions should they take? (Choose 2)
Medium168A startup is building a serverless application that processes events from Cloud Storage buckets. Each event triggers a Python function that resizes images. Which GCP compute service is MOST suitable for this event-driven workload?
Easy169A media company stores 400 TB of video assets in a Cloud Storage bucket in the europe-west1 region. Editors in Tokyo and São Paulo complain about slow first-byte times when previewing assets. The architect must improve read latency for these global users while keeping a single canonical copy of each object and avoiding application changes that rewrite object paths. Which approach best meets these requirements?
Hard170A security engineer is configuring VPC Service Controls to protect a project containing BigQuery datasets with PII. They want to prevent data exfiltration while allowing authorized users to query the data from outside the perimeter. Which configuration meets these requirements?
Hard171Which THREE of the following are recommended practices when designing a highly available architecture on Google Cloud using multiple regions?
Hard172A Cloud Spanner instance is experiencing high latency for point reads. The instance has 5 nodes and the read throughput is moderate. The table has a primary key with monotonically increasing values. What is the most likely cause and optimization?
Hard173A retail company runs a batch analytics workload on Compute Engine. Jobs run nightly, are fault-tolerant, and can be preempted. Finance wants to minimize compute cost while ensuring the jobs still complete each night. The jobs are managed by a Managed Instance Group (MIG) template that must stay within a single zone for data locality compliance. Which configuration should you recommend?
Medium174A company wants to use Binary Authorization to enforce that only images signed by their internal CI/CD pipeline can be deployed to their GKE clusters. They have set up Cloud Build to sign images. Which THREE steps are required to configure this? (Choose 3)
Hard175A company uses Cloud Storage to store sensitive customer data. They must ensure that data at rest is encrypted with a customer-managed key that is automatically rotated every 90 days. Which Cloud Storage configuration should they use?
Medium176A retail company is planning to move its on-premises data warehouse to Google Cloud. They need a fully managed, petabyte-scale analytics database that supports standard SQL and can ingest data in real time from Pub/Sub. They also want to minimize administration and cost. Which Google Cloud service should they choose?
Easy177Refer to the exhibit. A subnet was created with the `--enable-private-ip-google-access` flag. What does this flag enable for instances in this subnet?
Hard178An organization wants to enforce that all container images deployed to their Google Kubernetes Engine (GKE) clusters are signed and have passed a vulnerability scan. Which GCP service should they use to enforce this policy?
Easy179A company runs batch processing jobs nightly that can tolerate interruptions. They want to minimize compute costs for these jobs. Which Compute Engine machine type and provisioning model is most cost-effective?
Medium180A developer wants to allow a Compute Engine VM to authenticate to Google Cloud APIs without embedding service account keys in the VM image. What is the recommended approach?
Easy181A company wants to reduce costs for a batch analytics job that runs nightly for 4 hours on Compute Engine VMs. The job is fault-tolerant and can handle instance restarts. Which Compute Engine VM pricing model is MOST cost-effective?
Easy182A DevOps team wants to automate the deployment of infrastructure on Google Cloud using a declarative configuration language. They need to support Python and Jinja templates for reusable modules. Which service should they use?
Easy183A startup is deploying a new web application on Compute Engine. The application runs on a managed instance group and must be accessible from the internet over HTTP and HTTPS. The security team requires that the application be protected against common web attacks such as SQL injection and cross-site scripting. Which Google Cloud service should the architect use to meet these requirements?
Easy184Your team is deploying a new version of a microservices application on Google Kubernetes Engine (GKE). You want to gradually shift traffic to the new version while monitoring key performance indicators (KPIs) such as error rate and latency. If KPIs degrade, you need to automatically roll back. Which approach should you use?
Medium185A retail company runs a stateless web front end on a managed instance group of Compute Engine VMs behind an external Application Load Balancer. Traffic has grown, and the operations team wants to reduce the cost of idle capacity while still absorbing sharp, unpredictable spikes in user requests. They also want to avoid managing a separate autoscaling policy for each instance group. Which provisioning approach should the architect recommend?
Medium186A company runs a stateful application on GKE using StatefulSets. Which THREE practices improve reliability?
Hard187Your company runs a stateful web application on Compute Engine instances in a managed instance group (MIG) with autoscaling based on CPU utilization. The application maintains session state in memory on each instance. Recently, users have been experiencing session timeouts and data loss during scaling events. Additionally, the application's performance degrades under load due to frequent database queries for session data. You need to design a solution that ensures session persistence, improves performance, and minimizes application changes. The application is written in Java and uses Tomcat. Which of the following should you do?
Hard188A startup is setting up a CI/CD pipeline for their web application using Cloud Build and Cloud Deploy. They have configured a Cloud Build trigger that executes on pushes to the main branch of a Cloud Source Repositories repository. The trigger runs a build step that builds a Docker image and pushes it to Artifact Registry, then creates a release using Cloud Deploy. The pipeline fails with an error message indicating that the Cloud Build service account does not have permission to create releases. What should the architect do to resolve the issue?
Easy189A company runs a Kubernetes cluster on GKE. They need to ensure that pods cannot access Google Cloud APIs unless explicitly allowed through a service account. Which GKE feature should they use?
Medium190Refer to the exhibit. A Cloud Deployment Manager deployment fails with the error 'Resource 'my-firewall' already exists'. What is the most likely cause?
Hard191An e-commerce company uses Cloud SQL for MySQL to handle user sessions. During Black Friday sales, the database experiences high read latency and connection timeouts. The traffic pattern shows 95% read operations and 5% write operations. They need to improve read performance without significant architectural changes. Which action should they take?
Hard192You are responsible for operations reliability of a production service running on Google Cloud. The service is deployed on GKE and exposes an external HTTPS endpoint through an external Application Load Balancer. You need to implement monitoring that detects when the service is unhealthy from the user's perspective and alerts the on-call team. (Choose two.)
Medium193A startup runs a customer-facing web application on Cloud Run. The operations team needs to know when the service's request latency exceeds a threshold so they can respond before users complain. They want to be notified by email and also want a record of the incident for later review. Which Google Cloud service should they use to define the alerting policy?
Easy194Your company runs a multi-region Cloud Spanner instance for a global financial application. The SLA requirement is 99.999% availability. You need to ensure that the database remains available during a regional outage. What configuration should you use?
Medium195You are running a Kubernetes cluster in GKE with the default node pool configuration shown in the exhibit. Your application requires high disk I/O performance. You notice that the application is experiencing high latency for disk operations. What is the most likely cause?
Hard196Your company has a service running on Google Kubernetes Engine (GKE) that experiences occasional spikes in traffic. You need to ensure that the service remains available during these spikes by automatically scaling the number of pods based on CPU utilization. You also want to minimize cost by scaling down when traffic decreases. Which Kubernetes resource should you configure?
Easy197A startup runs a stateless web front end on a managed instance group in a single zone. Traffic is unpredictable, and the team wants the instance group to add or remove instances automatically based on CPU utilization without manual intervention. The architect must choose the simplest managed approach. Which option should the architect configure?
Easy198A media company runs a public web application behind a global external Application Load Balancer. They need to block traffic from specific countries subject to sanctions and rate-limit abusive clients, all without changing application code. Which Google Cloud service should the architect configure?
Easy199A startup is deploying a new web application on Google Cloud. They want to minimize operational overhead and ensure the application scales automatically based on traffic. They also want to pay only for what they use. Which Google Cloud service should the architect recommend?
Easy200A gaming company needs to store player session data that is frequently updated and requires strong consistency within a single region. The data model is simple key-value with few attributes. They expect up to 1 million concurrent players, each performing 10 writes per second. Which database is most suitable?
Medium201Your company runs a critical multi-tier application: a global HTTP(S) load balancer, multiple regional managed instance groups (MIGs) for the web tier, and Cloud Spanner for the data tier. You need to design for zone-level and region-level failures. What architecture ensures the highest availability?
Hard202A company has a fleet of Compute Engine instances that need to access a Cloud Storage bucket. The security team requires that only instances in specific VPC networks can access the bucket, and that the data is encrypted in transit. How can this be achieved?
Medium203A company runs a microservices application on Google Kubernetes Engine (GKE). They want to ensure that each service can only communicate with the services it explicitly depends on, and they need to enforce this at the network layer without modifying application code. They also want to monitor allowed and denied traffic. What should they do?
Hard204A financial services firm stores sensitive customer transaction data in Cloud Storage buckets. The security team wants to ensure that the data is encrypted at rest with a key that the firm controls, and that the key is automatically rotated every 90 days. They also need to be able to revoke access to the data immediately by disabling the key. Which Google Cloud service and configuration should they use?
Medium205A company wants to use Cloud Deploy to automate deployments to GKE. They need to configure an approval gate that requires manual approval before promoting a release to a production cluster. Where is this approval gate defined?
Medium206Your company is deploying a multi-tier application on Google Cloud. The application consists of a web frontend running on Compute Engine instances, a backend API running on Google Kubernetes Engine (GKE), and a Cloud SQL for MySQL database. You need to design the network architecture to ensure that the web frontend can communicate with the backend API, and the backend API can access the Cloud SQL database, while minimizing exposure to the public internet. Which two design choices should you implement? (Choose two.)
Hard207A company has a production database running on Cloud SQL. They need to ensure high availability with automatic failover in the event of a zone outage. What should they do?
Hard208An organization wants to manage Google Cloud infrastructure as code using declarative configuration files. They need a solution that supports Python and Jinja templating languages. Which service should they choose?
Easy209A company wants to allow users to authenticate to a web application running on Compute Engine using their existing corporate Active Directory credentials without exposing the application to the public internet. Which approach should they use?
Medium210Your organization runs a critical application on Compute Engine. The monthly bill shows sustained use discounts but the finance team wants to reduce costs further. The workload runs 24/7 with predictable usage for at least the next 12 months. You need to achieve the maximum possible discount without affecting performance or availability. What should you do?
Medium211A company is migrating a stateful application to Google Cloud. The application requires persistent disks with low latency and high IOPS for database workloads. They plan to use Compute Engine instances with SSD persistent disks. However, the database performance is lower than expected. Which action should the company take to improve disk performance?
Medium212Your team is responsible for a production service running on Google Cloud. You need to define Service Level Objectives (SLOs) and monitor them using Cloud Monitoring. You want to be alerted when the service's error budget is being consumed too quickly. Which approach should you take?
Medium213Which TWO are recommended practices for securing a Kubernetes Engine (GKE) cluster?
Medium214A company is using Cloud Load Balancing to expose a web application. They want to protect against common web attacks like SQL injection and cross-site scripting. Which Google Cloud service should they configure?
Medium215A developer wants to deploy a containerized web application on Google Cloud that can scale to zero when not in use and charges only for resources consumed during request processing. Which compute service should they choose?
Easy216A media streaming company wants to serve video content globally with low latency. They plan to cache static objects (thumbnails, manifest files) at edge locations, while dynamic API requests are handled by a backend in a single region. Which combination should they use?
Hard217Your organization runs a microservices application on Google Kubernetes Engine (GKE). Each microservice has its own deployment and horizontal pod autoscaler. You want to implement a robust cost governance process that provides chargeback to each team and prevents budget overruns. You need to attribute costs accurately without modifying application code. What should you do?
Hard218A startup wants to grant a contractor limited access to a single Cloud Storage bucket. The contractor should be able to view and download objects, but not delete or overwrite them. Which IAM role should be assigned?
Easy219A Cloud Run service needs to connect to a Cloud SQL MySQL instance privately without using public IP. What must be configured?
Medium220A company is designing a disaster recovery (DR) plan for their Cloud SQL for PostgreSQL instance. They need to recover the database to a specific point in time within the last 7 days, with a Recovery Point Objective (RPO) of less than 1 hour. Which feature should they use?
Medium221Which THREE of the following are best practices when using Deployment Manager to manage infrastructure? (Choose three.)
Medium222A Cloud Function fails to connect to a Cloud SQL instance. The Cloud SQL instance has a private IP. What should the developer check?
Medium223A media company runs a stateless web application on Compute Engine behind an HTTP(S) load balancer. They want to automatically replace unhealthy VMs and maintain a fixed number of running instances across two zones. What should they use?
Medium224Your company runs a production microservices application on GKE Standard. The operations team wants to be notified when any pod in the cluster is repeatedly restarting, indicating a potential CrashLoopBackOff. They want to use Cloud Monitoring to create an alert that fires when a container restarts more than 5 times in a 10-minute window. Which metric should they use as the basis for the alerting policy?
Medium225A team uses Cloud CDN to cache static assets. They update assets by deploying new versions with new URLs. However, sometimes they need to invalidate the cache for a critical fix immediately without changing the URL. What should they do?
Medium226A retail company runs a Black Friday promotion and expects a burst of read traffic against a product-catalog database. The application is read-heavy, tolerates slightly stale data, and the team wants to scale reads horizontally without changing application code. They are using Cloud SQL for MySQL. Which design should the architect recommend?
Easy227A security engineer wants to prevent data exfiltration from a project 'prod-data' by ensuring that only approved VPC networks can access BigQuery datasets. Which GCP service should be used?
Medium228Your company uses a CI/CD pipeline that builds container images and stores them in Artifact Registry. The images are deployed to Google Kubernetes Engine (GKE). You need to ensure that only images that have been scanned for vulnerabilities and approved by a security team can be deployed to the production GKE cluster. You want to enforce this policy automatically without modifying the CI/CD pipeline. What should you do?
Hard229A company uses Terraform to manage Google Cloud infrastructure. They want to store the Terraform state file in a remote backend with state locking to prevent concurrent modifications. Which Google Cloud service supports this natively?
Medium230A retail company runs a web application on Compute Engine instances behind an external HTTP(S) load balancer. During a flash sale, the operations team notices that the load balancer is returning HTTP 502 errors for a subset of requests. The backend service health checks are passing, and the instances are not under heavy CPU load. The team wants to identify the root cause quickly and prevent recurrence. Which action should they take first?
Medium231Your team is deploying a stateful web application on Google Kubernetes Engine (GKE). The application requires each replica to have a stable network identity and its own persistent disk that survives pod restarts. You also need to ensure that the persistent disk is automatically provisioned and attached. Which GKE feature should you use?
Medium232Which GCP service can be used to detect and redact sensitive data such as credit card numbers in text files stored in Cloud Storage?
Easy233A healthcare company is designing a system to process sensitive patient records on Google Cloud. They need to ensure that data is encrypted at rest with keys they control and can rotate on demand. They also require that the encryption keys are stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 validated. Which Google Cloud service should they use?
Hard234Your company is deploying a new application on Google Cloud and needs to ensure that it can meet a 99.9% availability SLA. You are designing the architecture for high availability. Which two practices should you implement? (Choose two.)
Medium235Which TWO of the following are valid methods to control access to Google Cloud resources using Identity and Access Management (IAM)?
Hard236A team is running a GKE cluster with a workload that has variable CPU and memory usage. They want to automatically adjust pod resource requests and limits based on historical usage to improve resource efficiency. Which feature should they use?
Hard237A media company stores large video files that are accessed infrequently (once a quarter) and must be retained for 10 years for compliance. They want to minimize storage cost. Which Cloud Storage class should they use?
Medium238A company is migrating its on-premises data warehouse to BigQuery. The security team requires that all data at rest in BigQuery is encrypted with keys that the company controls, and that key usage is logged for auditing. They also need to be able to revoke access to the data by disabling the key. Which configuration should they implement?
Medium239A media company runs a batch transcoding job on Compute Engine. The job pulls source files from a Cloud Storage bucket in the same project. Security policy forbids assigning external IP addresses to any VM. The VMs must reach the Cloud Storage API without traversing the public internet. What should the architect configure?
Medium240A company needs to encrypt data at rest in Cloud Storage using their own keys. They require that the keys are stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 certified. Which key management option should they choose?
Medium241A retail company uses a Cloud SQL for MySQL instance with a single zone. The database is critical for order processing, and the company wants to minimize downtime if the zone hosting the instance fails. They also want to ensure that the application can continue to write data during a zonal failure without manual intervention. What should they do?
Medium242A company wants to migrate an on-premises MySQL database to GCP with minimal downtime and support for automated failover in case of a zone outage. Which GCP service should they use?
Easy243An organization wants to enforce a policy that prohibits the creation of Cloud Storage buckets with uniform bucket-level access disabled. What should they use?
Hard244Which GCP service provides distributed tracing to help analyze latency in microservices applications?
Easy245A security engineer needs to restrict access to a Google Cloud project so that only a specific set of IP addresses can reach Cloud Storage buckets. Which feature should be configured?
Easy246A company stores large amounts of data in Cloud Storage and wants to reduce costs. Which two actions should they take? (Choose two.)
Medium247A company wants to allow a Kubernetes pod in GKE to authenticate to Google Cloud APIs without storing service account keys in the cluster. Which three components need to be configured to enable Workload Identity? (Choose three.)
Hard248A user runs the gsutil command shown in the exhibit and gets an AccessDenied error. The user is not authenticated with gcloud. What should the user do first?
Easy249A financial services company is designing a multi-region application on Google Kubernetes Engine (GKE) for high availability. They need to serve user requests from the closest region and automatically failover if a region becomes unavailable. Which architecture should they use?
Hard250An organization wants to protect an HTTPS load-balanced web application from common web attacks, such as SQL injection and cross-site scripting (XSS), as well as rate-limit traffic from specific IPs. Which three capabilities should they use together? (Choose three.)
Medium251A large enterprise is migrating their on-premises data center to Google Cloud. They have hundreds of VMs and need to minimize network latency between on-prem and cloud during migration. They have high bandwidth requirements. Which connectivity solution should they use?
Hard252An organization wants to manage DNS records for a domain they own (e.g., example.com) and use Google Cloud for authoritative DNS. They also need to resolve internal hostnames for resources within their VPC. Which Cloud DNS configuration should they use?
Easy253A financial services company runs a PCI-DSS regulated workload on Compute Engine. Auditors require that all administrative access to the VMs is brokered through a single, auditable control plane with short-lived credentials, and that no external IP addresses are assigned to the VMs. Which Google Cloud feature should the architect implement to meet these requirements?
Medium254An organization needs to store API keys and database passwords securely in Google Cloud. They want to automatically rotate secrets every 30 days. Which service should they use?
Medium255A logistics company is planning its first Google Cloud landing zone. It has three business units that must be billed separately, a central network team that manages shared VPCs, and a security team that needs to apply guardrails across everything. Which resource hierarchy design should the architect recommend?
Easy256A security team wants to audit all IAM role assignments in an organization. They need a historical record of changes. Which tool should they use?
Hard257An organization needs to encrypt data at rest in BigQuery using keys that are rotated every 90 days. They want to manage the keys themselves but cannot store keys on-premises. Which encryption approach should they use?
Hard258A company wants to allow a Kubernetes pod in GKE to access a Cloud Storage bucket using a specific service account without storing long-lived credentials. Which method should be used?
Medium259Your team manages a production web application on Compute Engine behind an external Application Load Balancer. During a recent incident, the load balancer's backend service marked all instances as unhealthy because the health check endpoint returned HTTP 200 but the application was actually in a degraded state. You need Cloud Monitoring to alert the operations team when the application's error rate exceeds 5% over a 5-minute window. You also need to ensure that the alert does not fire during planned maintenance windows. Which approach should you take?
Medium260A company is migrating an on-premises Oracle database to Google Cloud. They want to minimize application changes and need a fully managed, PostgreSQL-compatible database with high performance for OLTP workloads. Which service is MOST suitable?
Medium261Your company runs a production application on Compute Engine instances behind a managed instance group (MIG). You need to perform a rolling update with canary testing, gradually shifting traffic to the new version only if performance metrics are healthy. Which approach should you use?
Hard262A company wants to run batch processing workloads that can be interrupted and resumed, at the lowest possible cost. The jobs are fault-tolerant and can handle preemption. They also need predictable pricing for a baseline amount of compute. Which combination of compute options should they use?
Medium263Which THREE steps can reduce processing costs in a Dataflow streaming pipeline? (Choose three.)
Hard264A company wants to connect their on-premises network to Google Cloud with a dedicated, high-bandwidth, low-latency connection that supports Service Level Agreements (SLAs) up to 99.99% availability. Which connectivity option should they choose?
Easy265A company has Compute Engine instances that need to access the internet for updates but should not be reachable from the internet. They also need to access Google APIs and services like Cloud Storage. Which configuration meets these requirements?
Hard266A Cloud Run service frequently fails with 502 errors when making requests to a backend service running on Compute Engine. The two services are in the same VPC network. The Cloud Run service is configured with a VPC connector. What is the most likely cause?
Medium267A company operates a critical application on Google Cloud and wants to define a Service Level Objective (SLO) for its latency. They need to measure the proportion of requests that complete within 200 ms over a 28-day rolling window. They also want to alert when the error budget is being consumed too quickly. What should they use?
Medium268A company uses Shared VPC. A project admin in a service project tries to create a subnet in the shared VPC network but receives a permission denied error. What is the most likely cause?
Hard269A team runs periodic BigQuery queries on a large dataset. They notice high costs due to full table scans. They want to reduce costs and improve query performance. Which two actions should they take? (Choose two options that best fit the scenario.)
Medium270Your organization is deploying a global e-commerce platform on Google Cloud. The platform uses a microservices architecture running on GKE, and you need to route external HTTP(S) traffic to different services based on URL paths and also provide global load balancing with low latency. You also want to offload SSL/TLS termination and protect against DDoS attacks. Which Google Cloud service should you use?
Hard271A company is designing a highly available architecture for a web application using Google Cloud. They need to ensure that the application remains available even if an entire Google Cloud region experiences an outage. Which THREE components should they include in their architecture? (Choose THREE.)
Hard272A healthcare company runs a three-tier application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier. All tiers are in the same VPC in project prod-apps. The security team requires that rules be evaluated by source identity rather than IP ranges, and that no instance can reach the database unless explicitly allowed. Which configuration should the architect use?
Hard273Match each GCP monitoring/logging tool to its purpose.
Medium274A company runs a critical application on Compute Engine instances. They want to automatically patch the operating system on a weekly schedule to meet compliance requirements. Which Google Cloud service should they use?
Medium275A financial services company runs a critical application on a managed instance group (MIG) of Compute Engine instances. The application must be highly available and able to survive a zone failure without manual intervention. The company wants to ensure that the MIG automatically recovers from zone failures and maintains capacity. They also want to minimize latency for users across the United States. Which configuration should they use?
Hard276A healthcare company runs a patient portal on Cloud Run services in the us-central1 region. The compliance team requires that the portal remain readable during a regional outage and that failover to a secondary region occur without changing the public hostname. The portal's data is stored in Cloud SQL for PostgreSQL. Which design should the architect recommend?
Hard277A company wants to deploy a web application behind an HTTPS Load Balancer and only allow authenticated users from their corporate Active Directory. Which two services should they use together? (Choose two.)
Medium278A company is migrating its on-premises data center to Google Cloud. They need a dedicated, low-latency, high-bandwidth connection between their on-premises network and VPC. They anticipate consistent traffic above 10 Gbps. Which connectivity option should they choose?
Medium279A retail company is planning to migrate its on-premises data warehouse to Google Cloud. They want a fully managed, petabyte-scale, and highly scalable analytics data warehouse that supports ANSI SQL and integrates with their existing BI tools. Which Google Cloud service should they choose?
Easy280A data analytics company runs nightly batch jobs using Compute Engine instances. The jobs can tolerate interruptions, and the company wants to minimize costs. What should they do?
Medium281Your organization runs a customer-facing web application on a managed instance group of Compute Engine VMs behind an HTTP(S) load balancer. The monthly bill shows that the VMs are running at only 15% average CPU utilization, yet the team insists they need the current number of VMs to handle peak traffic. You want to reduce compute costs without risking performance during traffic spikes. What should you do?
Medium282A retail company runs a customer-facing API on GKE Autopilot in a single region. During a quarterly sales event, traffic triples for six hours and then returns to baseline. The SRE team wants to keep the API responsive during the spike, control spend, and avoid manual intervention. They have already configured a Horizontal Pod Autoscaler based on CPU utilization with a target of 60%. Which additional action best addresses the remaining scaling bottleneck?
Hard283An organization needs to audit all changes to network firewall rules in a GCP project. Which service should be used to capture these changes?
Hard284A security team wants to monitor and audit all changes to IAM policies in a Google Cloud organization. They need to set up real-time alerts when a new binding is added. Which THREE services should they combine to achieve this?
Hard285A company runs a batch processing workload on Compute Engine instances in a managed instance group (MIG). The job is CPU-intensive and takes approximately 4 hours to complete. The company wants to reduce costs without sacrificing performance. Which action should they take?
Easy286A company wants to connect their on-premises network to Google Cloud with a 99.99% SLA using encrypted tunnels over the public internet. Which connectivity solution should they choose?
Easy287A developer needs to secure secrets (API keys, passwords) used in a Cloud Function. What is the recommended approach?
Easy288You are the lead cloud architect for a startup that runs a web application on Google Kubernetes Engine (GKE) with a standard (zonal) cluster. The application is deployed with 3 replicas of a stateless frontend service. During a recent incident, a zone outage caused all GKE nodes to become unavailable, leading to application downtime of 45 minutes. You need to redesign the cluster to tolerate a single zone failure with no more than 5 minutes of downtime. Your budget allows for at most a 20% increase in compute costs. Which approach should you take?
Easy289A financial services company is migrating a sensitive customer data application to Google Cloud. The application runs on Compute Engine VMs in a VPC. The security team requires that all data at rest in Cloud Storage and BigQuery must be encrypted with customer-managed encryption keys (CMEK). Additionally, the keys must be stored in a different project than the data, and access to the keys must be audited. The operations team has set up a CMEK key in Cloud KMS in a separate project, assigned the Cloud KMS CryptoKey Encrypter/Decrypter role to the data project's Compute Engine service account, and enabled Cloud Storage and BigQuery to use CMEK. However, when the application tries to read from Cloud Storage, it fails with 'Access Denied.' The Cloud KMS key is in project 'kms-proj' and the data is in project 'data-proj'. What is the most likely cause?
Easy290A global SaaS company wants to reduce the latency of its API for users in Asia, Europe, and North America. The API is stateless and runs on GKE in a single region. The company wants a solution that improves latency for all users without changing the application code. Which approach should the architect recommend?
Hard291A financial services company must comply with PCI DSS. They use Cloud SQL for MySQL for transaction processing. They need to ensure that all data at rest is encrypted with keys generated and stored in a Hardware Security Module (HSM) and that key rotation occurs every 90 days. Which configuration should they use?
Hard292A retail company is designing a new order-processing system on Google Cloud. The system must expose a REST API that is reachable from the public internet over a custom hostname, must terminate TLS at the edge, and must route requests to different backend services based on URL path prefixes such as /orders and /inventory. The platform team wants a fully managed, globally distributed solution that scales automatically and does not require managing reverse-proxy VMs. Which Google Cloud component should they place in front of the backends?
Medium293A healthcare analytics team must run a stateless containerized API on Google Cloud. The platform must scale to zero when there is no traffic, expose an HTTPS endpoint with a managed certificate, and require no cluster or node management by the team. The architect is choosing among Google Cloud container platforms. Which two characteristics make Cloud Run the appropriate choice here? (Choose two.)
Medium294A company runs a web application on App Engine Standard environment. The application experiences downtime during deployments due to traffic shifting. Which two strategies should they implement to improve reliability? (Choose two.)
Hard295A company wants to centrally manage firewall rules for all projects in an organization using hierarchical firewall policies. Which three resources can be used in conjunction with hierarchical firewall policies? (Choose three.)
Hard296A startup is migrating a monolithic application to Google Cloud. They want to minimize operational overhead and auto-scale based on HTTP request load. Which compute solution should they choose?
Easy297A retail company is designing a Google Cloud landing zone for a regulated workload. They must ensure that encryption keys for Cloud Storage and BigQuery are generated and stored outside Google's infrastructure, with the ability to revoke access immediately. They also must retain detailed records of who accessed the data and when, for seven years. Which TWO configurations should the architect include? (Choose two.)
Medium298Match each GCP compute service to its characteristic.
Medium299Match each GCP migration term to its description.
Medium300A company is deploying a new application on Compute Engine. They need to ensure that the application can automatically recover from a zone failure. What is the best approach?
Medium301A company is performing a TCO analysis to compare on-premises costs with Google Cloud. Which cost should they include as a hidden operational cost on-premises?
Medium302Which THREE are best practices for designing a highly available application on Compute Engine?
Hard303You are the architect for a company that runs a three-tier web application on Compute Engine. The CTO wants to reduce the monthly cloud bill without impacting performance or availability. You review the billing export in BigQuery and notice that the VMs are sized for peak load, but CPU utilization rarely exceeds 20% on weekdays and 5% on weekends. The application is stateless and uses an external Cloud SQL database. Which cost optimization strategy should you implement first?
Medium304Your organization is adopting a multi-cloud strategy and wants to ensure consistent security policies across Google Cloud and another cloud provider. You need to centrally manage and enforce security policies, such as preventing public access to storage buckets, across both environments. What should you do?
Medium305Drag and drop the steps to recover a Cloud SQL instance from a backup into the correct order.
Medium306An organization wants to reduce costs for a batch data processing job that runs nightly and is resilient to interruptions. The job can be restarted from checkpoints. Which Compute Engine VM pricing model should be used?
Easy307A startup deploys a containerized web application on Cloud Run. They want to release a new revision to a small percentage of users before promoting it to all traffic, and they need the ability to roll back instantly if errors increase. Which Cloud Run feature should they use?
Easy308A company is deploying a multi-tier web application on Google Cloud. The application must comply with PCI DSS. Which combination of Google Cloud services should be used to restrict access to the database tier to only the application tier, while also encrypting data at rest and in transit?
Medium309A company is migrating a legacy on-premises application to Google Cloud. The application has strict low-latency requirements between its components and requires stateful TCP sessions. Which TWO design decisions should the architect recommend?
Hard310A healthcare analytics company is designing a BigQuery-based data warehouse that ingests patient records from multiple hospitals. Regulatory requirements mandate that queries never move data across regional boundaries and that only authorized analysts can access patient-identifiable columns. The architects want to enforce these controls at the platform level rather than relying on application code. Which combination of Google Cloud features should they design into the solution?
Hard311A startup wants to deploy a stateless containerized API that must scale automatically from zero and be billed only when requests are processed. The team has no Kubernetes expertise and wants minimal operational overhead. Which Google Cloud service should the architect recommend?
Easy312A company is migrating its on-premises workloads to Google Cloud. They have strict compliance requirements that all data at rest must be encrypted with customer-managed encryption keys (CMEK). Which Google Cloud service should they use to manage the lifecycle of these keys?
Medium313A financial services company runs a regulated trading platform in a single Google Cloud region. Regulators require that the platform survive the loss of an entire region with a recovery point objective of zero and a recovery time objective of under one minute. The database is Cloud Spanner, and the application tier runs on Google Kubernetes Engine. Which design should the architect choose?
Hard314A company is migrating an on-premises PostgreSQL database (5 TB) to Cloud SQL. They need minimal downtime and automated schema conversion if needed. Which GCP service should they use?
Medium315An engineer wants to migrate an on-premises MySQL database (5.6) to Cloud SQL for MySQL with minimal downtime. Which service should they use?
Easy316A company stores backup data in Cloud Storage. They observe high egress costs when clients download backups. Additionally, they must retain backups for 7 years for compliance. Which optimization should they implement first?
Medium317A company is migrating a monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single Compute Engine instance and stores session state in local memory. The migration must support horizontal scaling and high availability. What should the company do to manage session state in the new architecture?
Medium318You are designing a multi-region deployment for a critical application on GKE. The application must withstand a regional outage and automatically redirect traffic to the healthy region. Which THREE components must be configured? (Choose 3)
Hard319A DevOps team uses Cloud Build to deploy Docker images to GKE. They want to ensure that only images that have passed a vulnerability scan and been signed by a trusted authority can be deployed. Which service should they integrate with Cloud Build and GKE?
Medium320A company uses Cloud KMS to encrypt sensitive data. They need to ensure that encryption key usage is audited and that keys are rotated automatically every 30 days. Which two actions should they take? (Choose two.)
Hard321Refer to the exhibit. A Cloud Storage bucket has this IAM policy. What security recommendation should be made?
Medium322Which TWO statements are true about Google Cloud VPC networks? (Select exactly 2.)
Medium323A small startup wants to deploy a containerized web application that scales automatically and only charges for resources used. They have limited operational experience. Which compute solution should they choose?
Easy324The exhibit shows a managed instance group configuration. What is the primary purpose of the 'autoHealingPolicies' section?
Hard325A company is migrating a legacy monolithic application to Google Cloud. They want to minimise changes while taking advantage of cloud benefits. Which TWO migration strategies are most appropriate? (Choose TWO.)
Medium326A retail company runs its e-commerce checkout service on a single Compute Engine instance in us-central1. The service must survive a zonal outage with minimal data loss and automatic failover, but the operations team is small and does not want to manage replication or failover scripts themselves. Which design should the architect recommend?
Medium327A healthcare company must store patient records on Google Cloud. Regulatory requirements mandate that the data encryption keys be generated and stored outside Google Cloud, that the company control key rotation, and that access to the data be denied if the external key is unavailable. The data will be stored in Cloud Storage and BigQuery. Which approach should the architect recommend?
Hard328Your company has a Service Level Objective (SLO) of 99.9% availability for a web application running on Google Cloud. You want to create an alert that notifies the on-call team when the error budget is being consumed too quickly. Which Google Cloud service should you use?
Easy329A company uses Cloud Armor to protect an HTTPS Load Balancer. They want to allow traffic only from users who have passed a reCAPTCHA challenge. Cloud Armor supports which feature for this?
Hard330A financial services company needs a globally distributed relational database that supports strong consistency across regions, with multi-region writes and sub-10ms latency for most queries. The database must also support SQL and ACID transactions. Which database should they choose?
Hard331A financial services firm is designing a new payment-processing platform on Google Cloud. Regulatory requirements mandate that data never leaves the European Union, that encryption keys are generated and stored on hardware the firm controls inside its own data center, and that the firm can revoke key access instantly. The security team wants to use Cloud KMS but is unsure it meets all three requirements. Which combination of services should the architect recommend?
Hard332A financial services company is designing a new application on Google Cloud. The application must comply with PCI DSS and internal policies that require strict separation of duties and least privilege. The security team wants to ensure that developers cannot modify production resources, but they need to deploy code frequently. Which approach should the cloud architect recommend to meet these requirements while supporting continuous deployment?
Hard333Refer to the exhibit. The output is from `gcloud compute instances describe instance-1 --format=json`. What can you conclude from this output?
Easy334A healthcare company stores sensitive patient data in Cloud Storage buckets. The company must ensure that data is encrypted at rest with keys that are automatically rotated every 90 days and that the keys are managed by the company itself, not by Google. The company also needs to maintain full control over key lifecycle and access policies. Which encryption option should the architect recommend?
Hard335A company uses Cloud Composer to manage Apache Airflow workflows. They want to optimize costs. Which practice is most effective?
Medium336A company runs batch analytics workloads each night on Compute Engine VMs. The workloads are fault-tolerant and can be interrupted. The finance team wants to reduce compute costs. Which Compute Engine pricing model should they use?
Medium337Which TWO are best practices when designing a VPC network for a multi-tier application in Google Cloud?
Medium338An organization wants to ensure that only container images signed by an authorized CI/CD pipeline can be deployed to their GKE clusters. Which GCP service should they use?
Easy339A company wants to set up monitoring and alerting for their application running on GKE. They need to receive alerts via email and also trigger an automated remediation workflow. Which TWO components should they use? (Choose two.)
Medium340A startup is deploying a new web application on Google Cloud. They want to use a fully managed, serverless platform that automatically scales and requires no infrastructure management. The application is containerized and listens on HTTP. Which Google Cloud service should they use?
Easy341A financial services company runs a payment API on Compute Engine behind an internal passthrough Network Load Balancer. The compliance team requires that all administrative actions on the project be attributable to a named human, that production changes be reviewed before taking effect, and that no single engineer can delete the production database. Which combination of Google Cloud controls should the cloud architect implement?
Hard342A healthcare company is deploying a new patient portal on Google Cloud. The portal must be accessible globally with low latency, must survive a single region failure, and must use a single anycast IP address. The backend runs on managed instance groups in two regions. Which Google Cloud product should the architect use to expose the service?
Medium343A logistics company runs a latency-sensitive inventory service on Compute Engine in us-central1. The service writes to a Cloud SQL for MySQL instance and reads from a Memorystore for Redis cache. The architect must design for a zone failure in us-central1 with minimal data loss and automatic failover, without changing the application's connection strings. Which design should the architect choose?
Medium344You are designing a disaster recovery plan for a critical application running on GKE. You need to back up the cluster's state and application data. Which TWO services should you use together? (Choose 2)
Medium345A financial services firm must design a data residency solution. Regulators require that customer personal data never leaves the country of origin, but the firm wants to use a single centralized analytics project for aggregated, non-personal reporting. Which Google Cloud architecture best satisfies both requirements?
Hard346A developer notices that web-server-1 is preemptible. They want to ensure their application remains available even if this instance is terminated. What should they do?
Medium347A company needs to ensure that all data stored in Cloud Storage is encrypted at rest with keys that they control and can rotate on demand. They also need to maintain an audit trail of key usage. Which Google Cloud service should they use?
Easy348A company wants to migrate a large on-premises relational database to Cloud SQL for PostgreSQL with minimal downtime. They need to ensure data consistency during the migration. Which THREE steps should they take?
Medium349A company runs a stateful workload on Compute Engine with regional persistent disks (PD). They need to implement a disaster recovery (DR) plan with a Recovery Point Objective (RPO) of less than 1 hour and Recovery Time Objective (RTO) of less than 4 hours. Which THREE steps should they include in their DR plan? (Choose three.)
Medium350A startup wants to grant a new employee read-only access to view all Compute Engine instances in a project. What is the minimum IAM role they should assign?
Easy351An organization requires that only container images signed by a trusted authority can be deployed on Google Kubernetes Engine (GKE). Which Google Cloud service should they implement?
Easy352An organization uses Cloud Functions (2nd gen) for event-driven processing. They notice that some functions fail with 'memory limit exceeded' errors during peak load. The function processes messages from Pub/Sub and writes to Firestore. What should they do to improve reliability without sacrificing throughput?
Hard353A healthcare organization is storing sensitive patient data in Cloud Storage. They need to ensure that all objects are encrypted with a key managed by their on-premises HSM. Which encryption approach should they use?
Hard354A company is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that each microservice can only communicate with specific other microservices, and they need to enforce this at the network level. They also want to minimize operational overhead. Which approach should they use?
Hard355A media company stores video files in Cloud Storage for streaming. Infrequently accessed videos older than 90 days are currently in Standard storage. To reduce costs, they want to automatically move these files to a lower-cost storage class and delete them after 3 years. Which configuration should they use?
Medium356A company uses Cloud Spanner for a global financial application. They experience increased latency and transaction aborts during peak hours. Which measure should they take first to improve reliability?
Easy357A developer wants to monitor a custom application metric from their application running on GKE. What should they use?
Easy358Your company plans to connect an on-premises data center to Google Cloud with a Dedicated Interconnect. You need to ensure high availability for the connection. What is the minimum configuration required to meet a 99.99% SLA for Dedicated Interconnect?
Medium359Which TWO of the following are benefits of using a VPC Service Controls perimeter?
Easy360You are deploying a new version of a microservices application to a GKE cluster. The deployment must be released to a small subset of users first, and if errors occur, traffic must automatically revert to the previous version. You also need to monitor the error rate and latency of the new version. Which approach should you use?
Medium361A company wants to restrict network access to Cloud SQL instances such that only applications running in a specific VPC can connect. Which GCP feature should they use?
Medium362Which TWO options are valid ways to connect an on-premises network to a VPC in Google Cloud? (Choose two.)
Medium363A company wants to connect their on-premises data center to Google Cloud with a dedicated private connection that provides 99.99% availability and supports up to 100 Gbps bandwidth. They have a colocation facility near a Google Cloud region. Which connectivity option should they choose?
Medium364A company runs a global SaaS application on Google Cloud using Cloud Spanner. They need to ensure disaster recovery with a Recovery Time Objective (RTO) of less than 5 seconds and a Recovery Point Objective (RPO) of zero. Which configuration should they use?
Hard365An organization is planning to move 500 TB of archival data from on-premises to Cloud Storage. The data is not frequently accessed, and the network bandwidth is limited to 100 Mbps. What is the most efficient migration approach?
Easy366A company migrated their on-premises database to Cloud SQL and now experiences high latency for read-heavy workloads. How can they optimize performance?
Medium367Your company is using Cloud Storage to store sensitive customer data. The security team requires that all objects be encrypted with a customer-managed encryption key (CMEK) and that the key be automatically rotated every 90 days. You need to implement this without changing the application code. You have created a Cloud KMS key ring and a key with rotation period set to 90 days. What additional configuration is required?
Medium368The exhibit shows a command to create a Compute Engine instance. The instance is intended to run a web server that needs to access Cloud Storage buckets using its service account. However, the web server fails to read from a storage bucket. What is the most likely cause?
Hard369A healthcare company runs a critical patient portal on Google Kubernetes Engine. The security team requires that all container images be scanned for vulnerabilities before deployment, that only images from a trusted registry be admitted to the cluster, and that any attempt to deploy an untrusted image be blocked and logged. Which Google Cloud feature should the cloud architect implement to enforce these admission requirements?
Hard370A company uses Cloud Logging to capture application logs. They need to alert when the number of errors exceeds 100 in a 5-minute window. Which type of alert should they create?
Easy371A media company stores millions of video master files in a Cloud Storage bucket in the us-central1 region. Files are written once, accessed frequently for the first 30 days during editing and publishing, and then almost never accessed again, though they must remain retrievable for seven years. The company wants to minimize storage cost without changing the objects' names or the way applications read them. Which approach should the architect recommend?
Easy372A company runs a batch processing job that runs daily and can handle interruptions. The job runs on a single Compute Engine instance. Which machine configuration is the most cost-effective?
Easy373A multinational enterprise is designing its Google Cloud resource hierarchy. They want to enforce centrally managed policies, delegate administration to regional business units, and isolate billing. Which two design choices should the architects make? (Choose two.)
Medium374A company needs to ensure that only applications running in a specific GKE namespace can access a Cloud Storage bucket. Which approach should they use?
Medium375A healthcare company is designing a new patient portal on Google Cloud. Regulatory requirements mandate that all data at rest be encrypted with keys the company controls and can rotate on its own schedule, and that the keys never leave a hardware security module (HSM). The security team also wants to retain the ability to revoke Google's access to the data if the external key becomes unavailable. Which key management design should you recommend?
Hard376A company has a Cloud Run service that processes images uploaded by users. The service reads the images from a Cloud Storage bucket and writes processed images to another bucket. The team recently updated the service to use a custom service account named 'image-processor-sa' with minimal permissions. After the update, the service fails with permission errors when trying to read from the source bucket. The team verified that the service account has the Storage Object Viewer role on the source bucket and Storage Object Creator role on the destination bucket. What should the architect do to resolve the issue?
Easy377A data scientist needs read-only access to a Cloud Storage bucket containing training data. What is the least privileged IAM role to grant at the bucket level?
Easy378A company is migrating a monolithic application to microservices on Google Cloud. They need to manage service-to-service authentication and authorization. Which service should they use?
Hard379Your company runs a customer-facing API on Cloud Run with a concurrency setting of 80. The API calls a backend Cloud Function that performs a heavy computation (2–5 seconds). During peak hours, the API experiences increased latency and some requests time out after 60 seconds. Monitoring shows that the Cloud Run max instances is set to 100, and the Cloud Function max instances is set to 10. The timeout for Cloud Run is set to 300 seconds. The Cloud Function's timeout is set to 540 seconds. You need to reduce end-to-end latency and prevent timeouts while minimizing cost. Which action is most effective?
Medium380A financial services company must store customer data in a GCP region that is certified for FedRAMP High. They also need to ensure that only authorized personnel can access the data, and that access logs are kept for 10 years. Which combination of services meets these requirements?
Hard381A company is deploying a new application on Compute Engine and wants to automate the installation of a custom agent on every newly created VM in a specific project. Which Google Cloud service should they use?
Medium382A company is deploying a web application on Compute Engine. They want to ensure that only authenticated users can access the application. Which Google Cloud service should they use?
Easy383A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that pods can only pull container images from a private Artifact Registry repository and that images are scanned for vulnerabilities before deployment. They also want to prevent pods from being scheduled if they use images from public registries. What should they do?
Medium384A healthcare company runs a critical application on Google Kubernetes Engine (GKE) that processes patient data. The compliance team requires that all container images be scanned for vulnerabilities before deployment, and that only images from a trusted registry be allowed. The security team wants to enforce this policy across all clusters in the organization. They also need to audit any attempts to deploy untrusted images. Which combination of Google Cloud services should they use?
Hard385An application running on GKE Autopilot is experiencing intermittent failures due to resource limits. The team wants to ensure that the application always has enough CPU and memory without manual node management. What should they do?
Hard386Which Google Cloud service allows you to create alerting policies based on log entries?
Easy387A healthcare company is planning to store sensitive patient records in Cloud Storage. They need to ensure that the data is encrypted at rest with keys that they control and can rotate on demand. They also want to maintain an audit trail of key usage. Which Google Cloud service should they use?
Easy388A company has a Cloud SQL for PostgreSQL instance that experiences high connection overhead. Developers frequently open and close connections. Which solution reduces connection overhead without code changes?
Easy389A company has a VPC Service Perimeter that protects a project containing BigQuery datasets. They want to allow an external customer's BigQuery job to query data across the perimeter boundary using a private connection. Which configuration is required?
Hard390A developer wants to store a database password securely and have it automatically rotated every 30 days. The password is used by a Compute Engine instance. Which Google Cloud service should they use?
Medium391An engineer needs to create a custom dashboard in Cloud Monitoring to track the 99th percentile latency of their application over the last 7 days. Which type of metric should they use?
Easy392A financial services company runs a critical PostgreSQL database on Cloud SQL. They need to ensure automatic failover to a replica in another zone within the same region with minimal data loss. What configuration should they choose?
Hard393When creating a Compute Engine instance from a custom image stored in another project, which gcloud flag is required?
Easy394A developer ran the above command to create a health check for a backend service. Which of the following should they do to resolve the error?
Medium395A company wants to use BigQuery with a predictable monthly cost, regardless of query volume. They have a steady state of around 500 concurrent slots. Which pricing model should they choose?
Medium396Your company runs a data pipeline on Google Cloud using Cloud Dataflow for streaming processing from Pub/Sub to BigQuery. The pipeline writes to a BigQuery table partitioned by day. The data is used for real-time dashboards. Recently, a spike in traffic caused the Dataflow pipeline to fall behind, and the dashboard displayed stale data. You need to design the pipeline to handle traffic spikes without data loss or long delays. The pipeline must be cost-efficient and use defaults where possible. Which solution should you implement?
Hard397A healthcare analytics company ingests HL7 messages into Pub/Sub and processes them with a Dataflow streaming pipeline that writes results to BigQuery. During a regional outage, the pipeline stopped and the team discovered that unacknowledged messages were lost after the retention window expired. The company needs a design where a single-region failure does not cause message loss and the pipeline can resume with minimal manual intervention. What should the architect recommend?
Hard398A company uses Cloud SQL for MySQL for its transactional database. They need to ensure automatic failover in case of a zonal outage with minimal data loss. What configuration should they use?
Medium399A company runs a stateful application on Google Kubernetes Engine (GKE) that requires persistent storage and low-latency access across multiple zones. The application needs to perform well even during zonal failures. Which storage solution should they use?
Hard400A healthcare analytics firm processes patient records in a Dataflow streaming pipeline that writes enriched events to BigQuery. The pipeline currently uses a fixed number of workers sized for peak load, and utilization is low for most of the day. The team wants the pipeline to scale with incoming volume while keeping late-arriving events correct and bounded in cost. What should they do?
Hard401A company needs to retain object versions in Cloud Storage for 90 days to protect against accidental deletion or modification. After 90 days, versions should be deleted. What feature should they enable?
Easy402An organization wants to use VPC Service Controls to protect a Cloud Storage bucket and a BigQuery dataset from data exfiltration. They want to allow access from a specific on-premises network via a Cloud VPN. Which TWO components are required? (Choose 2)
Medium403A financial services company needs to ensure that all outbound traffic from its Compute Engine instances to the internet goes through a dedicated IP address for allowlisting by a partner. The instances are in a private subnet with no external IP addresses. The company wants to minimize management overhead and avoid single points of failure. Which solution should the architect implement?
Hard404A healthcare company is migrating a legacy on-premises Oracle database to Google Cloud. The database is used for a patient records application that requires strong consistency, ACID transactions, and a relational schema with complex joins. The company wants a fully managed, highly available relational database service that minimizes administrative overhead while supporting their existing SQL workloads. Which Google Cloud service should they choose?
Medium405A company wants to provision multiple similar environments (dev, test, prod) with consistent networking configurations. Which approach is a best practice for infrastructure as code?
Easy406A financial services firm runs a regulated workload in a Google Cloud organization. Compliance requires that no resource in any project can be created outside a defined set of approved regions, and that violations are blocked before resource creation rather than reported afterward. The organization has many projects and new projects are created frequently. Which approach should the architect implement?
Hard407A financial services company runs a latency-sensitive trading application on GKE. The platform team must guarantee that the application can be recovered within a 15-minute recovery time objective (RTO) and a 5-minute recovery point objective (RPO) after a regional failure. They use a multi-region Cloud Storage bucket for configuration and a regional GKE cluster. Which additional design element is required to meet both objectives?
Hard408A company has a Cloud SQL for PostgreSQL instance in a single zone. To achieve high availability, they want to ensure automatic failover with zero data loss and minimal downtime. Which configuration should they use?
Medium409A data engineer needs to automatically detect and redact sensitive data such as credit card numbers from text files uploaded to Cloud Storage before the data is loaded into BigQuery. Which GCP service should be used?
Hard410An organization requires that all Compute Engine instances in a project must have a specific tag for firewall rule compliance. How can they enforce this?
Hard411A healthcare company stores patient records in Cloud Storage buckets across multiple projects. An audit reveals that several buckets containing protected health information are publicly accessible. The security team wants a centralized, automated way to detect and remediate public access across all current and future projects, with minimal operational effort. Which solution should the architect recommend?
Hard412Which Google Cloud service automatically computes the optimal size or tier for underutilized Compute Engine instances and generates recommendations to reduce cost?
Easy413An e-commerce platform uses Cloud Spanner in a multi-region configuration. They want to achieve the highest possible availability SLA. Which deployment configuration should they choose?
Hard414Your company uses Cloud Monitoring to track the performance of a microservices application. The SRE team wants to define an SLO for the latency of a critical API. They need to measure the proportion of requests that complete within 200 ms over a rolling 30-day window. Which approach should they use to implement this SLO?
Hard415Your team uses Cloud SQL for PostgreSQL for an e-commerce application. You want to perform point-in-time recovery (PITR) to recover from a logical error that occurred 10 minutes ago. Which prerequisites are required?
Medium416A logistics company runs a latency-sensitive order-tracking service on Compute Engine instances spread across three zones in one region. They need the architecture to survive the loss of an entire zone while keeping inter-instance latency low, and they want automatic failover without manual intervention. Which design should the architects implement?
Hard417The exhibit shows the output of a 'gcloud compute instances describe' command for an instance. What is the most likely impact on reliability if the host machine needs maintenance?
Medium418A security team needs to detect and redact personally identifiable information (PII) from documents uploaded to Cloud Storage before they are stored. Which GCP service should they use?
Medium419A retail company runs a stateless web tier on a managed instance group (MIG) of Compute Engine VMs behind an external Application Load Balancer. Traffic spikes every evening and the operations team currently resizes the MIG manually. They want the group to add and remove VMs automatically based on CPU utilization without changing the instance template. What should the architect configure?
Easy420An engineer is troubleshooting a Cloud Build trigger that fails with the error 'PERMISSION_DENIED: Cloud Build service account does not have permission to access Artifact Registry'. The build needs to push a Docker image to Artifact Registry. What is the correct IAM role to assign to the Cloud Build service account?
Hard421Which TWO actions are required to allow a private GKE cluster to pull container images from Artifact Registry in the same project?
Medium422A company needs to connect their on-premises data center to Google Cloud with a dedicated, low-latency, and highly available connection. They require at least 10 Gbps throughput and want to avoid internet-based VPN. Which connectivity option should they choose?
Medium423A company runs a web application on GKE and wants to expose it to the internet using a global HTTP(S) load balancer with Cloud CDN. Which TWO GCP resources are required to configure this setup? (Choose TWO.)
Medium424An organization has multiple GCP projects managed by a central operations team. They want to define a common VPC configuration in a host project and allow service projects to use it. Which networking feature should they use?
Medium425A team is deploying a stateful application on GKE. They want to ensure that the application's pods are distributed across different zones for high availability and that during cluster upgrades, at least one pod remains available. Which THREE features should they configure?
Medium426A financial services company runs a regulated workload on Compute Engine in a single project. Auditors require that all data written to persistent disks, including boot disks, is encrypted with keys the company controls and can revoke on demand, without the company operating its own key management infrastructure. The security lead must choose an encryption approach that satisfies this requirement with the least operational overhead. What should the security lead do?
Medium427A company is migrating its on-premises Oracle database to Cloud SQL for PostgreSQL. The database team wants to minimize downtime during migration. Which approach should they use?
Medium428A financial services company uses VPC Service Controls to protect their project containing BigQuery datasets and Cloud Storage buckets. They have a perimeter that includes the BigQuery service. Users report that they cannot export data from BigQuery to Cloud Storage using the web console. The export job fails with an access denied error. The team needs to allow exports while maintaining data exfiltration prevention. The users have the necessary IAM permissions (BigQuery Data Editor, Storage Object Admin) on the appropriate resources. What should the architect do?
Hard429A healthcare company needs to run a stateful, containerized electronic medical records application that requires a stable network identity and persistent disk storage per replica. The operations team is already fluent with Kubernetes. Which Google Cloud service should they choose?
Easy430Which IAM role should be granted to a user who needs to view but not modify resources in a project?
Easy431Which THREE factors should be considered when choosing a Google Cloud region for deploying a low-latency application serving global users? (Choose three.)
Hard432An organization has a VPC with two subnets: subnet-a (10.0.1.0/24) and subnet-b (10.0.2.0/24). They launched a Compute Engine instance in subnet-a with an internal IP 10.0.1.2 and a public IP. They want the instance to only allow HTTPS traffic from the internet. Which firewall rule should they create?
Hard433A developer accidentally deleted a bucket in Cloud Storage. The bucket had object versioning enabled. How can the bucket and its objects be restored?
Easy434Match each GCP data processing service to its use case.
Medium435A small development team is deploying a stateless containerized API on Google Cloud. They want the simplest possible way to run containers without managing servers or Kubernetes clusters, and they want the service to scale to zero when there is no traffic to minimize cost. The API receives HTTP requests from external clients. Which Google Cloud service should the architect recommend?
Easy436A developer needs to store a database password securely and access it from a Cloud Run service. Which Google Cloud service should they use?
Easy437A global gaming company deploys a leaderboard service using Cloud Spanner with a single-region configuration. They need a Recovery Point Objective (RPO) of 5 seconds and a Recovery Time Objective (RTO) of 1 minute in the event of a regional outage. What should they do?
Hard438A company needs to store secrets such as API keys and database passwords securely and access them from Compute Engine instances. Which service provides secret storage with built-in IAM integration and automatic rotation?
Easy439An engineer is designing a Bigtable schema for time-series data consisting of sensor readings. Each sensor emits a reading every second. The access pattern is to retrieve all readings for a specific sensor within a time range. Which row key design will provide the best performance?
Hard440An online retailer is deploying a new order-processing system on Google Cloud. The system consists of a regional managed instance group (MIG) of Compute Engine VMs that read from and write to a Cloud SQL for MySQL instance. The database must tolerate the loss of an entire zone within the region with minimal downtime and no manual failover steps, while keeping costs predictable. Which Cloud SQL configuration should the architect recommend?
Medium441A company is using Cloud SQL for PostgreSQL and needs to run a one-time heavy analytical query that takes over 30 minutes and uses 100% CPU. The production database is serving user traffic with high QPS. What should the company do to run the query without impacting production?
Medium442Your company runs a critical application on Compute Engine instances in a managed instance group across three zones. The application writes logs to local disk. You are asked to improve the reliability of log retention and ensure logs are available in case of instance failure. You have already configured a health check that automatically recreates instances. However, after a recent zonal outage, logs from the affected instances were lost. You need to implement a solution that preserves logs even when instances are terminated. What should you do?
Easy443A startup is deploying a new web application on Compute Engine. The architect needs to ensure that the application can automatically recover from a zone failure and that the instances are distributed across multiple zones within a region. The application must also scale automatically based on traffic. Which Compute Engine feature should the architect use?
Easy444You want to create a log-based alert in Cloud Logging that triggers when a specific error message appears in application logs. What is the first step?
Easy445A company runs a web application on Google Kubernetes Engine (GKE) with Cluster Autoscaler enabled. During a traffic spike, the application becomes slow and some requests timeout. The cluster has sufficient CPU and memory headroom. What is the most likely cause and solution?
Medium446Your organization is moving a legacy monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single virtual machine with a local MySQL database. You need to design a cloud-native architecture that improves scalability and reliability. Which two actions should you take? (Choose TWO.)
Medium447A company runs a critical application on Compute Engine. The operations team wants to improve the mean time to recovery (MTTR) for incidents. They currently use manual runbooks stored in a wiki. You need to recommend a solution that automates incident response and integrates with existing monitoring. What should you do?
Medium448A media company stores millions of small image files in a Cloud Storage bucket in the us-central1 region. Users in Europe and Asia report slow image load times. The company wants to improve read latency globally while keeping write operations in us-central1 for cost and simplicity. Which storage configuration should you recommend?
Hard449A multinational retailer must comply with a regulation stating that customer personal data collected in the European Union may not be stored or processed outside the EU, including by support staff. The company uses Google Cloud and wants a platform-level mechanism that enforces this at the data-residency level while still allowing the global analytics team to query aggregated, non-personal results. Which Google Cloud capability should the architect use as the foundation?
Easy450A company uses Cloud Armor to protect their HTTP Load Balancer from DDoS attacks. Recently, they experienced a targeted attack that bypassed Cloud Armor's predefined rules. The attack involved a high rate of legitimate-looking requests from a small set of IPs that made the application unresponsive. The team needs to block the attack quickly without affecting legitimate users. What should they do?
Hard451A company is deploying a web application on Compute Engine behind a global HTTP(S) load balancer. They want to restrict access to only traffic from specific IP ranges. Which load balancer feature should they use?
Medium452A team is using Cloud Build to deploy a microservice to Cloud Run. They want to ensure that only containers built from a specific trusted branch in their source repository are deployed to production. Which Cloud Build feature should they use?
Medium453A company wants to restrict access to a Cloud Storage bucket so that only a specific service account can read objects. The bucket contains sensitive data. Which identity and access management (IAM) approach should the architect use?
Easy454A developer wants to store and retrieve non-relational data with flexible schema and automatic scaling. Which Google Cloud service should they use?
Easy455A media company uses Cloud CDN with an HTTP(S) Load Balancer to serve video content from Cloud Storage. After a month, they notice increased costs due to high cache miss rates. Analysis shows that many requests include a unique query parameter for analytics tracking. What is the most effective way to improve cache hit ratio while preserving analytics data?
Hard456A company runs a monolithic application on Compute Engine. They want to modernize by moving to microservices on Google Kubernetes Engine (GKE) to improve deployment frequency and resource utilization. However, they are concerned about the increased operational complexity. Which approach best balances modernization benefits with operational overhead?
Medium457A multinational manufacturer is planning its first Google Cloud landing zone. The security team requires that no data be stored outside approved European regions, that all workloads authenticate using short-lived credentials tied to their Google identities, and that network egress to the public internet be centrally inspected and logged. The platform team wants to minimize per-project configuration. Which two design elements should the architect include in the landing zone? (Choose two.)
Hard458A company wants to monitor the performance of their microservices deployed on Cloud Run. They need to capture request latencies and error rates, and also trace requests across services. Which TWO services should they use?
Medium459A data engineer needs to scan a Cloud Storage bucket for personally identifiable information (PII) and de-identify the data before loading it into BigQuery. Which Google Cloud service should they use?
Medium460Refer to the exhibit. A DevOps engineer created this Terraform configuration to deploy a Compute Engine instance. After applying, they notice the instance is not accessible from the internet. What is the most likely cause?
Easy461A company needs to store petabytes of time-series IoT sensor data and query it with single-digit millisecond latency at millions of reads per second. The data has a simple key-value structure with timestamps. Which Google Cloud database is MOST appropriate?
Medium462A financial services firm is designing the network for a new payment processing platform on Google Cloud. Regulatory rules require that no workload can reach the public internet, that all egress to an on-premises fraud-detection system stay off the public internet, and that Google APIs such as Cloud Storage and BigQuery remain reachable without exposing the workloads. The platform runs on Compute Engine VMs in a single VPC. Which two design elements must the architect include? (Choose two.)
Hard463A company wants to implement an event-driven architecture where uploads to a Cloud Storage bucket trigger processing in a serverless function. The function must process each object within a few seconds and handle bursts of thousands of uploads. Which service should they use?
Medium464Your organization runs a global e-commerce platform on Google Kubernetes Engine (GKE). The security team requires that all container images deployed to the cluster are scanned for vulnerabilities and that deployments are blocked if critical vulnerabilities are found. They also want to minimize operational overhead. What should you do?
Medium465A company wants to connect their on-premises data center to Google Cloud with a dedicated, low-latency, and highly available connection. They need bandwidth of 10 Gbps. Which option should they choose?
Easy466A company is migrating an on-premises application to Google Cloud. The application consists of a web front end and a backend that uses a relational database. The company wants to minimize downtime during the migration and ensure that the database remains consistent. They plan to use a phased approach. Which TWO steps should they take to achieve a successful migration? (Choose two.)
Medium467A company deploys a web application on Compute Engine behind a Global HTTPS Load Balancer. They need to restrict access to the application based on the client's IP address. Which Google Cloud service should they use?
Medium468An engineer needs to troubleshoot a production issue on a Compute Engine instance. They suspect the instance is running out of memory. Which THREE actions should they take to diagnose the problem? (Choose THREE.)
Easy469A company runs a web application on Compute Engine behind a Global HTTPS Load Balancer. Users report slow page loads, especially for static assets. The development team wants to cache content closer to users without modifying code. Which GCP service should they enable?
Medium470A company uses preemptible VMs for batch processing. They notice that during peak hours, many instances are terminated before finishing their tasks. The operations team observes the output shown in the exhibit. Which action would best improve job completion rates without significantly increasing costs?
Medium471A DevOps engineer needs to grant a CI/CD pipeline (running in a different Google Cloud project) the ability to deploy resources into a target project. The pipeline uses a service account. What is the best way to grant this access?
Medium472A company runs a latency-sensitive web application on Compute Engine with a managed instance group (MIG) behind an HTTP load balancer. They want to reduce latency for users in Europe and Asia. Which THREE actions should they take?
Medium473A company wants to restrict data exfiltration from its Google Cloud projects by preventing resources from copying data to external IP addresses. Which service should they use?
Easy474A company wants to encrypt data at rest in Cloud Storage using a key that they generate and manage themselves, not stored in Google Cloud. Which encryption type should they use?
Medium475A company is designing a data processing pipeline in Google Cloud that must be HIPAA compliant. Which three security features should they implement? (Choose three.)
Easy476A company stores infrequently accessed data in Cloud Storage Standard class. To reduce costs, they want to automatically move objects older than 90 days to a lower-cost storage class. Which approach should they use?
Medium477A company uses Assured Workloads to meet FedRAMP compliance. They need to ensure that only authorized personnel can access data access audit logs for their projects. Which IAM role should they grant to the security team?
Hard478A company is migrating a legacy monolithic application to Google Cloud. The application currently runs on a single on-premises server and uses a local MySQL database. The company wants to minimize changes to the application code while improving scalability and reliability. Which migration strategy should the architect recommend?
Easy479A healthcare company stores PHI in BigQuery. Compliance requires that analysts see masked values for patient names and MRNs, while a small data-engineering group must see unmasked values for pipeline troubleshooting. The policy must be enforced by BigQuery itself, independent of any application code. Which approach should the architect implement?
Hard480An organization wants to enforce that all Compute Engine VMs are created with specific disk encryption keys. Which policy mechanism should they use?
Hard481An organization uses Cloud SQL for MySQL in a production environment. They need to ensure high availability with automatic failover in case of a zonal failure. Which configuration should they use?
Hard482A company wants to enforce that all API calls to GCP services from outside their corporate network come through a specific Cloud VPN tunnel. Which GCP service can enforce this policy?
Medium483A team is designing a disaster recovery plan for a critical application. They need to ensure RPO of less than 1 hour and RTO of less than 4 hours. The application runs on Compute Engine with persistent disks and uses Cloud SQL for MySQL. Which THREE actions should they take? (Choose 3.)
Medium484A company is migrating an on-premises PostgreSQL database to Cloud SQL with minimal downtime. The database is 1 TB and the network link has 500 Mbps bandwidth. Which migration approach is most appropriate?
Medium485A multinational corporation needs to ensure that data stored in Cloud Storage buckets in their Google Cloud organization cannot be accessed from outside their corporate network, even if IAM policies are misconfigured. They want to enforce this at the organization level with minimal administrative overhead. What should they do?
Hard486An IoT company ingests telemetry from 40,000 devices spread across three continents. The architecture team wants a single logical endpoint that automatically routes each device's writes to the nearest healthy Google Cloud region, and they want to avoid managing per-region DNS records or load-balancer IPs. Which design should the architect choose?
Hard487A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that the application can automatically scale based on custom metrics, such as the number of pending requests in a queue. They also want to minimize operational overhead. Which TWO actions should they take? (Choose two.)
Medium488A media company stores finished video masters in a Cloud Storage bucket. Legal requires that every object be retained for exactly seven years and that no user, including project owners, be able to delete or overwrite an object before that period ends. Which bucket configuration should the architect apply?
Easy489A developer wants to deploy a Cloud Function that is triggered whenever a new object is created in a Cloud Storage bucket. Which trigger type should they choose?
Medium490A media company streams video from a global user base. The architect must provision a load balancer that terminates TLS, routes requests by URL path to different backend services, and provides a single global anycast IP address. The backend services run on managed instance groups in three regions. Which Google Cloud load balancer should the architect deploy?
Hard491Which TWO services can be used to create a CI/CD pipeline for a containerized application on Google Cloud? (Choose 2)
Medium492A logistics company is planning a new order-tracking platform on Google Cloud. The platform must handle sudden, unpredictable spikes from holiday promotions, keep costs low during idle periods, and provide a relational store that scales reads without the team managing replication. The architect is choosing between fully managed services and self-managed alternatives. Which two design choices meet these requirements? (Choose two.)
Medium493An engineer needs to list all Compute Engine instances in a project using the command line. Which gcloud command should they use?
Easy494A development team wants to automate the process of building container images from their GitHub repository and storing them in Artifact Registry. Which Google Cloud service should they use to create a build trigger that runs on every push to the main branch?
Easy495A company is planning to migrate a large on-premises Oracle database (10 TB) to Cloud SQL for PostgreSQL. They need to minimise downtime and ensure data integrity. Which TWO services or tools should they use? (Choose TWO.)
Medium496Your company runs a multi-tier web application on Google Kubernetes Engine (GKE). The application consists of a frontend service, a backend API service, and a PostgreSQL database deployed using a StatefulSet with persistent volumes. The backend service exposes a gRPC endpoint. Recently, the team noticed that the backend service experiences intermittent high latency and occasional timeouts. The frontend service is stateless and scales well. The backend service is CPU-bound. The database is not the bottleneck. The cluster has three nodes of type n1-standard-4. The backend service is deployed with 10 replicas, each requesting 1 CPU and 2 Gi memory. Node utilization is around 70% CPU. The team suspects the network is the issue. However, after reviewing the GKE monitoring dashboard, they see that the network bytes sent/received per second for the backend pods is well below the node's network bandwidth limit. The latency spikes seem correlated with periods of high CPU throttling on the backend pods. The backend service's gRPC requests are small (under 1 KB), and the responses are also small. The team has already optimized the application code. What should the team do to reduce latency?
Hard497A company runs batch machine learning training jobs that can be interrupted. They want to reduce compute costs. Which Compute Engine VM pricing model is MOST cost-effective?
Easy498A healthcare company is designing a new patient-records API on Google Cloud. The API must serve read-heavy traffic globally with low latency, tolerate the failure of an entire region, and keep operational overhead low. The data is stored in Cloud Spanner. Which design should the architect recommend?
Hard499An application uses Cloud Bigtable and experiences high latency for reads. The row key is a timestamp prefix followed by a random ID. Queries often scan a range of timestamps for a specific ID. What design change would MOST improve read performance?
Medium500A company is migrating on-premises workloads to Google Cloud. They have a critical application that requires consistent low-latency access to a database, with read replicas in multiple regions for disaster recovery. The application is expected to grow by 10x over the next year. Which database service and configuration should the architect choose to meet these requirements?
Medium501A company wants to automatically apply security patches to Compute Engine instances running Windows Server. They need a solution that can schedule patch installations and report compliance. Which service should they use?
Easy502A healthcare analytics company must build a data platform on Google Cloud that stores patient records subject to strict privacy rules. The design must ensure that analysts can query aggregated data without being able to read individual patient identifiers, and that all access to the raw records is logged for audit. Which two design choices should the architect include? (Choose two.)
Medium503A government agency must retain Cloud Storage objects for seven years in a bucket that also serves live traffic. Regulators require that no user, including project owners, can delete or shorten retention during that period. The architect needs a control that satisfies this. Which should the architect configure?
Hard504A team is adopting a DevOps model and wants to reduce the risk of configuration drift between environments. They deploy the same application to development, staging, and production projects on Google Cloud. Which practice should they adopt to ensure consistent, repeatable deployments across all environments?
Easy505A company wants to ensure that their development teams follow best practices for cost optimization. They want to implement a process that reviews architecture decisions before deployment and provides recommendations. Which Google Cloud tool should they use to get automated cost recommendations for their existing resources?
Easy506A company is migrating to Google Cloud and needs to implement a least-privilege access model. Which THREE Google Cloud services or features support this goal? (Choose three.)
Medium507A media startup wants to give its data science team isolated environments for experimentation while keeping billing and user management under one organization. Each environment must have its own quotas and IAM boundary, and the team wants to add or remove environments quickly without renegotiating billing. Which Google Cloud resource hierarchy construct should the architect use for each environment?
Easy508An application uses Cloud SQL (PostgreSQL) and experiences high connection overhead, often exhausting the max connections limit. The team wants to maintain a pool of persistent connections without modifying application code. Which solution should they implement?
Hard509A company runs a batch analytics job every hour on BigQuery. The job processes terabytes of data and the results are stored in Cloud Storage. The job must complete within 30 minutes. Which TWO actions can reduce query execution time? (Choose 2)
Hard510Your team has deployed a microservices application on Google Kubernetes Engine (GKE) with multiple services communicating via internal ClusterIP services. You notice that some requests between services are failing intermittently with 'connection refused' errors. The services are defined with readiness probes. What is the most likely cause?
Medium511A startup is developing a real-time analytics dashboard that ingests data from IoT devices. The data volume is unpredictable but can spike to millions of events per second. The dashboard must display near real-time aggregations with sub-second latency. Which Google Cloud architecture should the architect recommend?
Medium512A company wants to automate the deployment of their infrastructure on Google Cloud using a declarative approach. They need to manage resources such as VPCs, subnets, and Compute Engine instances in a repeatable and version-controlled manner. They also want to preview changes before applying them. Which tool should they use?
Easy513An enterprise is migrating a latency-sensitive trading application from an on-premises data centre to Google Cloud. The application's components exchange hundreds of thousands of small messages per second and require sub-millisecond inter-process communication. The architect must choose a compute and networking design. What should the architect recommend?
Hard514Your organization runs a production Cloud SQL for PostgreSQL instance. You need to ensure that if the primary zone fails, the database automatically fails over to a standby with no data loss. Which configuration should you use?
Medium515You are designing a solution to store and serve static web content for a global audience. The content consists of HTML, CSS, JavaScript, and images. You need to ensure low latency and high availability. Which Google Cloud service should you use?
Easy516A healthcare company runs a regulated patient-portal application on Google Cloud. Auditors require evidence that infrastructure changes are reviewed before they reach production and that production access is limited. The platform team currently applies Terraform changes directly from engineer laptops using personal credentials. Which two practices should the team adopt to satisfy the auditors while keeping delivery efficient? (Choose two.)
Medium517Your company runs a stateful application on GKE that stores data in persistent volumes backed by Compute Engine persistent disks. You need to back up the application data and the Kubernetes resource configurations (deployments, services, etc.) for disaster recovery. Which tool should you use?
Medium518A healthcare analytics company ingests continuous streams of device telemetry that must be processed in near real time, enriched with reference data from a Cloud SQL for MySQL instance, and written into BigQuery for analyst queries. The team wants minimal operational overhead and wants to use managed Google Cloud services. Which combination should the architect select?
Medium519A healthcare company runs a multi-tenant SaaS platform on Google Cloud. Each tenant has a dedicated folder inside a single organization, with projects for each environment. A recent audit found that a compromised service account in one tenant's dev project could enumerate and read Cloud Storage buckets belonging to other tenants because the service account had been granted roles/storage.admin at the organization level by mistake. The security team wants a preventive control that blocks any future IAM binding that grants a role to a principal at a scope broader than a single project, unless the principal is part of a small break-glass group. They also want the control to apply automatically to all new projects. What should the architect implement?
Hard520A company wants to implement a disaster recovery (DR) strategy for their Cloud SQL for MySQL databases. They need to be able to recover to a specific point in time (within seconds) in case of accidental data deletion. Which TWO actions should they take? (Choose TWO.)
Medium521Your company uses Cloud Spanner in a multi-region configuration to achieve 99.999% availability. You need to understand the impact of a regional failure on read and write availability. Which statement is correct?
Hard522A retail company runs its order-processing system on Google Kubernetes Engine (GKE). The operations team wants to improve the reliability and cost efficiency of the cluster. They observe that several workloads have no resource requests or limits set, and some nodes are consistently underutilised while others are overcommitted. Which two actions should the architect recommend to address these issues? (Choose two.)
Medium523A financial services company runs a latency-sensitive trading application on Compute Engine. The operations team needs to detect performance regressions and correlate them with recent deployments without instrumenting application code. They want to use Cloud Monitoring and Cloud Logging features that work automatically for Compute Engine VMs. (Choose two.)
Hard524A finance company needs to ensure that all compute instances in their VPC can only communicate with Google APIs (e.g., Cloud Storage) over internal IPs. Additionally, instances without external IPs should be able to access the internet for updates. Which TWO configurations should they implement?
Hard525A company requires a globally distributed relational database with strong consistency across regions and automatic replication. They need to support SQL queries and have a write throughput of 100,000 writes per second. Which Google Cloud database meets these requirements?
Hard526A team wants to deploy a microservice on Cloud Run that needs to access a Cloud Memorystore for Redis instance in the same region. The Redis instance is in a VPC network. Which configuration is required for Cloud Run to reach the Redis instance?
Medium527Your organization has a policy that all Compute Engine instances must have specific labels (env, team, cost-center) applied. You want to enforce this automatically when instances are created. What should you do?
Medium528A company runs a three-tier web application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier on TCP port 8080. The company wants to enforce these requirements at the network level with minimal administrative overhead and without relying on instance-level firewall software. What should they do?
Medium529An enterprise is planning to migrate 200 on-premises VMs to Google Cloud. The CIO wants to ensure that the migration aligns with the business goal of reducing IT operational overhead by 30% while maintaining application performance. The team has already completed a technical assessment of the VMs. Which additional step should the cloud architect take to ensure the migration plan is aligned with the stated business goal?
Medium530A healthcare analytics company runs a stateless API on a regional managed instance group behind an external Application Load Balancer. The SRE team wants to improve reliability and reduce customer-visible errors during zonal and instance failures. (Choose two.)
Hard531You need to automatically roll back a GKE deployment if a new version causes a spike in 5xx errors. The deployment uses a canary strategy with Istio traffic splitting. What should you do?
Easy532Drag and drop the steps to set up a shared VPC in Google Cloud for a multi-project environment into the correct order.
Medium533Refer to the exhibit. An application running on a GCE instance (ID: 1234567890) is unable to connect to a database at 10.0.0.1:5432. The logs show repeated 'Connection refused' errors. What is the most likely cause?
Medium534A company is migrating to Google Cloud and needs to connect their on-premises network to a VPC. They require high bandwidth and a reliable connection with a Service Level Agreement (SLA). Which solution should they choose?
Easy535A healthcare organization is designing a Google Cloud environment to comply with HIPAA. They need to ensure that all access to sensitive data is logged and that only authorized personnel can access it. They plan to use Cloud Audit Logs and IAM. Which two configurations should they implement? (Choose two.)
Hard536Match each GCP storage service to its typical use case.
Medium537A company wants to use Customer-Managed Encryption Keys (CMEK) for data at rest in Cloud Storage, but also needs to ensure that the keys are stored in a hardware security module (HSM) to meet compliance requirements. Which Cloud KMS key type should they choose?
Medium538A retail company runs a public-facing API on Cloud Run in the europe-west1 region. During a marketing campaign, traffic tripled within minutes. The service remained available, but some requests returned HTTP 503 errors. The team wants to reduce the chance of 503 errors during future traffic spikes while keeping the deployment simple. What should they do?
Easy539The exhibit shows a Cloud Storage bucket IAM policy. A developer (admin@example.com) wants to upload a file to the bucket but gets a permission denied error. What is the most likely reason?
Medium540The exhibit shows a Cloud Storage bucket configuration. What does this configuration ensure?
Medium541A financial services firm runs a three-tier application on Google Cloud. The security team requires that all outbound traffic from the application tier to the internet be inspected by a centralised next-generation firewall appliance, and that the application tier have no public IP addresses. The network team wants to minimise changes to the existing VPC. Which design should the architect recommend?
Hard542A healthcare analytics company must store patient records in Cloud Storage. Compliance requires that the data be encrypted with keys the company generates and rotates itself, and that the company retain the ability to revoke access by disabling the key. The data must remain readable by authorized applications in the same project. What should the architect implement?
Medium543Refer to the exhibit. A Cloud Deploy pipeline has a release with two targets: staging and prod. The staging rollout succeeded, but the prod rollout failed with 'MANIFEST_INVALID'. What is the most likely cause of the failure?
Hard544A developer needs to pass a startup script to a Compute Engine instance during creation. Which method should be used to ensure the script runs on first boot?
Easy545A small company wants to store sensitive files in Cloud Storage and ensure they are encrypted with a key that they control and rotate automatically every 90 days. They are currently using the default encryption provided by Google Cloud. They need a solution that is easy to manage and does not require manual key rotation. What should they do?
Easy546A company deploys a microservices application on Google Kubernetes Engine (GKE). Pods in one deployment are frequently OOMKilled. The team sets memory requests and limits, but pods still crash. What is the most likely remaining cause?
Medium547A company with multiple projects must ensure that no data can be exfiltrated from a specific project's Cloud Storage buckets to unauthorized locations outside the organization. They also need to allow access only from a corporate VPN IP range. Which configuration meets these requirements?
Hard548A company wants to protect their web application hosted on Google Cloud HTTP(S) Load Balancer from common web attacks like SQL injection and cross-site scripting (XSS). Which GCP service should they use?
Easy549A Cloud Run service needs to access resources in a VPC network (e.g., a Cloud SQL instance). The service should be able to send requests to the VPC and receive responses. What is the correct configuration?
Medium550A company runs a global application that requires strong consistency across regions for financial transactions. Which database should they choose?
Medium551A company is planning a hybrid cloud architecture using Anthos to manage workloads across on-premises data centers and Google Cloud. They need to select two key components that enable consistent configuration, policy, and security across environments. Which two should they choose?
Hard552Refer to the exhibit. What is the primary benefit of the `--preemptible` flag in this command?
Easy553Your organization runs a batch analytics platform that ingests data from a Pub/Sub topic into Cloud Storage, then loads it into BigQuery using a Dataflow streaming pipeline. The pipeline must handle sudden bursty traffic during month-end reporting, and you want to minimize operational overhead while ensuring the pipeline scales automatically. Which architectural approach should you choose?
Medium554A company wants to deploy a microservice on Cloud Run that requires high throughput and low latency. The service processes requests that can spike unpredictably. The team wants to minimize cold starts and ensure availability during traffic bursts. Which combination of Cloud Run settings should they configure?
Hard555An engineering team runs workloads on Compute Engine instances in a single VPC. The security team wants the instances to reach Google APIs such as Cloud Storage and BigQuery without any traffic traversing the public internet, and without managing service account key files on disk. The architect must choose the configuration that meets both goals. Which approach should the architect recommend?
Medium556An organization is implementing a data loss prevention (DLP) strategy for Cloud Storage. They want to automatically scan new objects uploaded to a specific bucket and redact sensitive data. Which service and configuration should they use?
Medium557An organization wants to deploy a containerized microservices architecture on Google Kubernetes Engine (GKE) and minimize operational overhead. They do not need to manage the node infrastructure and are willing to accept some limitations on node configuration. Which GKE mode should they choose?
Hard558An organization wants to monitor and alert on custom application metrics from a GKE cluster. They also need to view logs in real-time and create metrics from log content. Which two GCP services should they use? (Choose two.)
Medium559A retail company operates a global e-commerce platform on Google Cloud. Their architects need to choose a load balancing solution that terminates TLS at the edge, provides a single global anycast IP address, and automatically routes users to the closest healthy backend. Which Google Cloud load balancing product should they select?
Medium560A company is migrating a monolithic application to Google Cloud. They want to minimize changes to the application code while taking advantage of Cloud Run for serverless containers. Which approach should they take?
Easy561A company runs a stateful application on a single Compute Engine instance with a persistent disk. They need to ensure that the application can recover quickly in case of a zone failure. The recovery point objective (RPO) is 5 minutes, and the recovery time objective (RTO) is 15 minutes. Which approach should they take?
Hard562A team is migrating a stateful application to GKE. The application requires persistent storage with ReadWriteMany (RWX) access across multiple pods. Which Kubernetes volume type should they use to meet this requirement on GKE?
Medium563A company is migrating a legacy application that uses a file server to GCP. The application requires a shared file system that supports the NFS protocol and can be mounted by multiple Compute Engine instances. The team also needs to use Cloud NAT to allow the instances to download updates. Which TWO services should they use? (Choose 2)
Medium564A company has a Cloud Run service that processes high-throughput requests. They want to reduce latency by keeping a baseline of warm instances always ready to handle traffic. Which Cloud Run configuration parameters should they adjust?
Medium565A healthcare company is designing a solution to ingest and process millions of patient records daily. The data must be stored in a way that supports SQL queries and also allows for real-time analytics. The company wants to minimize operational overhead and needs a fully managed, petabyte-scale data warehouse. Which Google Cloud service should the solutions architect recommend?
Hard566A company wants to store customer transaction logs for 7 years for compliance. The logs are accessed rarely but must be retrievable within 24 hours. Which storage option is most cost-effective?
Easy567A startup wants to deploy a containerized web application with zero server management and automatic scaling based on HTTP requests. They expect very low traffic initially but want to scale to thousands of requests per second without configuration changes. Which compute service is most appropriate?
Easy568A retail company is deploying a customer-facing API on Google Cloud. The API must survive the loss of an entire region with minimal data loss and must serve users in North America, Europe, and Asia with low latency. The database layer must support strongly consistent reads and writes. Which design should the architect choose for the data tier?
Medium569A company runs a streaming data pipeline using Dataflow to process real-time data and insert into BigQuery. Recently, workers are frequently failing with out-of-memory errors and the pipeline latency is increasing. What should they do to resolve the issue?
Hard570Drag and drop the steps to migrate a Compute Engine VM to a different region using a snapshot into the correct order.
Medium571What are two best practices for designing a scalable Kubernetes architecture on GKE?
Easy572A financial services firm is designing a new application on Google Cloud. The application must store sensitive customer data and comply with regulations that require encryption at rest with keys managed by the company. The company also needs to control key rotation and revocation. Which Google Cloud service should the solutions architect use to meet these requirements?
Easy573A startup is building a mobile app backend that requires real-time data synchronization across multiple users. They need a fully managed, serverless NoSQL database that scales automatically and supports offline persistence. Which database should they choose?
Easy574A company is using BigQuery for analytics and wants to optimize query costs. They have many ad-hoc queries that scan large tables. What is the best practice?
Hard575A company wants to use their existing Active Directory for authentication to Google Cloud. They need to sync user and group identities to Cloud Identity and allow users to log in with their corporate credentials. Which two services should they use together?
Medium576A company wants to enforce that only container images built and signed by their CI/CD pipeline can be deployed in their GKE cluster. Which Google Cloud service should they use?
Hard577A financial services company is designing a Google Cloud landing zone. Regulators require that production workloads be isolated from non-production workloads, that each business unit control its own billing and quotas, and that a central team enforce network and security policies across everything. The company wants to minimize the number of projects it must manage manually. Which structure should the architect propose?
Hard578A company runs a critical application on Compute Engine instances in a managed instance group (MIG) across three zones in us-central1. The application uses a Cloud Spanner database. Recently, the application experienced increased latency and timeouts during peak hours. The operations team noticed that the MIG's CPU utilization is consistently above 80% during peak hours, and the autoscaler is configured to scale based on CPU utilization with a target of 60%. However, the autoscaler is not adding new instances quickly enough, causing performance degradation. The team also observed that new instances take over 5 minutes to become healthy and serve traffic. The health check is a simple TCP check on port 8080. The application startup script downloads large configuration files from Cloud Storage. What should the team do to improve the autoscaling response time and reduce latency?
Hard579An organization has a security policy that prohibits the use of external IP addresses on Compute Engine instances to reduce attack surface. They want to enforce this policy across all new and existing projects. Which approach should they use?
Hard580A financial services company runs a three-tier web application on Compute Engine across three zones in us-central1. Their security team mandates that database traffic must never traverse the public internet, and that the database subnet must be reachable only from the application subnet. The network team has already created a custom VPC named fin-vpc with separate subnets for web, app, and db tiers. Which combination of controls should the architect implement to satisfy these requirements?
Medium581A security engineer wants to configure Identity-Aware Proxy (IAP) for an HTTPS load-balanced application to enforce zero-trust access. Users will authenticate with their Google accounts. What is the minimum set of IAM roles needed for a user to access the application behind IAP?
Medium582An organization wants to ensure that all Compute Engine instances in a project are patched with the latest security updates. They also want to enforce a custom configuration (e.g., disable root SSH login) across all instances. Which TWO Google Cloud services should they use together?
Medium583A retail company runs an e-commerce platform on GKE. The SRE team wants to measure the error budget for a service level objective (SLO) defined as the proportion of requests served with HTTP 2xx or 3xx status over a 28-day window. They need a monitoring configuration that computes the burn rate and alerts when the budget is being consumed too quickly, while avoiding noisy alerts during brief spikes. What should they do?
Medium584Which THREE actions can help reduce costs for a BigQuery workload that runs frequent, ad-hoc analytical queries on a large dataset?
Hard585A retail company runs a stateful PostgreSQL database on a Compute Engine VM in project prod-db. The database writes nightly backups to a regional Cloud Storage bucket in a separate project, backup-archive. The security team requires that the VM's service account can upload objects but must not be able to delete or overwrite existing backups. Which IAM configuration should the architect implement?
Medium586A startup is migrating its on-premises MySQL database (5 TB) to Cloud SQL. The database is mission-critical and downtime must be minimized. Which migration service should they use to reduce downtime?
Easy587A company is migrating a legacy application to Google Cloud. The application requires a shared file system that can be accessed by multiple Compute Engine instances simultaneously. The file system must be POSIX-compliant, highly available, and scalable. The company wants to minimize management overhead. Which solution should they use?
Hard588A company is using Cloud Load Balancing with backend services across multiple regions. They notice that traffic is not being evenly distributed and some backends are overloaded. Which configuration should they check?
Medium589A healthcare analytics company is designing the Google Cloud landing zone for a new HIPAA-regulated workload. The security team requires that no project in the organization can enable a public Cloud Storage bucket by accident, and that all data-at-rest in BigQuery is encrypted with keys the company rotates on its own schedule. Which two design decisions should the architect include? (Choose two.)
Medium590A media company wants to serve publicly available images and videos to a global audience with low latency. Which Google Cloud service should they primarily use?
Easy591A financial services company is migrating a monolithic Java application to Google Kubernetes Engine (GKE) for improved scalability and reliability. The application serves real-time trading data and has strict latency requirements. Post-migration, the team observes frequent pod restarts due to OutOfMemory (OOM) errors, increased latency during peak trading hours, and occasional database connection timeouts. The current setup uses a single GKE cluster with a node pool of n1-standard-4 machines, a stateless application deployed as a Deployment with resource requests and limits set to 512 Mi memory and 1 CPU. The database is a Cloud SQL PostgreSQL instance with 2 vCPUs and 7.5 GB memory, and applications connect using a hardcoded connection string. The team wants to ensure reliable operation under load and during node maintenance events. Which course of action best addresses the reliability issues?
Hard592Your team manages a service with a 99.9% uptime SLO over a 30-day window. The error budget for this period is 43 minutes. In the first week, outages consumed 30 minutes of the budget. You are planning a new release. What should you do?
Medium593A company is migrating a legacy monolithic application to Google Cloud. The application runs on a single VM and uses a local MySQL database. The goal is to minimize changes to the application code while improving availability. Which strategy should the company use?
Medium594A startup deploys a web application on Compute Engine instances behind an HTTP load balancer. They need to handle unpredictable spikes in traffic with minimal operational overhead. What is the simplest scaling approach?
Easy595A healthcare company stores sensitive patient data in Cloud Storage. They must ensure that data is encrypted at rest with a key that they manage, and that the key is automatically rotated every 90 days. They also need to be able to audit key usage. Which approach should they take?
Medium596A company wants to deploy a microservices architecture on Google Cloud. They need a service mesh to manage traffic, security, and observability across services. They also want to run workloads on both GKE and Compute Engine. Which solution should they use?
Hard597A company is migrating 500 TB of on-premises file server data to Cloud Storage. The on-premises network has a 1 Gbps link to Google Cloud, but the migration must complete within 30 days. What is the MOST cost-effective and reliable method?
Medium598An engineer wants to store a database password securely and allow a Cloud Run service to access it. Which GCP service should they use?
Easy599Your team is following an incident management process. After resolving a major incident, you are tasked with conducting a postmortem. What is the PRIMARY goal of the postmortem process in Google Cloud's recommended approach?
Hard600A company deploys a web application on Compute Engine behind an HTTP Load Balancer. They want to ensure only healthy instances receive traffic. What should they configure?
Easy601A healthcare analytics company stores sensitive patient datasets in a Cloud Storage bucket in the us-central1 region. A new regulation requires that the data never leave the United States and that access be restricted to a defined set of projects. The security team wants a guardrail that prevents any future project from reading the bucket unless it is explicitly authorized, while keeping administration simple. What should the architect implement?
Hard602A healthcare company is planning a Google Cloud landing zone for a new regulated workload. They must enforce organization-wide guardrails, centralize billing visibility, and give each business unit autonomy over its own projects. The security team needs to apply policies that cannot be overridden by project owners. Which two design choices should you recommend? (Choose two.)
Medium603A developer needs to build a serverless event-driven application that responds to Cloud Storage object uploads by processing the file and storing results in Firestore. Which compute service is the best fit?
Medium604A company needs to connect their on-premises data center to Google Cloud with a dedicated, low-latency connection that provides a Service Level Agreement (SLA) of 99.99% uptime. They anticipate high bandwidth usage (10 Gbps). Which connectivity option should they choose?
Medium605A company uses Cloud Build to deploy a Java application to Artifact Registry. They want to automatically trigger a build only when changes are pushed to the 'main' branch in their Cloud Source Repository. Which configuration should they use?
Medium606A team wants to define an SLO for a service that requires 99.9% availability over a 30-day window. They need to measure the ratio of successful requests to total requests. Which SLI should they use?
Easy607Which THREE practices are recommended for organizing projects in a Google Cloud organization?
Easy608A government agency must run sensitive analytics in BigQuery while ensuring that analysts can see aggregated results but never the raw values of specific personal data columns. Analysts use SQL and must not be able to bypass the restriction by writing their own queries. The agency also needs to record who queried which columns. Which combination should the architect use?
Hard609A company wants to improve the reliability of their microservices architecture on Google Cloud. Which TWO practices should they implement? (Choose 2)
Medium610A company wants to ensure that all access to their Cloud Storage bucket is logged for compliance purposes. Which type of audit log should they enable?
Easy611A healthcare company must store patient documents in Cloud Storage. Compliance requires that the data be encrypted with keys the company controls and that key usage be centrally audited and revocable. The architect plans to use Cloud KMS. Which two actions should the architect take to meet these requirements? (Choose two.)
Medium612A company runs a critical application on a managed instance group in a single zone. The application stores data on a zonal persistent disk. The company wants to ensure that the application can survive a zone failure with minimal data loss and automatic failover. They also want to minimize changes to the application. Which approach should they take?
Hard613A company is deploying a multi-tenant SaaS application on GKE. Each tenant's data must be isolated at the network level. They want to use a single GKE cluster but ensure that pods from different tenants cannot communicate with each other. Which GCP feature should they use?
Hard614A company runs a microservices-based application on Google Kubernetes Engine (GKE) with a Regional cluster. They want to improve reliability by implementing best practices for pod scheduling and resilience. Which TWO actions should they take? (Choose two.)
Hard615A financial services firm is designing a new analytics platform on Google Cloud. Regulatory requirements mandate that data must never be replicated or processed outside the European Union, and the company wants to prevent accidental resource creation in non-EU regions regardless of which engineer is deploying. Which mechanism should the architect use to enforce this constraint?
Easy616A company needs to store archival data that is accessed less than once a year, with retrieval times of up to 12 hours acceptable. The data must be kept for 10 years for compliance. What is the most cost-effective Cloud Storage solution?
Hard617A startup wants to encrypt data at rest in Cloud Storage using Customer-Managed Encryption Keys (CMEK). They have already created a Cloud KMS key ring and key. What additional step is required to enable CMEK for a new Cloud Storage bucket?
Easy618A company is deploying a new microservices application on Google Kubernetes Engine (GKE). They need to ensure that each microservice can be independently scaled and updated without affecting other services. They also want to minimize the blast radius of a failure in one microservice. Which design approach should they use?
Medium619A company uses Cloud KMS with CMEK to encrypt data stored in BigQuery. They need to audit who has used the encryption key and when. Which type of audit log should they enable?
Hard620Which GCP service should be used to automatically scale a GKE cluster's number of nodes based on pending pods?
Easy621Which THREE are valid methods to connect an on-premises network to a Google Cloud VPC?
Medium622A company runs a public-facing web application on Compute Engine instances behind an external HTTP(S) load balancer. They want to protect the application from common web attacks such as SQL injection and cross-site scripting, and they also want to restrict access to known IP ranges. Which Google Cloud service should they use?
Medium623A multinational corporation operates in multiple regions and must comply with GDPR. They use Cloud Load Balancing to distribute traffic across regional backends. Their security team wants to block traffic from specific countries (e.g., non-EU countries) at the edge. What should they use?
Hard624A company runs a web application on Compute Engine with an HTTP Load Balancer. Users report intermittent 502 Bad Gateway errors. What is the most likely cause?
Medium625A media company is preparing to migrate a batch reporting application to Google Cloud. The application currently runs on physical servers that are used at about 20 percent CPU on average, but it has two short month-end peaks each quarter when utilization reaches 90 percent for about six hours. The company wants to reduce infrastructure cost while guaranteeing the application always has enough capacity during the peaks. What should the architect recommend?
Easy626Your company has migrated its legacy web application from a single Compute Engine instance to a managed instance group (MIG) behind an HTTP(S) load balancer. The application was updated to a new version as part of the migration. After the migration, users report intermittent 502 Bad Gateway errors. The application logs show no errors, and the load balancer backend health checks are reported as healthy. On investigation, the developers discover that the new version requires a specific environment variable for authentication to a downstream service. This variable was set manually on the original instance but is missing from the MIG's instance template. The health check endpoint does not depend on this variable and always returns a 200 status even when the variable is absent. As a result, instances created from the template are considered healthy by the load balancer, but when they receive requests that require authentication, they fail and return a 502 error to the client. What is the most likely cause of the 502 errors?
Easy627A company wants to implement a zero-trust access model for internal web applications running on Compute Engine. They need to authenticate users using corporate credentials and enforce context-aware access based on device posture and IP address. Which TWO services should they use?
Medium628Your company runs a global e-commerce platform on Google Cloud. The application is deployed across multiple regions for low latency. You use Cloud SQL for transactional data and Cloud Spanner for global consistency of inventory. Recently, the operations team reported that the application is experiencing increased latency during peak hours, and the monthly cloud bill has risen significantly. Upon investigation, you find that the Cloud SQL instance is underutilized (CPU < 20%) while Cloud Spanner split utilization is over 80%. The application instances are fronted by a global external HTTPS load balancer. Network egress costs are high. Which course of action would best address both the latency and cost issues?
Easy629You need to create a Cloud Logging sink that exports logs to a BigQuery dataset for long-term analysis. Which destination type should you specify?
Easy630A financial services firm stores sensitive customer records in Cloud Storage and must ensure that only identities in its corporate domain can read the objects, that no object can ever be made publicly accessible, and that access decisions are evaluated centrally. The firm wants the least administrative overhead while keeping these guarantees across many buckets created by different teams. What should the architect implement?
Hard631A financial services company runs a payment processing platform on Compute Engine. Compliance requires that all data at rest be encrypted with keys the company controls and that key material never leave their on-premises HSM appliances. They must also minimize operational overhead for key rotation. Which Google Cloud solution should the architect recommend?
Medium632A company runs a batch processing application on Compute Engine that reads data from Cloud Storage and writes results to BigQuery. The application runs on a managed instance group (MIG) with autoscaling. Recently, job failures occurred because instances could not authenticate to BigQuery. You need to ensure that the instances have the necessary permissions without embedding credentials in the application. What should you do?
Hard633Your organization wants to use Cloud SQL for a MySQL database with automatic failover in the event of a zone outage. Which configuration should you choose?
Easy634An organization needs to comply with FedRAMP requirements and restrict data storage to specific regions. They also need to audit all admin activities and data access. Which three components should they implement? (Choose three.)
Hard635A healthcare company stores protected health information in Cloud Storage and BigQuery. Compliance requires that access to this data be auditable and that no single administrator can both modify data and erase the audit trail. The security architect is designing the logging and access model. Which two actions should the architect take? (Choose two.)
Medium636Match each GCP security service to its function.
Medium637A company has a global web application deployed across multiple regions. They use an external HTTPS Load Balancer with backend services in us-central1 and europe-west1. They want users to be routed to the closest healthy backend. Which load balancing configuration is required?
Hard638An organization needs to run a stateful application on Google Kubernetes Engine (GKE) where the nodes are fully managed by Google and the application workload SLAs are guaranteed. They want to minimize operational overhead. Which GKE mode should they use?
Medium639You want to monitor the latency of an application running on Compute Engine and create an alert if the 99th percentile latency exceeds 500ms for more than 5 minutes. Which approach should you use?
Medium640A company wants to enforce that all secrets used by applications running on Compute Engine are rotated automatically every 30 days. Which GCP service should they use to store and manage these secrets?
Medium641A team manages a GKE cluster with node pools using different machine types. They plan to upgrade the cluster to a new Kubernetes version. What is the safest upgrade strategy to minimize application downtime?
Medium642A company has a multi-region deployment of App Engine and wants to optimize request routing for latency and cost. Which GCP service should they use?
Hard643Refer to the exhibit. A user reports that the instance 'batch-vm' is unavailable. Based on the output, what is the most likely cause of the unavailability?
Medium644A financial services company runs a containerized trading platform on Google Kubernetes Engine (GKE). Compliance requires that all inter-pod traffic be encrypted without modifying application code, and that the encryption keys be managed by the company rather than Google. The security team wants to enforce this at the infrastructure level. Which approach should they take?
Medium645A company runs a stateful application on GKE that requires persistent storage. They want to ensure that during cluster upgrades, pods are not disrupted and storage is preserved. Which configuration should they use?
Medium646A retail company is designing a new microservices architecture on Google Cloud. They want to minimize operational overhead, enable independent deployment of services, and ensure that a failure in one service does not cascade to others. They also want to use managed services where possible. Which two design choices should the architect recommend? (Choose two.)
Medium647A startup is deploying a new containerized web application to Google Cloud. The team wants the simplest way to run containers without managing Kubernetes nodes, needs automatic scaling from zero, and wants to pay only when requests are being handled. Which Google Cloud service should the architect recommend?
Easy648A team wants to provide a consistent, low-latency experience for global users accessing static content (images, CSS, JS) hosted on Cloud Storage. They also need to be able to invalidate cached content quickly when updates occur. Which service should they use?
Medium649A company is designing a VPC Service Controls perimeter to protect data stored in Google Cloud. They need to allow access from their on-premises network via a Cloud VPN tunnel while blocking all internet-based access. What is the most secure and manageable approach?
Medium650A startup is deploying a new web application on Google Cloud. They want to ensure that their development, staging, and production environments are isolated from each other for security and billing purposes. They also want to apply different IAM policies per environment. Which Google Cloud resource hierarchy structure should the architect recommend?
Easy651A company runs a batch processing job that uses preemptible VMs. The job occasionally fails due to VM preemption. They want to improve reliability without significantly increasing cost. Which TWO actions should they take? (Choose TWO.)
Easy652A company is moving a legacy application to Compute Engine. The application has inconsistent resource usage and the team wants to optimise costs without performance degradation. They are evaluating committed use discounts (CUDs) and other discount types. Which THREE statements are correct about CUDs? (Choose 3)
Hard653A team is migrating a monolithic application to microservices on GKE. They want to gradually shift users to the new microservices version while keeping the old monolithic version running. They need to route a small percentage of users based on a cookie. Which traffic management approach should they use?
Medium654A company runs a stateful application on Compute Engine with persistent disks. They want to ensure data durability across a zone failure. What is the best approach?
Hard655A company uses Cloud Bigtable for time-series data. They experience high latency and uneven load distribution across nodes. What is the most likely cause?
Hard656A company is migrating its on-premises data warehouse to BigQuery. They want to minimize the cost of storing large amounts of historical data that is rarely queried. The data must remain available for queries but can tolerate slightly longer query times. What should they do?
Easy657A company runs multiple microservices on Cloud Run. Each service uses a Serverless VPC Access connector to connect to a shared Cloud Memorystore for Redis instance (standard tier) in a VPC network. The Redis instance is configured with a firewall rule that allows TCP connections on port 6379 from the VPC connector's subnet (10.8.0.0/28). After a recent code update, the order-service fails to connect to Redis, while the user-service continues to work. The error logs in order-service show 'connection refused'. The engineer verifies that both services use the same VPC connector, the same Redis instance IP, and the same service account. The VPC connector's metrics show no errors. What is the most likely cause?
Hard658A data engineer needs to analyze data in BigQuery but must mask personally identifiable information (PII) based on user roles. Which service should they use?
Medium659A developer is writing a Cloud Function that processes files uploaded to a Cloud Storage bucket. Which trigger should they use?
Easy660Your organization is implementing a Disaster Recovery plan for a critical database. Which THREE components are essential for a robust DR strategy? (Choose 3)
Medium661A startup runs a public API on Compute Engine behind an external HTTP(S) load balancer. The security team wants to block common web attacks such as SQL injection and cross-site scripting at the edge, with minimal changes to the application, and they want the protection rules to be managed centrally and updated as new signatures are released. What should the architect recommend?
Easy662A startup wants to deploy a containerized web application that must scale automatically based on incoming request concurrency. The team wants to avoid managing Kubernetes nodes or clusters and prefers a fully managed serverless platform with per-request billing. Which Google Cloud service should the architect recommend?
Easy663Which Google Cloud service allows organizations to define perimeters that protect resources and data from exfiltration to other VPCs or networks?
Easy664A healthcare company stores patient records in a Cloud Storage bucket. Compliance requires that all data be encrypted with customer-managed keys, and that the company can revoke access to the data by disabling the key. They also need to audit every key usage. Which approach should they take?
Hard665An organization is migrating a legacy monolithic application to Google Cloud. The application currently runs on a single server with an on-premises database. The application is stateful and requires low-latency access to the database. The migration must minimize downtime and ensure high availability. Which architecture should the company adopt?
Hard666A company is designing a hybrid cloud architecture where on-premises applications need to access data stored in a Cloud Storage bucket. The company requires that traffic between on-premises and Google Cloud does not traverse the public internet and must be encrypted. They also need dedicated bandwidth. Which Google Cloud service should the solutions architect use?
Medium667A company is deploying a critical application on GKE and wants to ensure high availability during node upgrades and failures. Which TWO configurations should they implement? (Choose 2.)
Medium668A small development team is prototyping a containerized application on Google Cloud. They want the least operational overhead for running containers, automatic scaling based on incoming requests, and the ability to scale to zero when there is no traffic. They do not need Kubernetes APIs or custom networking. Which compute option should the architect recommend?
Easy669A company has Compute Engine instances in us-east1-a and us-east1-b zones. They want to allow communication between these instances with minimal latency and no additional cost. What is the best networking approach?
Medium670A company runs a critical application on Compute Engine instances in a managed instance group (MIG) with autoscaling. During a traffic spike, some instances become unhealthy but are not automatically replaced. What is the most likely cause?
Medium671A company is moving a legacy monolithic application to a microservices architecture on Google Cloud. They want to minimize operational overhead and automatically scale each service independently. Which TWO compute services should they consider? (Choose two.)
Medium672A company wants to improve the performance of their Cloud SQL for PostgreSQL instance. They notice many idle connections and slow queries. Which THREE actions could help? (Choose 3)
Medium673A healthcare company stores patient documents in Cloud Storage. Compliance requires that documents be retained for seven years and that no user, including administrators, can delete or overwrite them during that period. The company wants the simplest configuration that enforces this. What should the architect implement?
Easy674Which THREE options are valid strategies for disaster recovery (DR) in Google Cloud?
Hard675A retail company is building a new application on Google Cloud. The security team requires that all data at rest be encrypted with keys the company manages, that key usage be auditable, and that the application on Compute Engine never store long-lived credentials on disk. The architect is selecting controls for the design. (Choose two.)
Medium676A security team wants to receive alerts when a user attempts to grant the 'roles/owner' role to a member outside of the organization's domain. Which log filter should they use to create a log-based metric?
Easy677Your company is designing a new application on Google Cloud. The security team requires that all data at rest be encrypted with customer-managed encryption keys (CMEK) and that access to these keys be audited. You need to implement a solution that meets these requirements. (Choose two.)
Medium678A company is designing a disaster recovery strategy for a critical application running on Compute Engine with a regional managed instance group (MIG) and an HTTP load balancer. They require an RTO of 10 minutes and RPO of 1 hour. The application state is stored in Cloud SQL for PostgreSQL. What is the most cost-effective approach?
Hard679A retail company runs a monolithic Java application on Compute Engine instances in a single managed instance group behind an external Application Load Balancer. During a flash sale, the application becomes unresponsive, and the operations team observes that the CPU utilization of all instances reaches 100%. The team wants to ensure that the application remains available during similar events. They need a solution that automatically adjusts capacity based on demand and minimizes manual intervention. Which approach should they take?
Medium680An e-commerce company runs its order-processing service on Cloud Run. During flash sales, the service experiences sudden traffic spikes, and the operations team observes that new instances take too long to start, causing elevated latency and some request failures. The service has a large container image and initializes database connection pools at startup. Which configuration change should the team make to reduce cold-start impact while controlling cost?
Hard681A retail company runs a legacy order-processing system on a single Compute Engine VM with a local SSD. The system is business-critical and must be migrated to Google Cloud with minimal downtime and no data loss. The database is PostgreSQL, and the company wants to move to a managed service. The cutover window is only 30 minutes. Which migration approach should the architect recommend?
Hard682A financial services firm is deploying a three-tier application on Google Cloud. The web tier runs on managed instance groups behind an external HTTP(S) load balancer, the application tier runs on GKE, and the database tier runs on Cloud SQL. Security requires that the database tier accept connections only from the application tier and that no component be reachable from the public internet except the web tier. The architect must design the network and firewall configuration. (Choose two.)
Hard683A financial services company is designing a hybrid cloud architecture. They have an on-premises data center and want to extend their VPC network to Google Cloud. They require a dedicated, high-bandwidth, low-latency connection with a SLA, and they need to encrypt traffic in transit. They also want to avoid using the public internet. Which connectivity option should they choose?
Medium684What is the purpose of a Pod Disruption Budget (PDB) in GKE?
Easy685A multinational corporation must comply with GDPR and requires that all customer data stored in BigQuery be encrypted using customer-managed encryption keys (CMEK) and that the keys are stored in a specific region. Which combination of steps should they take?
Hard686An organization is migrating a MySQL database to Cloud SQL. They require automatic failover with zero data loss in the event of a zone outage. Which configuration should they use?
Medium687A healthcare company stores patient records in Cloud Storage buckets across several projects. Compliance auditors require that no object can ever be made publicly readable, even by a project Owner, and that any attempt to do so must be blocked centrally. The security team must enforce this without breaking existing application access. What should they do?
Medium688A company is designing a VPC architecture for a multi-tenant SaaS platform. Each tenant has isolated workloads that must not communicate with each other. They also need centralized network security and logging. Which VPC design meets these requirements?
Hard689A company runs a critical application on Compute Engine instances in a managed instance group (MIG) with autoscaling. Users report intermittent 503 errors during traffic spikes. Which action should the company take to improve reliability?
Easy690A company is building a web application on GKE. They want to automatically scale the number of pods based on HTTP request rate. Which TWO resources should they configure?
Easy691Your organization requires that all production changes to Google Cloud resources be auditable and that you can identify who made a change and when. You need to configure logging to meet this requirement. What should you do?
Easy692A company is using Cloud Storage for backups and wants to minimize costs. The backups are accessed infrequently and can tolerate retrieval delays. Which storage class is most appropriate?
Easy693An e-commerce company exposes a public API through an external HTTP(S) load balancer on Google Cloud. The security team wants to block traffic from known malicious IP ranges and apply rate limiting per client IP, while keeping legitimate customers unaffected. They want the least operational overhead and no changes to backend applications. What should they do?
Medium694A company is migrating sensitive customer data to Google Cloud. They need to ensure data is encrypted at rest and in transit. Which Google Cloud service provides a centralized way to manage encryption keys used by Google Cloud services?
Easy695Which TWO are required to allow on-premises hosts to access Google APIs using internal IP addresses (Private Google Access)? (Choose 2)
Medium696A company wants to store backup data that is accessed rarely but must be available for retrieval within minutes. Which Cloud Storage class is appropriate?
Easy697A company wants to run a legacy application on Google Cloud that requires a specific operating system version and kernel tuning. The application is not containerised and cannot be easily modified. Which compute service should they use?
Easy698Refer to the exhibit. An engineer deploys this Terraform configuration. After deployment, they can SSH into the VM using its public IP. However, they want to restrict SSH access to only a specific IP range (203.0.113.0/24). What change is required?
Medium699A retail company runs a stateful batch application on a managed instance group. The application writes intermediate results to the boot disk of each VM and takes several hours to complete. The operations team wants rolling updates that replace instances with a new image, but must guarantee that no in-flight job is interrupted. Which configuration should you recommend?
Hard700An e-commerce company uses Cloud SQL for MySQL for their transactional database. During a recent load test, the database experienced high latency under write-heavy workloads. The team needs to improve write performance without changing the application. Which action is most effective?
Medium701A DevOps team is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that the pods can securely access Google Cloud APIs (e.g., Cloud Storage) without managing service account keys. Which TWO steps should they take? (Choose two.)
Easy702A security admin wants to audit all 'create' and 'delete' operations on Compute Engine instances in a project for the last 90 days. Which type of audit log should they query?
Medium703Refer to the exhibit. An engineer deployed this Terraform configuration and can SSH to the instance using the external IP. However, they notice that the instance has a public IP address even though they intended to have no public IP. What change should be made to the configuration to ensure the instance does not get a public IP?
Medium704A company runs a large-scale data processing pipeline using Dataflow with streaming data from Pub/Sub. They notice increasing costs due to high data shuffle operations. They want to optimize the pipeline performance and cost. Which approach should they take?
Hard705A security team wants to enforce that only container images signed by their internal CI/CD pipeline can run on GKE clusters. They also need to ensure that unsigned images are rejected at admission time. Which combination of services and configurations should they use?
Hard706A company is using Cloud Storage to store sensitive data. They need to enforce that objects are deleted exactly 30 days after creation. Which object lifecycle rule should they configure?
Hard707An organization wants to monitor network traffic between VMs in a VPC for troubleshooting. Which TWO services can provide this?
Medium708Your company uses Cloud VPN (HA VPN) to connect to Google Cloud. You need to achieve a 99.99% SLA for the VPN connection. What configuration is required?
Medium709A company needs to protect an HTTPS load-balanced web application from OWASP Top 10 attacks, including SQL injection and cross-site scripting. Which GCP service should they enable?
Medium710A developer wants to deploy a stateless web application that automatically scales based on HTTP traffic. The application should be cost-effective and require minimal configuration. Which compute option is best?
Easy711A financial services company runs workloads on GKE and wants to ensure only container images that have been approved by the security team can be deployed. The approval process involves signing images after vulnerability scanning. Which GCP service should be integrated with GKE to enforce this policy?
Hard712Your organization runs a critical application on Google Cloud that uses Cloud SQL for PostgreSQL. The database is in us-central1. The business requires a recovery point objective (RPO) of 5 minutes and a recovery time objective (RTO) of 1 hour in case of a regional failure. What should you do?
Hard713A financial services company stores regulated data in BigQuery datasets. Auditors require that all data access be logged with the identity of the user, the query text, and the timestamp, and that logs be retained for 365 days and be immutable. The security team wants to use Google Cloud-native tools with minimal operational overhead. What should they implement?
Hard714A financial services company runs a high-volume transaction processing system on Google Cloud. They need to ensure that the system can handle sudden spikes in traffic during market open and close. The system uses a managed instance group of Compute Engine VMs behind a load balancer. They want to optimize costs while maintaining performance during peak hours. Which approach should the architect recommend?
Hard715You are responsible for incident management for a production service. You want to reduce manual toil during the initial response to common issues like high latency. What is the best approach?
Hard716A cloud architect is designing a CI/CD pipeline for a microservices application. Each service is deployed to Cloud Run. They want to use Cloud Build to automate building and deploying services only when changes occur in their respective directories. Which Cloud Build feature should they configure?
Medium717A company is designing a microservices architecture on Google Kubernetes Engine (GKE) for a global user base. They require high availability across multiple zones, automatic scaling, and rolling updates without downtime. Which Kubernetes workload resource should they use for each service?
Medium718A company is designing a highly available web application on Google Cloud. The application consists of stateless compute instances behind a global HTTP(S) Load Balancer. The compute instances must be able to handle sudden spikes in traffic. Which TWO strategies should the company implement? (Choose two.)
Hard719A company wants to automatically move data from Cloud Storage Standard to Nearline after 30 days and to Archive after 90 days. Which approach should they use?
Medium720Your organization uses Cloud Spanner for a customer database with a 99.999% availability SLA. You need a Disaster Recovery plan that ensures data consistency with zero RPO in case of a region failure. What should you do?
Medium721Drag and drop the steps to configure a Cloud Load Balancer with a backend service consisting of Compute Engine instances into the correct order.
Medium722An organization wants to receive alerts when their Cloud SQL instance's CPU utilization exceeds 80% for 5 minutes. They want to send the alert to both email and a Pub/Sub topic for further processing. What should they do?
Medium723A developer needs to deploy a containerized application on Google Kubernetes Engine (GKE) with minimal operational overhead. They want to automatically scale the number of pods based on CPU utilization. Which GKE feature should they use?
Easy724A retail company runs a customer-facing API on a managed instance group (MIG) of Compute Engine VMs behind an external Application Load Balancer. The SRE team wants the load balancer to stop sending traffic to a VM as soon as the local application health endpoint starts returning HTTP 500, even before the VM is fully unresponsive. Which load balancer component must be configured to achieve this?
Medium725A company uses BigQuery for analytics. They have a large partitioned table that is queried frequently. The query performance has degraded over time. Which optimization should they try first?
Medium726A developer needs to deploy a stateful application that requires persistent storage across pod restarts in Google Kubernetes Engine. Which resource should they use?
Easy727A global e-commerce site uses an external HTTPS load balancer with a backend service pointing to a managed instance group. Some users report 503 errors during peak traffic. The backend instances are healthy and not overloaded. What is the most likely cause?
Hard728A team wants to collect and analyze logs from multiple projects into a centralized BigQuery dataset for long-term retention and SQL querying. They want to exclude health check logs to reduce costs. Which approach should they use?
Medium729A company wants to minimize egress costs for data transferred between Compute Engine instances in the same region but different zones. What is the best practice?
Easy730A retail company runs its order-processing platform on Compute Engine instances in a single managed instance group (MIG) spread across three zones in us-central1. During seasonal peaks, the application must handle up to 10x normal traffic while keeping median request latency under 200 ms. The architecture team wants to add a caching layer that can absorb repeated catalogue reads and survive the loss of an entire zone without manual intervention. Which design should they choose?
Medium731Your company runs a microservices application on GKE. The development team wants to adopt a progressive delivery strategy to reduce the risk of new releases. They need to route a small percentage of production traffic to a new version, monitor key metrics, and automatically roll back if errors increase. Which approach should you recommend?
Hard732A data engineering team wants to ingest streaming data from Pub/Sub, transform it using Apache Beam, and load it into BigQuery for real-time analytics. They need a fully managed solution that handles autoscaling and does not require managing servers. Which TWO Google Cloud services should they use?
Medium733A multinational corporation needs to comply with data residency requirements for EU customer data. They want to ensure that data stored in Cloud Storage, BigQuery, and Cloud SQL for EU customers never leaves the European Union, even by administrators. They also want to detect and remediate any configuration drift that could violate this policy. What should they implement?
Hard734You are responsible for a Cloud Run service that experiences occasional cold starts, causing increased latency. You want to minimize cold starts while keeping costs under control. What should you do?
Medium735A global e-commerce company is designing its application architecture on Google Cloud. The application must serve users from multiple regions with low latency and must be able to fail over between regions automatically in case of a regional outage. The company wants to minimize operational overhead and ensure that the database layer supports multi-region writes with strong consistency. Which database solution should they choose?
Hard736A media company uses a multi-project Google Cloud organization. They want to optimize their cloud spend across all projects without sacrificing performance or reliability. They have already implemented committed use discounts for Compute Engine. Which two additional actions should the architect recommend to reduce costs? (Choose two.)
Medium737A company has a Cloud SQL for MySQL instance with automated backups enabled. They need to recover the database to a specific point in time within the last hour. Which feature should they use?
Medium738An organization requires that all container images deployed to GKE be signed and verified before deployment. Which GCP service should be used?
Medium739A company runs a high-traffic web application on Google Kubernetes Engine (GKE). The application uses a Cloud SQL for MySQL instance as its backend. The operations team wants to optimize the cost of the GKE cluster and the Cloud SQL instance without sacrificing performance or availability. Which two actions should they take? (Choose two.)
Medium740A logistics company runs a batch route-optimization job that reads 50 TB from Cloud Storage, performs CPU-intensive computation, and writes results back to Cloud Storage. The job runs for about four hours each night and must finish before the morning dispatch window. The team wants the lowest cost while guaranteeing completion within the window. Which compute design should the architect choose?
Hard741A retail company is planning a Google Cloud organization structure for a new e-commerce platform. They want to isolate production from non-production, allow central network and security teams to apply guardrails across all projects, and give application teams self-service within their own boundaries. Which two design choices support these goals? (Choose two.)
Medium742A startup wants to run a containerized web application that scales to zero when not in use and charges only for request processing time. Which compute service is most appropriate?
Easy743Your organization is adopting Google Cloud and wants to establish a cost governance framework. You need to implement mechanisms that provide visibility into spending and allow proactive control over costs. (Choose two.)
Medium744An organization uses Cloud Storage to store critical documents. They want to protect against accidental deletion or overwriting of objects. Which feature should they enable?
Medium745A company wants to migrate a MySQL database running on-premises to Cloud SQL with minimal downtime. Which GCP service should they use?
Easy746A company wants to restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read. Which approach should they use?
Medium747A company is building a microservices architecture on Google Kubernetes Engine (GKE) and needs to ensure each microservice can only access specific Cloud Storage buckets. IAM permissions should be assigned at the pod level, not at the node level. What is the recommended approach?
Medium748Your company has a production Cloud SQL for PostgreSQL instance in us-central1 with automated backups enabled. You need to ensure that if the zone fails, the database automatically fails over to a standby in a different zone with minimal downtime. What should you do?
Medium749A retail company runs a Java-based order service on Compute Engine. The service currently reads its database credentials from a plaintext file on the boot disk. A security review requires that the credentials be removed from disk, be automatically rotated every 30 days, and be retrievable by the application through a single API call. You want the least operational overhead. What should you do?
Medium750A multinational e-commerce company needs a globally distributed database that provides strong consistency and transactional support for order processing. Which Google Cloud database service should they use?
Easy751A company uses Cloud Deploy for continuous delivery. They have a delivery pipeline with multiple targets: dev, staging, and prod. They want to require manual approval before deploying to prod. How should they configure this?
Medium752Your company has a complex legacy application that runs on a single large VM. The application is stateful and has a monolithic architecture. You are tasked with migrating it to Google Cloud with minimal changes, but you also want to improve its reliability and scalability over time. Which migration strategy should you initially recommend?
Medium753An administrator is configuring firewall rules in a VPC. Two rules apply to the same traffic: rule 1 allows ingress from 0.0.0.0/0 on TCP 80, rule 2 denies ingress from 10.0.0.0/8 on TCP 80. Rule 1 has priority 1000, rule 2 has priority 500. What is the effective behavior for traffic from 10.0.0.1?
Easy754You are investigating a Vertex AI Workbench instance (instance-2) that is showing UNHEALTHY status. Based on the exhibit, what is the most likely cause of the issue?
Hard755A company wants to control which resources can be accessed by a service account in a specific project. Which IAM policy binding approach should be used?
Easy756A company is designing a highly available architecture for a stateful application on Compute Engine. They need to protect against zonal failures. Which THREE steps should they take?
Hard757A developer is trying to deploy a Compute Engine instance from a Cloud Build step. The build fails with the above error. What is the problem?
Easy758A developer needs to grant a Compute Engine instance the ability to read from a Cloud Storage bucket. The instance does not have a service account attached. What should the developer do?
Easy759Your team operates a production e-commerce application on a managed instance group (MIG) that serves traffic through a global external Application Load Balancer. During a new release, the team wants to deploy the new version to a small subset of instances and then progressively increase traffic to it while monitoring error rates, with the ability to immediately roll back if errors spike. The new version is already built as a custom image. Which approach should you use?
Medium760An analytics team runs a batch pipeline that reads several terabytes of data from a Cloud Storage bucket in us-central1 every night. To reduce egress and improve throughput, they decide to run the pipeline on Compute Engine VMs in the same region and want the traffic to stay on Google's internal network without traversing the public internet. They also want the VMs to reach Google APIs such as Cloud Storage and BigQuery. Which configuration should the architect recommend?
Hard761Which THREE Google Cloud services can be used to implement a zero-trust architecture for network security? (Choose three.)
Hard762A company is designing a disaster recovery strategy for a Cloud SQL for PostgreSQL database with a Recovery Point Objective (RPO) of 1 hour and a Recovery Time Objective (RTO) of 2 hours. They are using the Regional Cloud SQL tier. Which TWO actions should they take? (Choose TWO.)
Medium763A service account needs to be able to start and stop Compute Engine instances in a specific project. Which IAM role should be assigned at the project level?
Easy764A development team uses BigQuery for analytical queries. They want to reduce query costs for a large table that is frequently filtered by a date column and a customer_id column. Which TWO table design strategies will reduce the amount of data scanned? (Choose 2)
Easy765A logistics company is deploying a new three-tier application on Google Cloud. The architecture team must choose a managed database for the order-processing tier that provides automatic failover across zones with no application connection string changes, and they must also ensure that the database can scale read traffic independently of writes. (Choose two.)
Medium766Your company wants to implement a canary deployment for a microservice running on GKE. You need to gradually shift traffic from the stable version to the canary version while monitoring error rates. Which THREE components or practices should you use? (Choose 3)
Hard767A company stores sensitive data in Cloud Storage and wants to enforce encryption at rest using customer-managed keys. Which Google Cloud service should they use to manage the keys?
Easy768An organization wants to export their Cloud Logging logs to a centralized BigQuery dataset for long-term analysis. They also need to exclude logs from a specific source (e.g., a test project) to reduce costs. How should they set this up?
Hard769Your organization runs a microservices application on Google Kubernetes Engine (GKE). You need to ensure that the application can be rolled back quickly if a new deployment causes errors. You want to use a deployment strategy that allows you to shift traffic back to the previous version with minimal downtime. Which approach should you use?
Medium770An application running on Compute Engine frequently makes connection requests to a Cloud SQL for PostgreSQL instance. The connections are short-lived and many are created per second. What should be implemented to reduce latency and connection overhead?
Medium771An e-commerce platform uses Cloud Spanner for order processing. Recently, latency spikes have occurred during flash sales. The team suspects hot spots due to monotonically increasing order IDs. Which table design change would best solve this?
Hard772An e-commerce application uses Firestore for product catalog. They need to run complex analytical queries on the catalog data, such as aggregations and joins, without impacting production performance. What is the best approach?
Medium773Your company is designing a secure architecture for a new application on Google Cloud. They need to ensure that service accounts used by the application have only the necessary permissions, and that any use of those service accounts is auditable. Which two actions should they take? (Choose two.)
Hard774A company uses Cloud Logging to monitor their application logs. They notice that some logs from their Compute Engine instances are missing. The instances have the required logging permission. What is the most likely cause?
Medium775A cloud architect needs to implement a CI/CD pipeline for a team developing a Python-based microservice. The team uses GitHub as their source repository. The pipeline should automatically run unit tests and deploy the service to Cloud Run when changes are pushed to the main branch. Which THREE Google Cloud services should they use?
Easy776An organization runs workloads in multiple Google Cloud projects and wants a single, consistent way to detect and respond to threats such as compromised service accounts and anomalous API calls across all of them. The security operations team needs findings aggregated in one place and wants to reduce the effort of correlating events from Cloud Audit Logs, VPC Flow Logs, and Cloud DNS logs. Which Google Cloud service should the architect recommend?
Hard777A company uses Cloud Deployment Manager to manage infrastructure. They want to roll back to a previous deployment state after a failed update. What is the recommended approach?
Medium778A company wants to migrate on-premises workloads to Google Cloud. They need to assess the existing infrastructure, plan the migration, and track progress. Which tool should they use?
Medium779An organization deploys a web application on Compute Engine behind a global HTTPS load balancer. They want to reduce latency for users worldwide and minimize load on backend instances. Which GCP service should they use?
Medium780An e-commerce company uses Cloud SQL for MySQL for its transactional database. They need to run complex analytical queries on the same data without impacting OLTP performance. The analytical queries should be run on a read replica with minimal lag. Which solution is BEST?
Medium781A company is migrating a 200 TB on-premises file server to Cloud Storage. The network bandwidth is limited to 100 Mbps. The migration must complete within 30 days. Which approach should they use?
Medium782A media company is designing a hybrid architecture that connects its on-premises data center to a Google Cloud VPC. The company needs high-bandwidth, low-latency, private connectivity that does not traverse the public internet, and it wants redundancy so that a single link failure does not interrupt traffic. The architect is evaluating interconnect options. Which two characteristics apply to Dedicated Interconnect in this scenario? (Choose two.)
Hard783A security engineer wants to ensure that all admin activity in their GCP organization is logged and retained for 3 years. They also need to be alerted if a new firewall rule is created. Which logs should they enable?
Medium784A web application running on Compute Engine behind a global HTTP(S) load balancer experiences high latency during traffic spikes. Which quick fix would best address this issue without changing the architecture?
Medium785A company is adopting Site Reliability Engineering (SRE) practices. After a major incident, they want to conduct a review to understand what went wrong and how to prevent recurrence, without blaming individuals. Which SRE practice should they follow?
Easy786A media company runs a batch transcoding pipeline on Google Kubernetes Engine. Jobs read input from a Cloud Storage bucket and write output to a second bucket. The team wants the pipeline to keep processing through transient Cloud Storage 429 and 503 errors without losing work, and they want the pods to stop being killed mid-job during node upgrades. Which combination should the architect implement?
Medium787A company needs to ensure that only approved container images can be deployed to a GKE cluster. They already use Binary Authorization. What additional step is required to enforce this policy?
Medium788A company wants to run a containerized web application that experiences unpredictable traffic spikes. They want to pay only for resources used during request processing, with no idle cost. Which compute service should they choose?
Easy789An organization needs to store secrets used by multiple GCP services. They require automatic rotation of secrets every 30 days and integration with Cloud Functions. Which service should they use?
Hard790A company runs a latency-sensitive web application on Compute Engine in us-east1. They want to improve response times for users in Europe and Asia without changing the application architecture. Which TWO actions should they take? (Choose 2.)
Hard791A company wants to use Cloud Armor to protect their HTTP load balancer from SQL injection attacks. Which rule action should they configure to block malicious requests?
Easy792A company runs a web application on Compute Engine instances behind a global HTTP(S) Load Balancer. The application uses Cloud SQL for MySQL for user data. Users report that during peak hours, the page load times increase significantly. The development team notices that the number of database connections exceeds the maximum allowed, causing some requests to fail. The application is designed to use connection pooling with a maximum pool size of 100 connections per instance. There are currently 10 instances. The Cloud SQL instance is configured with 4 vCPUs and 15 GB memory, and the maximum connections is set to 400. The application team wants to minimize cost while resolving the issue. What should the architect recommend?
Easy793An organization runs a Kubernetes cluster on GKE with cluster autoscaling enabled. They notice that pods are frequently in 'Pending' state due to insufficient CPU, but the cluster autoscaler does not add nodes quickly enough. What is the most likely cause?
Hard794A team is building a CI/CD pipeline for a Java application that will run on GKE. They want to automatically build the application, run unit tests, create a Docker image, push it to Artifact Registry, and deploy to GKE. Which two GCP services should be combined? (Choose two.)
Medium795Your organization stores critical financial data in Cloud Storage. You need to ensure that if an object is deleted or overwritten, you can recover it within 30 days. What feature should you enable?
Medium796A company needs to store archival data that is accessed less than once a year and must be retained for 10 years for compliance. The data retrieval time is not critical. Which Cloud Storage class is MOST cost-effective?
Easy797A team is designing a disaster recovery (DR) plan for a critical application. Which THREE components are essential for a robust DR plan? (Choose 3)
Hard798A financial services company requires a globally distributed relational database with strong consistency and horizontal scalability to serve a multi-region banking application. Write conflicts are rare. Which database should they choose?
Medium799A company wants to automatically rotate cryptographic keys on a schedule without manual intervention. Which service should they use?
Easy800A team needs to set up alerting for a production service. They want to receive notifications when the 99th percentile latency exceeds 500ms for 5 minutes. Which two Cloud Monitoring components are required? (Choose two.)
Medium801A user wants to store a database password that will be used by a Compute Engine instance. What is the most secure and manageable approach?
Easy802A company uses Google Cloud Armor to protect their HTTP load balancer from OWASP Top 10 attacks. After deploying a security policy with pre-configured WAF rules, they notice that some legitimate user requests are being blocked because they match a rule incorrectly. The security team wants to fine-tune the rules to reduce false positives while maintaining strong protection. They also want to evaluate the impact of changes before enforcing them. What should they do?
Medium803A company hosts a web application on Google Kubernetes Engine (GKE) and wants to protect against SQL injection attacks. Which service should they configure?
Medium804A financial services firm is planning its Google Cloud resource hierarchy before migrating production workloads. The architecture team wants to enforce separation between business units, centralize network administration, and apply consistent IAM and policy controls across many projects. Which two design choices should the architect recommend? (Choose two.)
Medium805A company wants to run a containerized application that scales down to zero when not in use and only incurs costs when requests are being processed. They do not want to manage infrastructure. Which compute service should they use?
Easy806A company runs a critical application on a managed instance group (MIG) with autoscaling enabled. The application experiences sudden traffic spikes, and the team wants to ensure that new instances are added quickly while maintaining cost efficiency. They also want to avoid over-provisioning. Which autoscaling metric should they use?
Hard807A developer wants to monitor the CPU usage of a single Compute Engine VM and receive alerts when it exceeds 80%. What is the simplest way to achieve this?
EasyOther domains
All PCA exam domains
Frequently asked questions
- What does the scenario questions domain cover on the PCA exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 807 scenario questions questions in the PCA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.