Courseiva
← Back to Google Professional Cloud Architect questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Google Professional Cloud Architect practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
PCA
exam code
Google Cloud
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related PCA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Analysing and Optimising Technical and Business Processes practice questions

Analysing and Optimising Technical and Business Processes practice questions for PCA.

Managing Implementation and Ensuring Solution and Operations Reliability practice questions

Targeted PCA practice covering Managing Implementation and Ensuring Solution and Operations Reliability.

Managing and Provisioning a Solution Infrastructure practice questions

Practise PCA questions linked to Managing and Provisioning a Solution Infrastructure.

Designing for Security and Compliance practice questions

Work through PCA questions on Designing for Security and Compliance.

Design for security and compliance practice questions

Design for security and compliance practice questions for PCA.

Design and plan a cloud solution architecture practice questions

Work through PCA questions on Design and plan a cloud solution architecture.

Manage and provision cloud infrastructure practice questions

Manage and provision cloud infrastructure practice questions for PCA.

Analyze and optimize technical and business processes practice questions

Analyze and optimize technical and business processes practice questions for PCA.

Ensure solution and operations reliability practice questions

Sharpen your PCA knowledge of Ensure solution and operations reliability.

Manage implementation of cloud architecture practice questions

Work through PCA questions on Manage implementation of cloud architecture.

PCA fundamentals practice questions

Practise PCA questions linked to PCA fundamentals.

PCA scenario practice questions

Work through PCA questions on PCA scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. A Cloud Deployment Manager deployment fails with the error 'Resource 'my-firewall' already exists'. What is the most likely cause?

Exhibit

resources:
- name: my-firewall
  type: compute.v1.firewall
  properties:
    network: https://www.googleapis.com/compute/v1/projects/my-project/global/networks/default
    allowed:
    - IPProtocol: tcp
      ports: ['80','443']
    sourceRanges: ['0.0.0.0/0']
- name: my-instance
  type: compute.v1.instance
  properties:
    zone: us-central1-a
    machineType: https://www.googleapis.com/compute/v1/projects/my-project/zones/us-central1-a/machineTypes/n1-standard-1
    networkInterfaces:
    - network: https://www.googleapis.com/compute/v1/projects/my-project/global/networks/default
      accessConfigs:
      - name: External NAT
        type: ONE_TO_ONE_NAT
Question 2easymultiple choice
Full question →

Refer to the exhibit. A user (ops@example.com) is unable to create a new VPC network in the project. What should the administrator verify first?

Exhibit

{
  "bindings": [
    {
      "role": "roles/compute.viewer",
      "members": [
        "user:ops@example.com"
      ]
    }
  ]
}
Question 3hardmultiple choice
Full question →

Refer to the exhibit. A Cloud Deploy pipeline has a release with two targets: staging and prod. The staging rollout succeeded, but the prod rollout failed with 'MANIFEST_INVALID'. What is the most likely cause of the failure?

Network Topology
gcloud deploy rollouts listdelivery-pipeline=my-pipelineregion=us-central1release=release-001...targetArtifacts:staging:applyManifest: |apiVersion: apps/v1kind: Deploymentmetadata:name: my-appspec:replicas: 3manifest:- apiVersion: apps/v1template:containers:- image: gcr.io/my-project/my-app:v1prod:replicas: 5- id: rollout-001targetId: stagingstate: SUCCESS- id: rollout-002targetId: prodstate: FAILEDfailureCause: MANIFEST_INVALID
Question 4mediummultiple choice
Full question →

Refer to the exhibit. An application running on a GCE instance (ID: 1234567890) is unable to connect to a database at 10.0.0.1:5432. The logs show repeated 'Connection refused' errors. What is the most likely cause?

Network Topology
gcloud logging read "resource.type=gce_instancelimit 5format=json"severity": "ERROR","textPayload": "Connection refused to 10.0.0.1:5432","resource": {"labels": {"instance_id": "1234567890"},"timestamp": "2024-05-01T10:00:00Z""timestamp": "2024-05-01T10:05:00Z"
Question 5mediummultiple choice
Full question →

The exhibit shows a Cloud Storage bucket configuration. What does this configuration ensure?

Exhibit

Refer to the exhibit.

{
  "kind": "storage#bucket",
  "id": "my-important-bucket",
  "name": "my-important-bucket",
  "retentionPolicy": {
    "retentionPeriod": "2592000",
    "effectiveTime": "2024-01-01T00:00:00Z",
    "isLocked": true
  },
  "versioning": {
    "enabled": true
  }
}
Question 6easymultiple choice
Full question →

Refer to the exhibit. What is the primary benefit of the `--preemptible` flag in this command?

Exhibit

```
gcloud compute instances create my-instance \
    --zone=us-central1-a \
    --machine-type=e2-medium \
    --image-family=debian-10 \
    --image-project=debian-cloud \
    --preemptible
```
Question 7mediummultiple choice
Full question →

Refer to the exhibit. A cloud administrator is attempting to grant the BigQuery Data Viewer role to an external user (user@example.com) but receives the error shown. What is the most likely cause?

Exhibit

{
 "textPayload": "Error 403: The caller does not have permission to access the resource. Request prohibited by organization's policy. [ORGANIZATION_POLICY: constraints/iam.allowedPolicyMemberDomains]"
}
Question 8mediummultiple choice
Full question →

Refer to the exhibit. An engineer deployed this Terraform configuration and can SSH to the instance using the external IP. However, they notice that the instance has a public IP address even though they intended to have no public IP. What change should be made to the configuration to ensure the instance does not get a public IP?

Exhibit

resource "google_compute_instance" "vm" {
  name         = "example-vm"
  machine_type = "e2-medium"
  zone         = "us-central1-a"

  boot_disk {
    initialize_params {
      image = "debian-cloud/debian-11"
      size  = 50
    }
  }

  network_interface {
    network    = "default"
    subnetwork = "default"

    access_config {
      // Ephemeral public IP
    }
  }

  metadata = {
    enable-oslogin = "TRUE"
  }
}

# Output after 'terraform apply'
Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
Outputs:
instance_ip = "34.123.45.67"
Question 9hardmultiple choice
Full question →

Refer to the exhibit. All five nginx pods are scheduled on the same node (default-pool-1). What is the most likely reason?

Network Topology
zone us-central1-anum-nodes=3enable-autoscalingmin-nodes=1max-nodes=10machine-type=e2-standard-2scopes=cloud-platformkubectl run nginximage=nginxreplicas=5requests=cpu=500mlimits=cpu=1kubectl get pods -o widekubectl get nodesNAME STATUS ROLES AGE VERSIONgke-my-cluster-default-pool-1 Ready node 15m v1.28gke-my-cluster-default-pool-2 Ready node 15m v1.28gke-my-cluster-default-pool-3 Ready node 15m v1.28
Question 10mediummultiple choice
Full question →

Refer to the exhibit. A Cloud Storage bucket has this IAM policy. What security recommendation should be made?

Exhibit

```json
{
  "bindings": [
    {
      "role": "roles/storage.objectViewer",
      "members": [
        "allUsers"
      ]
    }
  ]
}
```
Question 11easymultiple choice
Full question →

Refer to the exhibit. The output is from `gcloud compute instances describe instance-1 --format=json`. What can you conclude from this output?

Exhibit

{
  "kind": "compute#instance",
  "name": "instance-1",
  "machineType": "https://www.googleapis.com/compute/v1/projects/my-project/zones/us-central1-a/machineTypes/n1-standard-2",
  "cpuPlatform": "Intel Skylake",
  "creationTimestamp": "2024-01-01T00:00:00.000-08:00",
  "status": "RUNNING"
}
Question 12easymultiple choice
Full question →

Refer to the exhibit. A DevOps engineer created this Terraform configuration to deploy a Compute Engine instance. After applying, they notice the instance is not accessible from the internet. What is the most likely cause?

Exhibit

Refer to the exhibit.

```
resource "type" "name" {
  project = "my-project"
  name    = "example-instance"
  machine_type = "e2-medium"
  zone         = "us-central1-a"
  boot_disk {
    initialize_params {
      image = "debian-cloud/debian-11"
      size  = 10
      type  = "pd-standard"
    }
  }
  network_interface {
    network = "default"
    access_config {
      // Ephemeral public IP
    }
  }
}
```
Question 13mediummultiple choice
Full question →

Refer to the exhibit. An engineer deploys this Terraform configuration. After deployment, they can SSH into the VM using its public IP. However, they want to restrict SSH access to only a specific IP range (203.0.113.0/24). What change is required?

Exhibit

resource "google_compute_firewall" "allow_ssh" {
  name    = "allow-ssh"
  network = "default"
  priority = 1000
  allow {
    protocol = "tcp"
    ports    = ["22"]
  }
  source_ranges = ["0.0.0.0/0"]
  target_tags   = ["ssh-allowed"]
}

resource "google_compute_instance" "my_instance" {
  name         = "my-instance"
  machine_type = "e2-micro"
  zone         = "us-central1-a"
  tags         = ["web", "ssh-allowed"]
  boot_disk {
    initialize_params {
      image = "debian-cloud/debian-11"
    }
  }
  network_interface {
    network = "default"
    access_config {
      // Ephemeral public IP
    }
  }
}
Question 14mediummultiple choice
Full question →

Refer to the exhibit. A user reports that the instance 'batch-vm' is unavailable. Based on the output, what is the most likely cause of the unavailability?

Network Topology
filter='name~batch-vm'gcloud compute instances listformat='table(name,zone,machineType,preemptible,networkInterfaces[0].networkIP,status)'
Question 15hardmultiple choice
Full question →

The exhibit shows a command to create a Compute Engine instance. The instance is intended to run a web server that needs to access Cloud Storage buckets using its service account. However, the web server fails to read from a storage bucket. What is the most likely cause?

Exhibit

Refer to the exhibit.

gcloud compute instances create my-instance \
    --zone=us-central1-a \
    --machine-type=n1-standard-4 \
    --image-family=ubuntu-2004-lts \
    --image-project=ubuntu-os-cloud \
    --boot-disk-size=50GB \
    --boot-disk-type=pd-ssd \
    --scopes=cloud-platform \
    --service-account=my-sa@project.iam.gserviceaccount.com \
    --tags=http-server,https-server

These PCA practice questions are part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style PCA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.