Courseiva

Google PCA Ensure solution and operations reliability Practice Question

Network Topology
gcloud deploy rollouts listdelivery-pipeline=my-pipelineregion=us-central1release=release-001...targetArtifacts:staging:applyManifest: |apiVersion: apps/v1kind: Deploymentmetadata:name: my-appspec:replicas: 3manifest:- apiVersion: apps/v1template:containers:- image: gcr.io/my-project/my-app:v1prod:replicas: 5- id: rollout-001targetId: stagingstate: SUCCESS- id: rollout-002targetId: prodstate: FAILEDfailureCause: MANIFEST_INVALID

Refer to the exhibit. A Cloud Deploy pipeline has a release with two targets: staging and prod. The staging rollout succeeded, but the prod rollout failed with 'MANIFEST_INVALID'. What is the most likely cause of the failure?

⚠ Common exam trap

A common trap is confusing 'MANIFEST_INVALID' with permission or quota issues, which are separate failure modes in the deployment pipeline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The manifest for prod contains a syntax error or references a resource that does not exist in the prod cluster.

The 'MANIFEST_INVALID' error in Cloud Deploy indicates that the Kubernetes manifest provided for the prod target is syntactically incorrect or references a resource (e.g., a ConfigMap, Secret, or custom resource definition) that does not exist in the prod cluster. This is a validation failure that occurs before any deployment attempt, so it is not related to runtime issues like permissions or quotas.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The manifest for prod contains a syntax error or references a resource that does not exist in the prod cluster.

    Why this is correct

    A manifest that parses cleanly against staging can still fail validation against prod, because MANIFEST_INVALID is raised when the rendered manifest is syntactically malformed or references resources absent from the target cluster. The prod target's differing namespace, CRDs or API versions therefore satisfy the stem's constraint that staging succeeded while prod alone failed.

  • ✗

    The prod target's applyManifest has a higher replica count than staging, which violates a cluster quota.

    Why it's wrong here

    A replica count exceeding cluster quota fails at apply time with a quota or admission error, not MANIFEST_INVALID, which indicates the manifest itself cannot be parsed or rendered. Quota limits are tempting because they do block rollouts, but they yield a distinct error.

  • ✗

    The prod cluster does not have the necessary permissions to pull the container image.

    Why it's wrong here

    MANIFEST_INVALID signals a malformed or unrenderable manifest, not an image-pull authorisation failure, which surfaces as ImagePullBackOff or a permission error. Image-pull permissions are tempting because they block deployments, but they produce a different failure signature.

  • ✗

    The release was not approved for the prod target.

    Why it's wrong here

    Approval gating blocks a rollout before it starts, producing a pending-approval state rather than MANIFEST_INVALID, which Cloud Deploy raises when the rendered manifest fails schema or API validation against the target cluster. Approval is the right control when you need a human gate between staging and prod.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.