Courseiva

CCNA Manage Implementation Questions

65 questions · Manage Implementation topic · All types, answers revealed

1
MCQmedium

Refer to the exhibit. A cloud administrator is attempting to grant the BigQuery Data Viewer role to an external user (user@example.com) but receives the error shown. What is the most likely cause?

A.The organization policy constraints/iam.allowedPolicyMemberDomains blocks external domains.
B.The BigQuery dataset requires domain-wide delegation.
C.The user does not have the resourcemanager.projects.setIamPolicy permission.
D.The external user must first be added to a Google Group.
AnswerA

The constraint `constraints/iam.allowedPolicyMemberDomains` restricts which identity domains may appear in IAM policy bindings. Because `user@example.com` sits outside the permitted Workspace or Cloud Identity customer, the binding is rejected outright, matching the stem's failure to grant BigQuery Data Viewer to that external account.

Why this answer

The error indicates that the organization's policy constraints/iam.allowedPolicyMemberDomains is blocking the addition of an external user. This constraint restricts IAM policy bindings to only allow members from specified domains, and since user@example.com is from an external domain, the binding is denied. The error message directly references this constraint, making it the most likely cause.

Exam trap

Google often tests the distinction between IAM permission errors and organization policy constraints, where candidates mistakenly focus on the administrator's permissions (Option C) rather than the broader policy that blocks external members.

How to eliminate wrong answers

Option B is wrong because domain-wide delegation is a Google Workspace feature for service accounts to access user data, not related to granting IAM roles to external users. Option C is wrong because the error message does not indicate a permissions issue for the administrator; the error is about policy constraints, not missing IAM permissions. Option D is wrong because Google Groups are not required for granting IAM roles to external users; the constraint blocks any external member regardless of group membership.

2
MCQeasy

A company wants to deploy a containerized application on Google Cloud and needs persistent storage that can be accessed by multiple pods in a GKE cluster concurrently. Which storage solution should they use?

A.Persistent Disk with ReadWriteMany access mode
B.Cloud Storage via Storage FUSE
C.Compute Engine persistent disk attached to each node
D.Filestore
AnswerD

Filestore provides a fully managed NFS file share, so multiple GKE pods can mount the same volume concurrently across nodes. This satisfies the stem's requirement for shared persistent storage, unlike zonal persistent disks, which support only ReadWriteOnce attachment to a single node.

Why this answer

Filestore is the correct choice because it provides a managed NFS file server that supports the ReadWriteMany (RWX) access mode, allowing multiple pods in a GKE cluster to concurrently read from and write to the same persistent storage volume. This is essential for workloads like content management systems or shared data processing that require simultaneous access from multiple pods.

Exam trap

The trap here is that candidates often confuse Persistent Disk's ReadWriteOnce capability with ReadWriteMany, or incorrectly assume that Cloud Storage FUSE provides the same concurrent POSIX access as a true shared filesystem like NFS.

How to eliminate wrong answers

Option A is wrong because Persistent Disk volumes in GKE support only ReadWriteOnce (RWO) access mode, meaning they can be mounted by only a single pod at a time, not multiple pods concurrently. Option B is wrong because Cloud Storage via Storage FUSE provides a file-system interface to object storage, but it does not offer true POSIX-compliant concurrent read-write access from multiple pods and introduces latency and consistency limitations. Option C is wrong because Compute Engine persistent disks attached to each node are local to that node and cannot be shared across multiple nodes or pods; they also default to ReadWriteOnce mode.

3
MCQmedium

A media company stores millions of video files in a Cloud Storage bucket and serves them to users worldwide. Users in Asia report slow download speeds, while users in North America are satisfied. The files are immutable after upload and are read frequently for the first 30 days, then almost never. You want to improve global performance while minimizing cost. What should you do?

A.Move the files to a bucket in the asia-east1 region and serve them directly from that location.
B.Create a Cloud CDN distribution with the Cloud Storage bucket as the backend, and add a lifecycle rule to move objects to Nearline Storage after 30 days.
C.Recreate the bucket as a multi-region bucket and enable Autoclass to manage storage classes automatically.
D.Enable Object Versioning on the bucket and create a Cloud CDN distribution backed by the bucket.
AnswerB

Cloud CDN caches immutable objects at edge locations, so users in Asia are served from nearby points of presence instead of the origin bucket. A lifecycle rule transitioning objects to Nearline after 30 days matches the access pattern and lowers storage cost. Because the files are immutable, caching is safe and effective, making this the best performance-and-cost combination.

Why this answer

Serving immutable objects through Cloud CDN puts copies at Google's edge points of presence, which directly improves download speeds for users far from the origin. Pairing that with a lifecycle rule that transitions rarely accessed objects to Nearline Storage after 30 days aligns storage cost with the actual access pattern, so performance improves without unnecessary expense.

Exam trap

The trap here is reaching for multi-region storage to fix latency, when multi-region placement improves durability and availability rather than edge delivery to end users.

4
Multi-Selecteasy

A company is deploying a web application on Compute Engine. They want to automatically scale the number of instances based on CPU utilization. Which two components are required to set up autoscaling? (Choose two.)

Select 2 answers
A.Cloud Functions
C.Instance template
D.Managed instance group
E.Cloud Monitoring
AnswersC, D

An instance template defines the machine type, boot disk image, and startup configuration used to create each replica. Autoscaling needs it so the managed instance group can provision identical new VMs when CPU utilisation crosses the target threshold.

Why this answer

Option C (Instance template) is correct because a managed instance group requires an instance template to define the machine type, boot disk image, network, and other configuration used when automatically creating new VM instances during scaling. Option D (Managed instance group) is correct because autoscaling in Compute Engine operates on a managed instance group (MIG), where the autoscaler adds or removes instances based on the specified CPU utilization target. Cloud Functions (A) is a serverless event-driven compute service and plays no role in Compute Engine autoscaling.

Cloud Load Balancing (B) is commonly used to distribute traffic to the instances but is not a required component to configure the autoscaling policy itself. Cloud Monitoring (E) can surface metrics and alerts, but the autoscaler uses the MIG's built-in CPU utilization signal and does not require a separate Monitoring configuration.

Exam trap

The trap here is that candidates often think Cloud Monitoring is required because autoscaling uses CPU metrics, but the autoscaler automatically accesses those metrics without requiring Cloud Monitoring to be separately configured.

5
MCQhard

An engineer runs the command above. A few days later, the instance becomes unresponsive. Upon investigation, you find that the boot disk is 100 GB and 95% full. The data disk is 500 GB and only 20% full. What is the most likely cause of the unresponsiveness?

A.The boot disk is too small and has run out of space.
B.The data disk is pd-standard, which is causing I/O bottlenecks for the OS.
C.The boot disk is pd-ssd, which is too slow for the workload.
D.The instance has run out of IOPS on the boot disk.
AnswerA

The boot disk holds the operating system, logs, and temporary files. At 95% of 100 GB, it lacks space for normal writes, causing the instance to hang. The data disk's free capacity is irrelevant because the OS cannot use it for boot-volume operations.

Why this answer

The boot disk is 95% full, which leaves insufficient free space for the operating system to write temporary files, logs, or perform essential system operations. When a Linux or Windows boot disk runs out of space, the OS can become unresponsive because critical processes (e.g., systemd, journald, or the Windows Registry) cannot write to disk. In Google Cloud, the boot disk is the root device (typically /dev/sda1), and filling it to 95% on a 100 GB disk means only 5 GB remains, which is easily exhausted by normal system activity.

Exam trap

Google Cloud often tests the distinction between disk space exhaustion and performance bottlenecks; the trap here is that candidates may focus on disk type (pd-standard vs pd-ssd) or IOPS limits instead of recognizing that a nearly full boot disk directly causes OS unresponsiveness.

How to eliminate wrong answers

Option B is wrong because pd-standard disks are HDD-based and can cause I/O bottlenecks, but the data disk is only 20% full and the question states the instance became unresponsive due to disk space, not I/O performance. Option C is wrong because pd-ssd is a high-performance SSD type, not too slow for typical workloads; the issue is space exhaustion, not speed. Option D is wrong because running out of IOPS would cause performance degradation or throttling, not unresponsiveness due to disk space; the boot disk is nearly full, which is a capacity problem, not an IOPS limit.

6
MCQmedium

An organization uses Cloud Deployment Manager to manage infrastructure as code. They need to ensure that changes to production resources are reviewed and approved before deployment. What should they do?

A.Use Cloud Scheduler to run deployment configs and review logs after deployment
B.Integrate Cloud Deployment Manager with Cloud Build and add a manual approval step in the Cloud Build pipeline
C.Create a Cloud Deployment Manager preview deployment and manually approve it
D.Use Cloud Build with a trigger on a branch that requires pull request approval before merging
AnswerB

Cloud Build triggers can pause on a manual approval gate before executing the Deployment Manager template, ensuring production changes are reviewed and authorised. Deployment Manager alone has no native approval workflow, so the pipeline supplies the required control.

Why this answer

Integrating Cloud Deployment Manager with Cloud Build allows you to create a CI/CD pipeline that includes a manual approval step. This ensures that changes to production resources are reviewed and approved before the deployment config is applied, meeting the requirement for change control.

Exam trap

The trap here is that candidates often confuse code review (pull request approval) with deployment approval, thinking that merging code with approval automatically ensures deployment approval, but Cloud Deployment Manager requires a separate approval step in the deployment pipeline to control when infrastructure changes are actually applied.

How to eliminate wrong answers

Option A is wrong because Cloud Scheduler is a cron job service for triggering actions on a schedule; it does not provide any review or approval mechanism, and reviewing logs after deployment does not prevent unapproved changes. Option C is wrong because a Cloud Deployment Manager preview deployment only shows what changes would be made without actually applying them, but it does not enforce a formal review and approval workflow; manual approval of a preview is not a built-in feature of Deployment Manager. Option D is wrong because while using Cloud Build with a trigger on a branch that requires pull request approval before merging enforces code review, it does not directly integrate with Cloud Deployment Manager to control the deployment of infrastructure; it only controls the merge of code, not the deployment of resources.

7
MCQeasy

A company is migrating its on-premises Hadoop cluster to Google Cloud. They want to use a fully managed service that supports HDFS, Hive, and Spark, and allows them to run ephemeral clusters that can be created and deleted on demand. They also want to minimize infrastructure management. Which Google Cloud service should they use?

A.Cloud Bigtable
B.BigQuery
C.Cloud Dataflow
D.Cloud Dataproc
AnswerD

Cloud Dataproc is a fully managed service for running Apache Hadoop, Spark, Hive, and other open-source big data tools. It allows you to create ephemeral clusters that can be spun up quickly, run jobs, and then be deleted, minimizing costs and infrastructure management. It supports HDFS as the distributed storage layer. This meets all the requirements.

Why this answer

Cloud Dataproc is the only service that provides a managed Hadoop and Spark environment with support for HDFS, Hive, and ephemeral clusters. It allows you to create clusters on demand and delete them when jobs are complete, reducing operational overhead. The other services are not Hadoop-compatible or do not support the required tools.

Exam trap

The trap here is assuming that BigQuery or Dataflow can replace Hadoop workloads; they are different paradigms and do not support HDFS or Hive.

8
Matchingmedium

Match each IAM role type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Legacy roles like Owner, Editor, Viewer

Fine-grained roles managed by Google

User-defined roles with specific permissions

Another name for Basic roles

Identity for applications, not users

Why these pairings

In GCP, IAM roles are categorized into basic (broad), predefined (service-specific), and custom (user-defined). Common confusions arise between predefined and custom roles.

9
MCQmedium

A company is using Cloud Load Balancing to distribute traffic to a managed instance group (MIG) of web servers. The web servers are currently running in us-central1. To improve availability, the company plans to add a second MIG in us-west1. What must be done to ensure traffic is automatically routed to the closest healthy backend?

A.Use a Network Load Balancer in us-central1 and configure a redirect to the new MIG.
B.Use a global external HTTP(S) load balancer and add both MIGs as backends.
C.Use an internal TCP/UDP load balancer in each region and configure DNS-based routing.
D.Use an external TCP/UDP Network Load Balancer with the new MIG as an additional backend.
AnswerB

A global external HTTP(S) load balancer provides a single anycast VIP with Google's global frontend, so it can route each user to the closest healthy backend across both us-central1 and us-west1 MIGs. A regional load balancer cannot span regions.

Why this answer

A global external HTTP(S) load balancer can route traffic to backends in multiple regions and automatically directs requests to the closest healthy backend based on the client's geographic location and backend health. Adding both MIGs as backends to this single anycast IP ensures traffic is distributed to the nearest region without additional DNS-based routing or redirects.

Exam trap

The trap here is that candidates confuse regional load balancers (Network Load Balancer, TCP/UDP Proxy) with global load balancers, assuming any external load balancer can span regions, but only the global external HTTP(S) load balancer (and the global external SSL proxy) support multi-region backends with automatic proximity-based routing.

How to eliminate wrong answers

Option A is wrong because a Network Load Balancer is regional and cannot route traffic across regions; a redirect would introduce a single point of failure and latency, not automatic closest-backend routing. Option C is wrong because internal TCP/UDP load balancers are regional and cannot be used for external traffic; DNS-based routing would require manual configuration and does not provide automatic proximity-based routing with health-aware failover. Option D is wrong because an external TCP/UDP Network Load Balancer is regional (not global) and cannot distribute traffic to backends in multiple regions; it only supports backends within a single region.

10
Multi-Selecthard

A healthcare company runs a patient portal on Google Kubernetes Engine (GKE). Auditors require that all container images be scanned for vulnerabilities before deployment and that only images from a trusted registry be admitted to the cluster. You are configuring Binary Authorization. Which TWO actions should you take to meet these requirements? (Choose two.)

Select 2 answers
A.Enable the Container Analysis API and configure a vulnerability scanning policy so that images pushed to Artifact Registry are analyzed automatically.
B.Create a Binary Authorization attestor and require an attestation from a trusted build pipeline before images can be deployed.
C.Apply a Kubernetes NetworkPolicy that allows egress only to the trusted registry so nodes cannot pull other images.
D.Configure a PodSecurityPolicy that restricts images to those hosted in Artifact Registry.
E.Set the cluster's default namespace to use the kube-system service account for all workloads so admission checks are bypassed.
AnswersA, B

Container Analysis performs automated vulnerability scanning on images in Artifact Registry and records findings as metadata. Binary Authorization attestations can be based on the results of that analysis, so enabling scanning is a prerequisite for enforcing that only scanned images are admitted. Without scanning, there is no vulnerability signal for the policy to evaluate.

Why this answer

Binary Authorization enforces deploy-time policy based on attestations. Enabling Container Analysis provides automated vulnerability scanning of registry images, and defining an attestor that your trusted build pipeline signs ensures only verified images are admitted. Together they create a verifiable chain from scanning to admission, which satisfies the auditors' requirements.

Exam trap

The trap here is assuming that Kubernetes PodSecurityPolicy or NetworkPolicy can restrict image sources, when only Binary Authorization evaluates image provenance at admission time.

11
MCQeasy

A company is planning to deploy a global web application on Google Cloud. They expect low latency for users worldwide and need to serve static content (images, CSS) as well as dynamic API responses. Which architecture should they use?

A.Use Cloud CDN in front of an external HTTPS Load Balancer with backend services in multiple regions.
B.Use Cloud NAT to allow egress traffic from instances and distribute static content via a shared VPC.
C.Use Cloud DNS with geo-routing to direct users to the closest regional Cloud Run service.
D.Use VPC Network Peering to connect multiple regional VPCs and serve content from a central location.
AnswerA

Cloud CDN caches static assets at edge locations, while the external HTTPS Load Balancer with multi-region backends routes dynamic API traffic to the nearest healthy region, satisfying the worldwide low-latency requirement for both content types.

Why this answer

Cloud CDN in front of an external HTTPS Load Balancer with backend services in multiple regions is correct because it provides global anycast IP termination, low-latency content delivery via Google's edge cache for static content, and dynamic API requests are forwarded to the nearest healthy backend in the closest region. This architecture meets both the low-latency requirement for users worldwide and the need to serve both static and dynamic content efficiently.

Exam trap

Google Cloud often tests the misconception that DNS geo-routing alone (Option C) can provide low-latency global content delivery, but it lacks caching and introduces DNS resolution delays, making it unsuitable for static content without a CDN.

How to eliminate wrong answers

Option B is wrong because Cloud NAT is used for outbound internet access from private instances, not for distributing static content or reducing latency for global users; it does not provide any caching or global load balancing. Option C is wrong because Cloud DNS with geo-routing directs traffic based on DNS resolution, but it cannot cache static content and introduces DNS propagation delays; Cloud Run services alone do not include a CDN for static assets. Option D is wrong because VPC Network Peering connects VPCs for private networking but does not provide global load balancing, caching, or low-latency content delivery; serving from a central location would increase latency for distant users.

12
MCQeasy

A startup wants to deploy a web application on Google Cloud with a MySQL database. They anticipate low traffic initially but want the ability to scale seamlessly. They also want to minimize operational overhead. Which combination of services should they choose?

A.Compute Engine with a self-managed MySQL instance.
B.Cloud Run with Cloud Spanner.
C.App Engine Standard Environment with Cloud SQL.
D.Google Kubernetes Engine (GKE) with Cloud SQL.
AnswerC

App Engine Standard automatically scales instances with traffic and requires no server management, while Cloud SQL provides a managed MySQL database, together minimising operational overhead. This pairing satisfies the low-traffic start, seamless scaling, and reduced administration constraints.

Why this answer

App Engine Standard Environment provides a fully managed, autoscaling platform for web applications, while Cloud SQL offers a managed MySQL database with automatic replication and backups. This combination minimizes operational overhead because Google handles infrastructure provisioning, patching, and scaling, and Cloud SQL integrates natively with App Engine via the Cloud SQL proxy or Unix socket, requiring no manual configuration for connectivity.

Exam trap

Google Cloud often tests the misconception that Kubernetes (GKE) is always the best choice for scalability, but the trap here is that for a low-traffic application with minimal operational overhead requirements, a fully managed platform like App Engine Standard Environment is more appropriate than the complex orchestration overhead of GKE.

How to eliminate wrong answers

Option A is wrong because Compute Engine with a self-managed MySQL instance requires the startup to manually handle OS patching, database backups, replication, and scaling, which increases operational overhead and contradicts the goal of minimizing it. Option B is wrong because Cloud Spanner is a globally distributed, strongly consistent relational database designed for high-throughput, horizontal scaling, which is overkill and more expensive for a low-traffic web application that only needs a MySQL-compatible database. Option D is wrong because Google Kubernetes Engine (GKE) introduces significant operational complexity for managing container orchestration, node pools, and networking, which is unnecessary for a low-traffic application that could be served by a simpler, fully managed platform like App Engine.

13
MCQeasy

A startup wants to deploy a containerized application with minimal operational overhead. They expect variable traffic. Which compute option should they choose?

A.App Engine Flexible Environment
B.Cloud Run
C.Compute Engine single VM
D.Google Kubernetes Engine (GKE)
AnswerB

Cloud Run abstracts all infrastructure, scaling containers to zero when idle and automatically with demand, which directly satisfies the minimal operational overhead and variable traffic constraints. Unlike GKE, no cluster nodes require patching or capacity planning, and billing occurs only per request, suiting unpredictable startup workloads.

Why this answer

Cloud Run is the correct choice because it is a fully managed serverless compute platform that automatically scales from zero based on traffic, charges only for resources used during request processing, and eliminates all infrastructure management. This aligns perfectly with the startup's requirement for minimal operational overhead and handling variable traffic patterns without provisioning or scaling concerns.

Exam trap

The trap here is that candidates often confuse Cloud Run with App Engine Flexible Environment, assuming both are fully managed, but App Engine Flexible Environment does not scale to zero and requires VM-level management, making Cloud Run the only option that truly minimizes operational overhead for variable traffic.

How to eliminate wrong answers

Option A is wrong because App Engine Flexible Environment requires you to manage the underlying VM instances and does not scale to zero, incurring costs even when idle, which contradicts the goal of minimal operational overhead and cost efficiency for variable traffic. Option C is wrong because a single Compute Engine VM provides no autoscaling, requires manual capacity planning and maintenance, and cannot handle variable traffic without manual intervention or over-provisioning, leading to either downtime or wasted resources. Option D is wrong because Google Kubernetes Engine (GKE) introduces significant operational overhead for cluster management, node scaling, and Kubernetes configuration, which is excessive for a simple containerized application with variable traffic and contradicts the 'minimal operational overhead' requirement.

14
MCQeasy

A company is using Cloud NAT to allow private instances to access the internet. They notice that outbound connections are failing intermittently. What is the most likely cause?

A.The private instances are using the wrong DNS server.
B.The VPC firewall rules are blocking egress traffic.
C.Cloud NAT does not support TCP connections.
D.The number of concurrent connections exceeds the Cloud NAT source port capacity for the assigned NAT IPs.
AnswerD

Cloud NAT allocates a finite pool of source ports per NAT IP address, and each connection consumes one tuple. When concurrent outbound connections exceed that capacity, new connections cannot be translated and fail intermittently, matching the reported symptom.

Why this answer

Cloud NAT uses source network address translation (SNAT) to map private instance IPs to a single public IP address. Each NAT IP has a limited pool of source ports (typically 64,512 per IP for TCP/UDP). When concurrent connections exceed this capacity, new outbound connections are dropped, causing intermittent failures.

This is the most likely cause given the symptom of intermittent failures.

Exam trap

The trap here is that candidates confuse intermittent failures with firewall misconfigurations or DNS issues, but the key clue is 'intermittent'—which points to a resource exhaustion problem like port capacity, not a static policy or configuration error.

How to eliminate wrong answers

Option A is wrong because DNS server misconfiguration would cause name resolution failures, not intermittent connection drops after resolution; Cloud NAT operates at the network layer and is independent of DNS. Option B is wrong because VPC firewall rules blocking egress traffic would cause consistent, not intermittent, failures; the question states failures are intermittent, which points to resource exhaustion rather than a static rule. Option C is wrong because Cloud NAT explicitly supports TCP, UDP, and ICMP connections; it performs SNAT for all these protocols.

15
MCQhard

Your company runs a containerized microservices application on Google Kubernetes Engine (GKE) with a regional cluster. The application consists of a frontend service, a backend API service, and a background worker service that processes messages from Cloud Pub/Sub. The worker service uses a Deployment with 3 replicas. Recently, the team noticed that the worker service is frequently failing with 'ContainerCreating' errors. The error message in the pod events is: 'Failed to pull image "gcr.io/my-project/my-worker:latest": rpc error: code = DeadlineExceeded desc = context deadline exceeded'. The image is stored in Container Registry in the same project. The cluster nodes are n1-standard-2 VMs with 10 GB of disk space. The team has confirmed that the image exists and that the nodes have internet access. What is the most likely cause of the issue?

A.The worker pods require node affinity to a specific node pool that is not configured.
B.The nodes have insufficient disk space to pull the new image, causing the pull to time out.
C.The nodes do not have the necessary permissions to access Container Registry.
D.The cluster is a regional cluster, but the worker pods are all scheduled in the same zone, causing resource contention.
AnswerB

With only 10 GB of node disk, image layers plus container runtime and logs exhaust available space, so the kubelet cannot pull the new image before the deadline, producing the DeadlineExceeded ContainerCreating failure despite the image existing.

Why this answer

The error 'context deadline exceeded' when pulling an image indicates that the kubelet timed out while trying to download the container image. With only 10 GB of disk space on n1-standard-2 nodes, the node's disk may be nearly full, causing the image pull to stall or fail due to insufficient space to unpack the layers. This is the most likely cause because the image exists and internet access is confirmed, ruling out authentication or connectivity issues.

Exam trap

Google Cloud often tests the distinction between image pull errors that are due to permissions (e.g., 'unauthorized') versus resource exhaustion (e.g., disk full), and candidates mistakenly assume internet connectivity or permissions are the issue when the error message explicitly mentions a deadline exceeded.

How to eliminate wrong answers

Option A is wrong because node affinity is used to constrain pod scheduling to specific nodes, but the error is about pulling an image, not scheduling; the pods are already being created but fail during container setup. Option C is wrong because if nodes lacked permissions to access Container Registry, the error would be 'unauthorized' or 'access denied', not a deadline exceeded timeout; the team confirmed the image exists and nodes have internet access. Option D is wrong because a regional cluster distributes pods across zones by default, and even if all pods were in one zone, resource contention would manifest as 'Unschedulable' or 'CPU/memory pressure', not a pull timeout.

16
Multi-Selecteasy

A company is designing a data pipeline to ingest streaming data from IoT devices and store it in BigQuery for analysis. They need to minimize latency and operational overhead. Which two Google Cloud services should they use? (Choose two.)

Select 2 answers
A.Cloud Dataflow
B.Cloud Pub/Sub
C.Cloud Dataproc
D.Cloud Storage
E.Cloud Functions
AnswersA, B

Cloud Dataflow provides serverless, autoscaling stream processing with exactly-once semantics, satisfying the low operational overhead constraint. It reads from Pub/Sub and writes into BigQuery using built-in connectors, so no cluster management is needed to meet the latency requirement.

Why this answer

Cloud Pub/Sub is the recommended service for ingesting streaming data, and Cloud Dataflow can process the data and write it directly to BigQuery with low latency. Cloud Storage is for batch uploads, Cloud Functions is event-driven but not ideal for high-throughput streaming, and Cloud Dataproc is for batch processing.

17
MCQmedium

Your team is deploying a new internal web application on Compute Engine. The security team requires that all outbound internet traffic from the instances be inspected by a third-party firewall appliance running on a separate VM. You need to implement this with minimal changes to the application instances. What should you do?

A.Configure a custom route in the VPC that sends all traffic destined for 0.0.0.0/0 to the internal IP address of the firewall appliance. Enable IP forwarding on the firewall instance and configure it to forward traffic to the internet.
B.Use VPC peering to connect the application subnet to the firewall appliance's subnet. Configure the application instances to send all traffic to the firewall's IP by setting a static route on each instance's operating system.
C.Create a new VPC network with a global external HTTP(S) load balancer and set the backend service to the firewall appliance. Configure the application instances to use the load balancer's IP as their default gateway.
D.Deploy the firewall appliance as a managed instance group and configure an internal TCP/UDP load balancer. Set the application instances' default gateway to the load balancer's IP address using a startup script.
AnswerA

This approach uses a custom static route to redirect all default internet-bound traffic to the firewall appliance's internal IP. Enabling IP forwarding on the appliance allows it to act as a next-hop and forward packets to the internet, satisfying the inspection requirement without modifying the application instances.

Why this answer

Routing outbound traffic through a third-party firewall is typically done by creating a custom route for 0.0.0.0/0 with the firewall's internal IP as the next hop, and enabling IP forwarding on the firewall VM. This transparently redirects traffic without modifying application instances. Other options involve services not designed for this purpose or require unsupported configuration changes.

Exam trap

The trap here is assuming that a load balancer can act as a default gateway for outbound traffic, when it is only for inbound or internal distribution.

18
MCQmedium

Your team is deploying a new three-tier application to Google Cloud. The security team requires that the application's Compute Engine instances never receive public IP addresses, yet the instances must still download OS patches from the public internet and reach a third-party REST API over HTTPS. You need to implement this with the least operational overhead. What should you do?

A.Configure Cloud NAT on a Cloud Router in the region, and create a route so instances without external IP addresses can reach the internet.
B.Create a VPN tunnel from the VPC to an on-premises network and route all internet-bound traffic through that network.
C.Assign each instance an ephemeral external IP address and use firewall rules to block all inbound traffic on every port.
D.Deploy a third-party forward proxy on a Compute Engine instance with an external IP address and point all instances at it.
AnswerA

Cloud NAT lets instances with only internal IP addresses initiate outbound connections to the internet without exposing them to inbound traffic. Attaching it to a Cloud Router in the same region and VPC supports patch downloads and third-party API calls while satisfying the no-public-IP requirement, with no per-instance agents or proxies to maintain.

Why this answer

Cloud NAT provides managed, regional outbound internet access for instances that have no external IP address. It satisfies both the security constraint and the functional need for patch downloads and third-party API calls, without introducing proxy servers, ephemeral public addresses, or on-premises dependencies. This is the lowest-overhead native option.

Exam trap

The trap here is assuming that firewall rules can substitute for removing a public IP address, when the requirement is about address assignment rather than traffic filtering.

19
MCQeasy

Your organization is using Google Cloud to host a web application that experiences unpredictable traffic spikes. You need to ensure the application scales automatically and maintains high availability across multiple zones. The application runs on Compute Engine instances behind a load balancer. What should you do?

A.Create a managed instance group with an autoscaling policy based on CPU utilization, and configure the group to span multiple zones. Place the instance group behind an external HTTP(S) load balancer.
B.Create an unmanaged instance group with instances in multiple zones, and manually add or remove instances based on traffic. Use a network load balancer to distribute traffic.
C.Deploy the application on a single Compute Engine instance with a powerful machine type, and use a global load balancer to direct traffic to it. Configure a health check to restart the instance if it fails.
D.Use a regional managed instance group with autoscaling, and place it behind an internal TCP/UDP load balancer. Configure the load balancer to distribute traffic across zones.
AnswerA

A managed instance group with autoscaling automatically adjusts the number of instances based on load, and spanning multiple zones ensures high availability. An external HTTP(S) load balancer distributes traffic across instances and provides a single global IP, making this the correct solution for scaling and availability.

Why this answer

A managed instance group with autoscaling and multi-zone deployment provides automatic scaling and high availability. An external HTTP(S) load balancer is designed for web traffic, offering global distribution and SSL termination. This combination meets the requirements for unpredictable traffic and multi-zone availability.

Exam trap

The trap here is confusing internal and external load balancers, or assuming that an unmanaged instance group can autoscale.

20
MCQmedium

A developer is using Cloud Build to automate deployments. The build fails with an error: 'Permission 'iam.serviceAccounts.actAs' denied.' What is the most likely cause?

A.The developer does not have iam.serviceAccounts.actAs permission on the project
B.The build configuration is missing a required step
C.The Cloud Build service account is not enabled
D.The Cloud Build service account does not have the Service Account User role on the service account used in the build steps
AnswerD

The `iam.serviceAccounts.actAs` permission is granted by the Service Account User role (`roles/iam.serviceAccountUser`), which Cloud Build's service account requires to impersonate the service account specified in build steps. Without it on that target service account, Cloud Build cannot act as it, producing exactly this denial.

Why this answer

The error 'Permission iam.serviceAccounts.actAs denied' occurs when a Cloud Build build step tries to impersonate a service account (e.g., to deploy resources) but the Cloud Build service account lacks the Service Account User role on that target service account. Option D correctly identifies that the Cloud Build service account does not have the `roles/iam.serviceAccountUser` role on the service account used in the build steps, which is required to delegate access.

Exam trap

Google Cloud often tests the distinction between granting permissions to a user versus granting roles to a service account, and the trap here is that candidates mistakenly think the developer needs the `actAs` permission directly (Option A), when in fact it is the Cloud Build service account that requires the Service Account User role on the target service account.

How to eliminate wrong answers

Option A is wrong because the `iam.serviceAccounts.actAs` permission is not granted directly to the developer; it is granted to a service account (the Cloud Build service account) on another service account. The error is about the Cloud Build service account lacking this permission, not the developer. Option B is wrong because a missing build step would typically cause a syntax or execution error, not a specific IAM permission denial.

Option C is wrong because the Cloud Build service account is enabled by default when Cloud Build is used; the error is about missing IAM roles on that service account, not its existence.

21
MCQhard

A company is deploying a global web application on Google Cloud. The application serves static content from a Cloud Storage bucket and dynamic content from a managed instance group backend. They want to use a single global IP address and provide low latency to users worldwide. They also want to protect the application from DDoS attacks. Which solution should they implement?

A.Configure an external HTTP(S) load balancer with a global anycast IP address, a backend service for the managed instance group, and a backend bucket for the Cloud Storage bucket. Enable Cloud CDN and Google Cloud Armor.
B.Use a global external HTTP(S) load balancer with a single backend service that points to both the managed instance group and the Cloud Storage bucket using a hybrid connectivity network endpoint group (NEG).
C.Deploy a third-party DDoS protection service in front of the application, and use a network load balancer with a global IP address for both backends.
D.Create a global TCP proxy load balancer with a global IP address, and configure backends for the managed instance group and Cloud Storage bucket.
AnswerA

An external HTTP(S) load balancer provides a single global anycast IP address and can route traffic to both a managed instance group backend and a Cloud Storage backend bucket. Cloud CDN caches static content at the edge for low latency, and Cloud Armor provides DDoS protection and WAF capabilities. This meets all requirements.

Why this answer

The external HTTP(S) load balancer provides a global anycast IP and supports both backend services and backend buckets, allowing static and dynamic content to be served from the same IP. Cloud CDN caches static content for low latency, and Cloud Armor protects against DDoS and other attacks. This integrated solution meets all the requirements without third-party dependencies.

Exam trap

The trap here is assuming that a TCP proxy load balancer can serve HTTP(S) traffic and integrate with Cloud CDN; it operates at layer 4 and lacks these features.

22
Drag & Dropmedium

Drag and drop the steps to deploy a containerized application to Google Kubernetes Engine (GKE) using a Deployment into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The image must be in a registry before the Deployment can reference it. The Service provides external access.

23
MCQeasy

A startup wants to deploy a containerized web application that must scale automatically based on incoming HTTP request volume and must be reachable at a stable HTTPS endpoint. The team has no Kubernetes experience and wants to minimize infrastructure management. Which Google Cloud service should they use?

A.Google Kubernetes Engine Autopilot with a HorizontalPodAutoscaler and an Ingress resource.
B.Compute Engine managed instance groups with an HTTP(S) load balancer and autoscaling based on CPU.
C.App Engine flexible environment with automatic scaling enabled and a custom runtime.
D.Cloud Run, with the container deployed as a service and request concurrency used to drive automatic scaling.
AnswerD

Cloud Run runs containers on a fully managed platform, scales instances automatically based on incoming requests and concurrency, and provides an HTTPS endpoint out of the box. It requires no cluster or VM management, which directly matches the team's lack of Kubernetes experience and their goal of minimizing infrastructure work.

Why this answer

Cloud Run is a fully managed container platform that scales automatically in response to request volume and exposes an HTTPS endpoint by default. Because it abstracts away clusters and VMs, it fits a team without Kubernetes skills that wants to minimize infrastructure management while still running a containerized web application.

Exam trap

The trap here is equating containers with Kubernetes, when a managed serverless container platform can run the same image with far less operational effort.

24
Multi-Selecthard

Which THREE of the following are recommended practices when designing a highly available architecture on Google Cloud using multiple regions?

Select 3 answers
A.Deploy Compute Engine instances in a single regional managed instance group
B.Use a global external HTTP(S) load balancer with backend services in multiple regions
C.Use Cloud Spanner or cross-region replication for databases
D.Implement health checks and automated failover using Cloud DNS with weighted routing
E.Use a single Cloud VPN tunnel for connectivity between regions
AnswersB, C, D

A global external HTTP(S) load balancer uses a single anycast IP and routes users to the nearest healthy regional backend. This satisfies the multi-region availability requirement by failing over automatically when a regional backend becomes unhealthy.

Why this answer

Option B is correct because a global external HTTP(S) load balancer uses a single anycast IP and automatically routes users to the closest healthy backend service across multiple regions, providing global failover and low-latency access. Option C is correct because Cloud Spanner offers a multi-region configuration with synchronous replication and strong consistency, and cross-region replication for databases ensures data survives a regional outage. Option D is correct because health checks detect unhealthy endpoints and Cloud DNS weighted routing (or failover routing policies) can automatically direct traffic away from a failed region.

Option A is not recommended because a single regional managed instance group confines instances to one region, so a regional outage takes down the whole workload. Option E is not recommended because a single Cloud VPN tunnel is a single point of failure; highly available designs require redundant tunnels or Cloud Interconnect with multiple paths.

Exam trap

Google Cloud often tests the misconception that a single regional managed instance group or a single VPN tunnel is sufficient for multi-region high availability, but the exam expects you to recognize that redundancy across regions and elimination of single points of failure are mandatory.

25
MCQeasy

A startup is setting up a CI/CD pipeline for their web application using Cloud Build and Cloud Deploy. They have configured a Cloud Build trigger that executes on pushes to the main branch of a Cloud Source Repositories repository. The trigger runs a build step that builds a Docker image and pushes it to Artifact Registry, then creates a release using Cloud Deploy. The pipeline fails with an error message indicating that the Cloud Build service account does not have permission to create releases. What should the architect do to resolve the issue?

A.Add the Cloud Deploy Developer IAM role to the Cloud Build service account.
B.Verify that the cloudbuild.yaml file contains the correct steps.
C.Enable the Cloud Deploy API for the project.
D.Grant the Cloud Build service account the Cloud Run Admin role.
AnswerA

Granting the Cloud Deploy Developer role to the Cloud Build service account supplies the missing `clouddeploy.releases.create` permission, which the trigger's build step requires when invoking Cloud Deploy to create a release. This directly satisfies the stem's constraint: the service account currently lacks permission to create releases.

Why this answer

The Cloud Build service account (typically the Compute Engine default service account or a custom service account) needs the Cloud Deploy Developer IAM role (roles/clouddeploy.developer) to create releases in Cloud Deploy. This role grants the necessary permissions, such as clouddeploy.releases.create, which are required for the Cloud Build trigger to successfully create a release after building and pushing the Docker image. Without this role, the pipeline fails with a permission error, making option A the correct resolution.

Exam trap

The trap here is that candidates might assume the Cloud Build service account has sufficient permissions by default (e.g., via the Editor role) or confuse Cloud Deploy permissions with Cloud Run permissions, leading them to select the Cloud Run Admin role instead of the specific Cloud Deploy Developer role.

How to eliminate wrong answers

Option B is wrong because the cloudbuild.yaml file's correctness is irrelevant to the permission error; the error explicitly states the Cloud Build service account lacks permissions, not that the build steps are misconfigured. Option C is wrong because if the Cloud Deploy API were not enabled, the error would typically indicate that the API is not available or that the resource is not found, not a specific permission denied error for creating releases. Option D is wrong because the Cloud Run Admin role (roles/run.admin) grants permissions for Cloud Run services, not for Cloud Deploy release creation; Cloud Deploy uses its own IAM roles (e.g., Cloud Deploy Developer) to manage releases and delivery pipelines.

26
MCQmedium

Your team is deploying a stateful web application on Google Kubernetes Engine (GKE). The application requires each replica to have a stable network identity and its own persistent disk that survives pod restarts. You also need to ensure that the persistent disk is automatically provisioned and attached. Which GKE feature should you use?

A.DaemonSet with hostPath volumes
B.Deployment with a PersistentVolumeClaim
C.StatefulSet with a PersistentVolumeClaim template
D.CronJob with a PersistentVolumeClaim
AnswerC

StatefulSets are designed for stateful applications, providing stable network identities and persistent storage. The volumeClaimTemplates automatically create a PersistentVolumeClaim for each replica, which dynamically provisions a PersistentVolume (e.g., a Compute Engine persistent disk) and attaches it to the pod. This meets the requirement for stable identity and persistent storage that survives pod restarts.

Why this answer

StatefulSets are the correct choice for stateful applications on GKE because they provide stable network identities and persistent storage per replica. The volumeClaimTemplates automatically create PVCs, which dynamically provision persistent disks. Deployments, DaemonSets, and CronJobs lack these features, making them unsuitable for this scenario.

Exam trap

The trap here is assuming that a Deployment with a PersistentVolumeClaim can provide stable network identities and per-replica storage, but Deployments are designed for stateless workloads and do not offer these guarantees.

27
MCQhard

A large enterprise is migrating their on-premises data center to Google Cloud. They have hundreds of VMs and need to minimize network latency between on-prem and cloud during migration. They have high bandwidth requirements. Which connectivity solution should they use?

A.Cloud Interconnect
B.Cloud VPN
C.Cloud NAT
D.Peering with Google
AnswerA

Cloud Interconnect provides dedicated private connectivity at 10 Gbps or 100 Gbps per attachment, bypassing the public internet. This satisfies the high-bandwidth, low-latency requirement for migrating hundreds of VMs, unlike VPN tunnels which traverse shared internet paths.

Why this answer

Cloud Interconnect provides a dedicated, high-bandwidth, low-latency connection between on-premises data centers and Google Cloud, bypassing the public internet. This is ideal for large-scale migrations with hundreds of VMs where minimizing latency and ensuring consistent throughput is critical.

Exam trap

The trap here is that candidates often confuse Cloud VPN with Cloud Interconnect, assuming VPN is sufficient for high-bandwidth, low-latency needs, but VPN's reliance on the public internet introduces jitter and bandwidth constraints that make it unsuitable for large-scale migrations.

How to eliminate wrong answers

Option B (Cloud VPN) is wrong because it uses IPSec tunnels over the public internet, which introduces variable latency, lower throughput limits, and no SLA for bandwidth, making it unsuitable for high-bandwidth, latency-sensitive migrations. Option C (Cloud NAT) is wrong because it is used to enable outbound internet access for private VMs without public IPs, not for establishing a private, low-latency connection between on-prem and cloud. Option D (Peering with Google) is wrong because it provides connectivity to Google services (e.g., YouTube, Gmail) via public peering points, not a dedicated private connection to a specific VPC network, and lacks SLA-backed bandwidth and latency guarantees required for enterprise migration.

28
MCQeasy

A company runs a batch processing workload on Compute Engine instances in a managed instance group (MIG). The job is CPU-intensive and takes approximately 4 hours to complete. The company wants to reduce costs without sacrificing performance. Which action should they take?

A.Purchase committed use discounts for the instance type.
B.Change the machine series to a smaller machine type.
C.Use preemptible VMs for the MIG and implement a checkpointing mechanism to handle interruptions.
D.Provision additional reserved VMs to ensure capacity.
AnswerC

Preemptible VMs cost substantially less than standard instances but can be reclaimed at any time, so checkpointing preserves progress across interruptions. This suits the four-hour CPU-intensive batch job, cutting cost while the MIG restarts reclaimed instances to maintain throughput.

Why this answer

Preemptible VMs are significantly cheaper than standard VMs but can be terminated at any time. For a batch processing workload that is CPU-intensive and runs for 4 hours, using preemptible VMs in a MIG with a checkpointing mechanism allows the job to resume from the last saved state after an interruption, thus reducing costs without sacrificing performance.

Exam trap

Google Cloud often tests the misconception that committed use discounts are the best cost-saving option for any workload, but they are only cost-effective for predictable, always-on instances, not for batch jobs that can leverage preemptible VMs.

How to eliminate wrong answers

Option A is wrong because committed use discounts require a 1- or 3-year commitment and do not reduce costs for short-lived or interruptible workloads; they are best for steady-state, always-on instances. Option B is wrong because changing to a smaller machine type would reduce performance, potentially increasing job duration and negating cost savings. Option D is wrong because provisioning additional reserved VMs increases costs without addressing the need to reduce them, and reserved VMs are not cost-effective for batch jobs that can tolerate interruptions.

29
MCQeasy

A developer needs to secure secrets (API keys, passwords) used in a Cloud Function. What is the recommended approach?

A.Store secrets in environment variables
B.Store in Cloud Storage and download at runtime
C.Use Secret Manager
D.Hard-code in the function code
AnswerC

Secret Manager stores API keys and passwords encrypted at rest, granting the Cloud Function access through IAM roles rather than embedding credentials in code or environment variables. This satisfies the stem's requirement to secure secrets, since versioned, audited retrieval replaces hard-coded values that leak through source control or function configuration.

Why this answer

Secret Manager is the recommended approach for securing sensitive data like API keys and passwords in Cloud Functions because it provides encrypted storage, fine-grained access control via IAM, and automatic rotation. Unlike environment variables, which are visible in the Cloud Console and logs, Secret Manager ensures secrets are never exposed in plaintext and are injected securely at runtime.

Exam trap

Google Cloud often tests the misconception that environment variables are a secure way to store secrets because they are 'hidden' from code, but in reality they are plaintext and accessible via the Cloud Console and logs.

How to eliminate wrong answers

Option A is wrong because environment variables are not encrypted by default and can be viewed in the Cloud Console, logs, or by anyone with access to the function's configuration, making them insecure for secrets. Option B is wrong because storing secrets in Cloud Storage requires managing bucket permissions and encryption keys manually, and downloading at runtime introduces latency and potential exposure if the bucket is misconfigured. Option D is wrong because hard-coding secrets in function code exposes them in source control, build artifacts, and logs, violating security best practices and making rotation nearly impossible.

30
MCQeasy

A startup is migrating a monolithic application to Google Cloud. They want to minimize operational overhead and auto-scale based on HTTP request load. Which compute solution should they choose?

A.Compute Engine managed instance groups with autoscaling
B.Google Kubernetes Engine (GKE)
C.Cloud Functions
D.Cloud Run
AnswerD

Cloud Run is fully managed and scales to zero, removing cluster and node operational overhead entirely. It autoscales on HTTP request concurrency, directly satisfying the startup's requirement to scale with request load without managing infrastructure.

Why this answer

Cloud Run is the best choice because it is a fully managed serverless platform that automatically scales from zero based on HTTP request load, minimizing operational overhead. It abstracts away infrastructure management, supports containerized applications, and charges only for resources used during request processing, aligning perfectly with the requirement to auto-scale based on HTTP traffic.

Exam trap

The trap here is that candidates often choose GKE or Compute Engine for 'auto-scaling' without recognizing that serverless options like Cloud Run offer the same capability with significantly less operational overhead for HTTP-based workloads.

How to eliminate wrong answers

Option A is wrong because Compute Engine managed instance groups with autoscaling require managing virtual machines, patching OS, and configuring scaling policies, which increases operational overhead compared to serverless options. Option B is wrong because Google Kubernetes Engine (GKE) introduces cluster management, node patching, and container orchestration complexity, which is not minimal operational overhead for a simple HTTP workload. Option C is wrong because Cloud Functions is designed for event-driven, short-lived functions, not for running a monolithic application that typically requires a persistent runtime environment and longer request handling.

31
MCQmedium

A company is migrating a monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single Compute Engine instance and stores session state in local memory. The migration must support horizontal scaling and high availability. What should the company do to manage session state in the new architecture?

A.Refactor the application to store session state in Cloud Memorystore for Redis and make the application stateless.
B.Use a StatefulSet with a headless service to assign stable network identities to pods.
C.Use GKE Ingress with session affinity (sticky sessions) to route requests to the same pod.
D.Store session state in Cloud SQL using a replicated database.
AnswerA

Storing session state in Cloud Memorystore for Redis externalises it from pod memory, so any replica can serve any request and pods can scale or restart freely, satisfying the horizontal scaling and high availability constraints of the GKE migration.

Why this answer

Migrating to a stateless architecture with Cloud Memorystore for Redis allows the application to scale horizontally without session state being tied to any single pod. By externalizing session state to a managed, highly available Redis service, any pod can handle any request, which is essential for high availability and autoscaling in GKE.

Exam trap

Google Cloud often tests the distinction between 'making the application stateless' versus 'using sticky sessions or StatefulSets'—the trap here is that candidates may think session affinity (Option C) is sufficient for high availability, but it actually creates a single point of failure at the pod level.

How to eliminate wrong answers

Option B is wrong because StatefulSets with headless services are designed for stateful workloads that require stable network identities and persistent storage, not for managing session state in a horizontally scalable stateless application. Option C is wrong because GKE Ingress with session affinity (sticky sessions) ties a client to a specific pod, which prevents true horizontal scaling and high availability—if that pod fails, the session is lost. Option D is wrong because Cloud SQL is a relational database not optimized for high-speed session state access; using it for session storage would introduce latency and unnecessary overhead compared to an in-memory data store like Redis.

32
MCQhard

A company is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that each microservice can only communicate with specific other microservices, and they need to enforce this at the network level. They also want to minimize operational overhead. Which approach should they use?

A.Configure VPC firewall rules to allow or deny traffic between GKE nodes.
B.Use Kubernetes NetworkPolicies to define ingress and egress rules between pods.
C.Use Google Cloud Armor security policies to restrict traffic between services.
D.Implement a service mesh like Istio to manage service-to-service communication.
AnswerB

Kubernetes NetworkPolicies allow you to specify which pods can communicate with each other based on labels and namespaces. They are enforced by the container network interface (CNI) plugin, such as Calico, which is available in GKE. This approach provides fine-grained control at the pod level and is native to Kubernetes, minimizing operational overhead compared to custom solutions.

Why this answer

Kubernetes NetworkPolicies are the native, low-overhead way to enforce pod-level network segmentation in GKE. They allow you to define which pods can communicate based on labels and namespaces, and they are enforced by the CNI plugin. This meets the requirement for fine-grained control with minimal operational effort compared to a service mesh or node-level firewall rules.

Exam trap

The trap here is assuming that VPC firewall rules can provide pod-level isolation, but they operate at the node level and cannot distinguish between pods.

33
Multi-Selecteasy

Which TWO of the following are benefits of using a VPC Service Controls perimeter?

Select 2 answers
A.Prevent data exfiltration from managed services like BigQuery and Cloud Storage
B.Act as a network firewall for Compute Engine instances
C.Provide encryption of data in transit between on-premises and Google Cloud
D.Replace Identity and Access Management (IAM) for service access control
E.Allow access to Google Cloud services only from within an authorized VPC network
AnswersA, E

VPC Service Controls builds a security perimeter around Google-managed services, restricting data movement across its boundary. This directly blocks exfiltration paths such as copying BigQuery datasets or Cloud Storage objects to unauthorised projects, satisfying the containment requirement.

Why this answer

VPC Service Controls perimeters are designed to mitigate data exfiltration risks for managed services such as BigQuery, Cloud Storage, and other Google Cloud APIs, so option A is correct because the perimeter restricts data movement across its boundary even when credentials are valid. Option E is also correct because a perimeter defines an authorized boundary (based on VPC networks, projects, and access levels) from which managed services can be reached, effectively allowing access only from authorized VPC networks. Option B is wrong because VPC Service Controls is not a network firewall for Compute Engine instances; that role belongs to VPC firewall rules and hierarchical firewall policies.

Option C is wrong because encryption in transit between on-premises and Google Cloud is handled by mechanisms such as Cloud VPN, Cloud Interconnect with MACsec, or application-layer TLS, not by VPC Service Controls. Option D is wrong because VPC Service Controls complements rather than replaces IAM; IAM still governs identities and permissions, while the perimeter adds an independent context-aware boundary.

Exam trap

Google Cloud often tests the misconception that VPC Service Controls are a firewall or encryption mechanism, when in fact they are a context-aware access boundary that works alongside IAM and network controls.

34
MCQmedium

You are deploying a new version of a microservices application to a GKE cluster. The deployment must be released to a small subset of users first, and if errors occur, traffic must automatically revert to the previous version. You also need to monitor the error rate and latency of the new version. Which approach should you use?

A.Create two separate GKE clusters, one for the old version and one for the new version, and use a global load balancer to split traffic 50/50. Monitor errors and manually shift traffic back if needed.
B.Deploy the new version as a separate Kubernetes Service and use an Ingress with session affinity to route a percentage of users to the new version. Monitor errors and adjust the Ingress configuration manually.
C.Use a Kubernetes Deployment with a rolling update and configure readiness probes; use kubectl rollout undo if errors occur.
D.Use Anthos Service Mesh to implement a canary deployment with traffic splitting, and configure automatic rollback based on error rate metrics.
AnswerD

Anthos Service Mesh provides traffic splitting, allowing you to send a percentage of traffic to the new version. It integrates with Cloud Monitoring to automatically roll back if error rates exceed thresholds. This directly satisfies the canary release and automatic revert requirements, and provides observability for latency and errors.

Why this answer

Anthos Service Mesh offers advanced traffic management, including canary deployments with precise traffic splitting and automated rollback triggered by monitoring metrics. This aligns with the need to release to a subset, monitor, and revert automatically. The other options lack either the fine-grained traffic control or the automation required.

Exam trap

The trap here is assuming that a Kubernetes rolling update or Ingress can perform canary releases with automatic rollback, but they lack native traffic splitting and metric-based automation.

35
MCQeasy

A company has a Cloud Run service that processes images uploaded by users. The service reads the images from a Cloud Storage bucket and writes processed images to another bucket. The team recently updated the service to use a custom service account named 'image-processor-sa' with minimal permissions. After the update, the service fails with permission errors when trying to read from the source bucket. The team verified that the service account has the Storage Object Viewer role on the source bucket and Storage Object Creator role on the destination bucket. What should the architect do to resolve the issue?

A.Ensure the Cloud Run service uses the correct service account by redeploying with the --service-account flag set to 'image-processor-sa@project-id.iam.gserviceaccount.com'.
B.Grant the service account the Cloud Run Invoker role on the Cloud Run service.
C.Assign the Storage Admin role to the service account.
D.Enable the Cloud Storage API for the project.
AnswerA

Cloud Run defaults to the Compute Engine default service account unless explicitly overridden, so the new permissions were never applied. Redeploying with the --service-account flag binds the revision to image-processor-sa, letting its Storage Object Viewer role take effect.

Why this answer

The error occurs because the Cloud Run service is not using the custom service account 'image-processor-sa' despite it being created and granted permissions. By default, Cloud Run uses the Compute Engine default service account unless explicitly overridden. Redeploying with the --service-account flag attaches the correct identity to the Cloud Run revision, allowing it to authenticate with Cloud Storage using the minimal permissions already assigned.

Exam trap

Google Cloud often tests the distinction between granting permissions to a service account versus actually attaching that service account to a resource; candidates mistakenly assume that creating and granting roles to a service account automatically makes it the active identity of the Cloud Run service.

How to eliminate wrong answers

Option B is wrong because the Cloud Run Invoker role grants permission to invoke the service (i.e., call its HTTP endpoint), not to read from Cloud Storage; it does not resolve the missing identity binding. Option C is wrong because assigning Storage Admin is an overly permissive solution that violates the principle of least privilege; the service account already has the necessary Object Viewer and Object Creator roles, so the issue is not about missing permissions but about the service not using the correct account. Option D is wrong because the Cloud Storage API is enabled by default when Cloud Storage is used; the error is not due to a disabled API but due to the service running under the wrong identity.

36
MCQmedium

A company is deploying a new application on Compute Engine and wants to automate the installation of a custom agent on every newly created VM in a specific project. Which Google Cloud service should they use?

A.VM Manager (OS Config) with a guest policy to install the agent.
B.Instance templates with startup scripts.
C.Deployment Manager with a template that includes the agent installation.
D.Cloud Build triggered on new VM creation events.
AnswerA

VM Manager's OS Config agent executes guest policies on Compute Engine instances, letting a policy assignment target the project so the custom agent installs automatically at each VM's creation. This directly satisfies the requirement for automated installation across every newly created VM in that specific project.

Why this answer

VM Manager (OS Config) with a guest policy is the correct choice because it provides a native, agent-based configuration management service that can enforce the installation of a custom agent on all existing and newly created VMs in a project without requiring changes to instance templates or startup scripts. Guest policies are evaluated and applied at VM boot time and periodically thereafter, ensuring consistent agent deployment across the fleet.

Exam trap

The trap here is that candidates often confuse configuration management (OS Config guest policies) with provisioning-time automation (startup scripts in instance templates), assuming that startup scripts are sufficient for fleet-wide enforcement when they only apply at creation time and are not re-evaluated.

How to eliminate wrong answers

Option B is wrong because instance templates with startup scripts only apply to VMs created from that specific template; they do not automatically cover VMs created from other templates, images, or via other methods, and they do not enforce the agent on existing VMs. Option C is wrong because Deployment Manager is an infrastructure-as-code tool for deploying resources, not a configuration management service; it cannot automatically apply agent installation to VMs created outside its deployment scope. Option D is wrong because Cloud Build is a CI/CD service for building and testing artifacts, and it cannot be triggered directly by new VM creation events; there is no native event trigger for Compute Engine VM creation in Cloud Build.

37
MCQhard

A financial services company uses VPC Service Controls to protect their project containing BigQuery datasets and Cloud Storage buckets. They have a perimeter that includes the BigQuery service. Users report that they cannot export data from BigQuery to Cloud Storage using the web console. The export job fails with an access denied error. The team needs to allow exports while maintaining data exfiltration prevention. The users have the necessary IAM permissions (BigQuery Data Editor, Storage Object Admin) on the appropriate resources. What should the architect do?

A.Add Cloud Storage to the same VPC Service Controls perimeter.
B.Remove BigQuery from the VPC Service Controls perimeter.
C.Create an access level that permits exports during business hours.
D.Grant the users the Storage Object Admin role at the bucket level.
AnswerA

VPC Service Controls blocks cross-perimeter data movement, so the BigQuery-to-Cloud-Storage export is denied because Cloud Storage sits outside the perimeter. Adding Cloud Storage to the same perimeter authorises that API path while preserving exfiltration prevention, satisfying the requirement to allow exports without weakening controls.

Why this answer

VPC Service Controls perimeters enforce data exfiltration prevention by default, blocking egress from protected services (like BigQuery) to unprotected services (like Cloud Storage). Adding Cloud Storage to the same perimeter allows BigQuery to export data to Cloud Storage while still preventing data from leaving the perimeter. The users already have the necessary IAM roles (BigQuery Data Editor and Storage Object Admin), so the issue is solely the perimeter boundary, not permissions.

Exam trap

The trap here is that candidates often confuse IAM permissions with VPC Service Controls boundaries, assuming that granting the correct IAM roles (like Storage Object Admin) will resolve the access denied error, when in fact the error is caused by the perimeter blocking cross-service egress, not by insufficient IAM privileges.

How to eliminate wrong answers

Option B is wrong because removing BigQuery from the perimeter would disable all VPC Service Controls protections for BigQuery, exposing the datasets to data exfiltration risks, which contradicts the requirement to maintain data exfiltration prevention. Option C is wrong because access levels control ingress based on client attributes (e.g., IP address, device state) and do not affect egress permissions between services within a perimeter; the export failure is a perimeter boundary issue, not an access level restriction. Option D is wrong because the users already have the Storage Object Admin role at the bucket level (as stated in the question), and the error is an access denied from the perimeter, not from IAM; granting the same role again does not resolve the VPC Service Controls boundary.

38
Multi-Selecthard

Which THREE factors should be considered when choosing a Google Cloud region for deploying a low-latency application serving global users? (Choose three.)

Select 3 answers
A.Proximity to your user base to minimize network latency.
B.Availability of the specific Google Cloud services required by the application.
C.Pricing differences between regions due to variations in compute and storage costs.
D.Compliance with data residency requirements (e.g., GDPR, CCPA).
E.Number of zones in the region to ensure high availability.
AnswersA, B, D

Placing the region close to users shortens the physical network path, directly reducing round-trip latency for a global low-latency application. Distance is the dominant factor because light-speed propagation through fibre cannot be optimised away by configuration.

Why this answer

Option A is correct because placing the region close to the user base reduces round-trip network latency, which is the primary driver of perceived responsiveness for a low-latency application serving global users. Option B is correct because not every Google Cloud service or machine type is available in every region, so you must confirm the required services (for example, specific compute SKUs or managed services) exist in the chosen region before deploying. Option D is correct because data residency and privacy regulations such as GDPR or CCPA can legally require that user data be stored and processed within specific jurisdictions, directly constraining which regions are permissible.

Option C is not among the marked answers because, while regional pricing differences exist, cost optimization is secondary to latency, service availability, and legal compliance when the explicit goal is low-latency global service. Option E is not among the marked answers because the number of zones affects fault tolerance and high availability rather than the latency experienced by global users, and zone count is not the deciding factor for region selection in this scenario.

Exam trap

This exam often tests the misconception that high availability (zones) is equivalent to low latency for global users, but zones only provide redundancy within a region, not reduced network distance for geographically distributed users.

39
MCQeasy

A developer accidentally deleted a bucket in Cloud Storage. The bucket had object versioning enabled. How can the bucket and its objects be restored?

A.Contact Cloud Support to restore the bucket from the undisclosed backup within a limited time window.
B.Restore the bucket from the Trash in the Cloud Console.
C.Enable bucket lock and then undo deletion.
D.Use the gsutil ls -a command to list deleted buckets and gsutil cp to restore.
AnswerA

Object versioning preserves noncurrent object versions, but deleting the bucket itself removes the container. Only Cloud Support can restore the entire bucket from Google's undisclosed internal backup within the limited window, after which the versioned objects return.

Why this answer

When a Cloud Storage bucket is deleted, even with versioning enabled, the bucket itself is removed along with its objects. Google Cloud does not provide a self-service restore option for deleted buckets; instead, it maintains an internal, undisclosed backup for a limited time (typically 7 days). Only Cloud Support can initiate the restoration process from this backup, making Option A the correct approach.

Exam trap

Google Cloud often tests the misconception that versioning provides a safety net for bucket deletion, but versioning only protects objects within an existing bucket—it does not prevent or undo the deletion of the bucket itself.

How to eliminate wrong answers

Option B is wrong because Cloud Storage does not have a 'Trash' feature for buckets; the Trash in Cloud Console is for Compute Engine resources like VM instances, not for storage buckets. Option C is wrong because bucket lock is a feature for retention policies (e.g., preventing object deletion or modification), not for undoing a bucket deletion; once a bucket is deleted, there is no 'undo deletion' operation. Option D is wrong because the `gsutil ls -a` command lists object versions within an existing bucket, not deleted buckets; there is no `gsutil` command to list or restore a deleted bucket.

40
MCQmedium

A company is using Cloud SQL for PostgreSQL and needs to run a one-time heavy analytical query that takes over 30 minutes and uses 100% CPU. The production database is serving user traffic with high QPS. What should the company do to run the query without impacting production?

A.Run the query directly on the primary instance during low traffic hours.
B.Create a read replica of the production instance and run the query on the replica.
C.Use Cloud SQL's pgBouncer to pool connections and queue the query.
D.Create a clone of the production instance and run the query on the clone.
AnswerB

A read replica receives its own compute and storage, so the 30-minute analytical query consumes replica CPU without competing with production traffic. Replication is asynchronous, so the query reads slightly stale data, which is acceptable for analytics.

Why this answer

A read replica in Cloud SQL for PostgreSQL is a separate instance that asynchronously replicates data from the primary. Running the heavy analytical query on the replica offloads the CPU-intensive workload from the production primary, ensuring user-facing traffic with high QPS is not impacted. The replica can handle read-only queries without affecting the primary's performance or availability.

Exam trap

Google Cloud often tests the distinction between a read replica (which offloads read traffic) and a clone (which is a point-in-time copy not kept in sync), leading candidates to choose the clone option because they confuse it with a replica's ability to handle production queries without impact.

How to eliminate wrong answers

Option A is wrong because even during low traffic hours, a query using 100% CPU on the primary instance will still degrade performance for any concurrent user requests, risking latency spikes or timeouts. Option C is wrong because pgBouncer is a connection pooler that manages database connections, not a query scheduler or resource isolator; it cannot queue or throttle a single heavy query to prevent CPU saturation. Option D is wrong because a clone creates a new primary instance from a snapshot, which requires provisioning time and does not provide ongoing replication; it is suitable for testing or development but not for running a one-time query without impacting production, as the clone is not kept in sync and the heavy query still runs on a separate instance that does not offload the primary's workload.

41
MCQeasy

Your company runs a critical application on Compute Engine instances in a managed instance group across three zones. The application writes logs to local disk. You are asked to improve the reliability of log retention and ensure logs are available in case of instance failure. You have already configured a health check that automatically recreates instances. However, after a recent zonal outage, logs from the affected instances were lost. You need to implement a solution that preserves logs even when instances are terminated. What should you do?

A.Increase the size of the local SSD to accommodate more logs and set a longer retention period.
B.Configure each instance to write logs to a persistent disk that is retained after instance deletion.
C.Install the Cloud Logging agent on each instance and configure it to stream application logs to Cloud Logging.
D.Mount a Cloud Storage bucket using gcsfuse on each instance and write logs directly to the bucket.
AnswerC

Local disk logs are lost when an instance is terminated or recreated. Streaming them off-instance to Cloud Logging decouples retention from instance lifecycle, so logs survive zonal outages and instance failure, satisfying the requirement to preserve logs even when instances are terminated.

Why this answer

The Cloud Logging agent streams logs directly to Cloud Logging (now part of Google Cloud's operations suite), which stores logs independently of the Compute Engine instances. This ensures logs are preserved even if instances are terminated due to a zonal outage or health check recreation, as logs are sent to a centralized, durable logging service rather than being stored on local disk.

Exam trap

Google Cloud often tests the misconception that persistent disks or Cloud Storage buckets are sufficient for log durability, but the key requirement is centralized log management with automatic streaming, which only Cloud Logging provides without additional complexity or latency.

How to eliminate wrong answers

Option A is wrong because increasing local SSD size and retention period does not protect logs from instance termination; local SSDs are ephemeral and their data is lost when an instance is deleted or recreated. Option B is wrong because persistent disks are not automatically retained after instance deletion unless the 'delete-on-terminate' flag is set to false, and even then, logs would be tied to a specific disk that may not survive a zonal outage if not replicated; the question requires a solution that works across instance failures, not just disk retention. Option D is wrong because while gcsfuse can mount a Cloud Storage bucket, writing logs directly to a bucket introduces latency and potential consistency issues, and the bucket is not a log management solution; Cloud Logging is purpose-built for log ingestion, analysis, and retention.

42
Multi-Selectmedium

Your organization is moving a legacy monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single virtual machine with a local MySQL database. You need to design a cloud-native architecture that improves scalability and reliability. Which two actions should you take? (Choose TWO.)

Select 2 answers
A.Deploy the entire application in a single container with a large custom machine type to handle load.
B.Refactor the application into microservices and deploy each as a separate deployment in GKE.
C.Expose the application using a simple Service of type LoadBalancer with round-robin distribution.
D.Use Cloud SQL for MySQL instead of running the database in the same cluster.
E.Use a single Pod with multiple containers that communicate via localhost to reduce latency.
AnswersB, D

Splitting the monolith into microservices, each deployed as its own GKE Deployment, lets components scale and fail independently, directly addressing the scalability and reliability constraints of the single-VM legacy design. Independent Deployments also enable rolling updates per service rather than whole-application redeployment.

Why this answer

Option B is correct because refactoring the monolith into microservices and deploying each as a separate Deployment in GKE enables independent scaling, rolling updates, and fault isolation, which directly improves scalability and reliability in a cloud-native architecture. Option D is correct because moving the local MySQL database to Cloud SQL for MySQL provides a managed, highly available, and automatically backed-up database service, decoupling state from the cluster and allowing the application tier to scale independently. Option A is not appropriate because a single large container on a custom machine type preserves the monolithic scaling and single-point-of-failure limitations rather than adopting cloud-native elasticity.

Option C is not the best choice because a basic LoadBalancer Service only provides L4 round-robin distribution and does not by itself deliver the architectural scalability and reliability improvements required. Option E is incorrect because a single Pod with multiple containers communicating via localhost tightly couples the components, prevents independent scaling, and keeps the database co-located with the application, undermining reliability.

Exam trap

Google Cloud often tests the misconception that simply containerizing a monolith or using a larger machine type is sufficient for cloud-native scalability, when in fact true scalability requires decoupling components into independently scalable units and separating stateful services like databases.

43
Multi-Selectmedium

A company is migrating an on-premises application to Google Cloud. The application consists of a web front end and a backend that uses a relational database. The company wants to minimize downtime during the migration and ensure that the database remains consistent. They plan to use a phased approach. Which TWO steps should they take to achieve a successful migration? (Choose two.)

Select 2 answers
A.Use Database Migration Service to continuously replicate data from the on-premises database to a Cloud SQL instance, then perform a cutover.
B.Configure Cloud SQL read replicas in multiple regions to ensure high availability and offload read traffic.
C.Set up a Cloud VPN or Dedicated Interconnect between on-premises and Google Cloud to establish a secure network connection.
D.Deploy the web front end on Compute Engine instances and use a managed instance group with autoscaling to handle traffic.
E.Export the on-premises database to a CSV file, upload it to Cloud Storage, and import it into Cloud SQL during a maintenance window.
AnswersA, C

Database Migration Service supports continuous replication from various sources to Cloud SQL, allowing you to keep the target in sync with minimal downtime. After initial load, it replicates ongoing changes, and you can promote the Cloud SQL instance during a short cutover window. This directly addresses the requirement for minimal downtime and data consistency.

Why this answer

Establishing a secure network connection and using Database Migration Service for continuous replication are critical for a low-downtime migration. The network connection enables data transfer, and Database Migration Service keeps the target in sync until cutover. These steps ensure minimal downtime and data consistency, unlike manual export/import or unrelated scaling measures.

Exam trap

The trap here is focusing on post-migration scaling or high availability features instead of the core steps needed to perform the migration with minimal downtime.

44
MCQmedium

A company uses preemptible VMs for batch processing. They notice that during peak hours, many instances are terminated before finishing their tasks. The operations team observes the output shown in the exhibit. Which action would best improve job completion rates without significantly increasing costs?

A.Increase the number of instances to compensate for terminations
B.Use sole-tenant nodes for these instances
C.Use instance groups with a mix of preemptible and regular VMs
D.Use committed use discounts for 1 year
E.Switch to regular VMs for critical jobs
AnswerC

Mixing preemptible and regular VMs in a managed instance group lets batch workloads continue on standard instances when preemptible capacity is reclaimed, directly addressing the premature termination constraint. Autoscaling and instance templates maintain throughput during peak hours, while the preemptible portion keeps costs low.

Why this answer

Using a mixed instance group with both preemptible and regular VMs allows the batch processing job to continue on regular VMs when preemptible VMs are terminated during peak hours. This balances cost and reliability: preemptible VMs handle most of the workload at low cost, while regular VMs act as a fallback to ensure job completion without the full expense of switching entirely to regular VMs.

Exam trap

Google Cloud often tests the misconception that simply adding more preemptible VMs or switching entirely to regular VMs is the solution, but the correct answer requires a hybrid approach that balances cost and reliability using instance groups with a mix of VM types.

How to eliminate wrong answers

Option A is wrong because simply increasing the number of preemptible instances does not address the root cause of terminations during peak hours; it only increases the likelihood of more terminations and may lead to higher costs from repeated restarts. Option B is wrong because sole-tenant nodes provide dedicated hardware but do not prevent preemption; they are used for compliance or licensing, not for improving job completion rates of preemptible VMs. Option D is wrong because committed use discounts require a 1-year commitment and apply to regular VMs, not preemptible VMs, so they would increase costs without solving the termination issue.

Option E is wrong because switching all critical jobs to regular VMs would significantly increase costs, as regular VMs are more expensive than preemptible VMs, and the question asks for an improvement without significantly increasing costs.

45
MCQhard

An organization wants to enforce that all Compute Engine VMs are created with specific disk encryption keys. Which policy mechanism should they use?

A.Organization policies with constraints/compute.restrictDiskEncryptionKeyTypes
B.IAM roles with compute.diskEncryptionKey permissions
C.VPC Service Controls
D.Cloud Scheduler to check compliance
AnswerA

Organization policies with `constraints/compute.restrictDiskEncryptionKeyTypes` enforce CMEK requirements at the resource hierarchy level, blocking VM creation that lacks customer-managed encryption keys. This satisfies the stem's constraint that all Compute Engine VMs must be created with specific disk encryption keys, applying prevention rather than detection.

Why this answer

The Organization Policy constraint `constraints/compute.restrictDiskEncryptionKeyTypes` allows administrators to enforce that all Compute Engine VMs must use specific disk encryption key types (e.g., CMEK or CSEK). This policy is evaluated at resource creation time and blocks any VM that does not comply with the allowed key types, providing a preventive control rather than a reactive one.

Exam trap

The trap here is confusing IAM permissions (who can do something) with Organization Policy constraints (what is allowed to be done), leading candidates to choose IAM roles instead of the correct policy mechanism.

How to eliminate wrong answers

Option B is wrong because IAM roles with `compute.diskEncryptionKey` permissions control who can set or view encryption keys, but they do not enforce which key types must be used on VMs; IAM is an authorization mechanism, not a policy enforcement mechanism. Option C is wrong because VPC Service Controls are designed to protect data exfiltration by controlling access to Google Cloud APIs from outside a VPC perimeter, not to enforce disk encryption key types on Compute Engine VMs. Option D is wrong because Cloud Scheduler is a cron-like job scheduler that can trigger compliance checks, but it is a reactive, after-the-fact mechanism and cannot prevent non-compliant VM creation in real time.

46
MCQmedium

Your team has deployed a microservices application on Google Kubernetes Engine (GKE) with multiple services communicating via internal ClusterIP services. You notice that some requests between services are failing intermittently with 'connection refused' errors. The services are defined with readiness probes. What is the most likely cause?

A.The readiness probes are not passing, causing the service endpoints to be removed.
B.The services are not exposed via a VPC peering connection to the client's VPC.
C.The services are using NodePort instead of LoadBalancer type, causing port conflicts.
D.The services are not associated with an Ingress resource.
AnswerA

Failing readiness probes cause the pod to be removed from service endpoints, leading to connection refused.

Why this answer

The 'connection refused' error indicates that the client is attempting to connect to a port on which no process is listening. In GKE, when a readiness probe fails, Kubernetes removes the pod's IP from the corresponding ClusterIP service's endpoints. If all pods for a service fail their readiness probes, the service has no healthy endpoints, and any request to the ClusterIP will be refused because there is no backend to accept the connection.

This matches the intermittent nature of the issue, as pods may temporarily fail the probe and then recover.

Exam trap

Google Cloud often tests the distinction between readiness and liveness probes, where candidates may incorrectly assume that a failing liveness probe (which restarts the pod) is the cause of 'connection refused', but the key is that readiness probes control endpoint membership, directly causing the error when all endpoints are removed.

How to eliminate wrong answers

Option B is wrong because VPC peering is used for connectivity between separate VPC networks, not for internal service-to-service communication within the same GKE cluster; ClusterIP services are inherently reachable within the cluster without any peering. Option C is wrong because NodePort and LoadBalancer are service types for external exposure, not for internal pod-to-pod communication; port conflicts are not a typical cause of 'connection refused' errors within a cluster, and NodePort does not affect internal ClusterIP functionality. Option D is wrong because an Ingress resource is used for external HTTP/S traffic routing to services, not for internal service-to-service communication; the absence of an Ingress has no impact on direct ClusterIP-based communication between microservices.

47
MCQeasy

You are designing a solution to store and serve static web content for a global audience. The content consists of HTML, CSS, JavaScript, and images. You need to ensure low latency and high availability. Which Google Cloud service should you use?

A.Cloud Storage with a multi-region bucket and Cloud CDN.
B.Compute Engine instances in multiple regions behind a global load balancer.
C.Cloud Run services deployed in multiple regions with a global load balancer.
D.App Engine standard environment with a custom domain and Cloud CDN.
AnswerA

Cloud Storage multi-region buckets provide high availability and geo-redundancy, and Cloud CDN caches content at edge locations worldwide, reducing latency. This combination is ideal for serving static web content globally. It requires minimal configuration and scales automatically.

Why this answer

Cloud Storage with a multi-region bucket provides durable, highly available storage, and Cloud CDN caches content globally to reduce latency. This is the simplest and most cost-effective solution for static web content. The other options involve unnecessary compute resources or management overhead.

Exam trap

The trap here is overcomplicating the solution by using compute services when a simple storage and CDN combination suffices.

48
MCQmedium

Your organization has a policy that all Compute Engine instances must have specific labels (env, team, cost-center) applied. You want to enforce this automatically when instances are created. What should you do?

A.Enable Cloud Audit Logs and set up a metric-based alert to detect instances without labels.
B.Create a Cloud Function that listens for instance creation events and adds labels automatically.
C.Assign a custom IAM role that includes permission to label instances, and remove the default compute.instances.create permission.
D.Use the Organization Policy service with a custom constraint to require labels on Compute Engine instances.
AnswerD

Organization Policy custom constraints let you define and enforce label requirements across the project hierarchy, blocking non-compliant instance creation at the API level. This satisfies the policy's demand for automatic enforcement at creation time, rather than relying on manual labelling or post-hoc auditing.

Why this answer

Organization Policy Service with a custom constraint allows you to enforce that all Compute Engine instances must have specific labels (env, team, cost-center) at creation time. This is a preventive control that blocks creation of non-compliant instances, unlike reactive or permission-based approaches. Custom constraints use the `compute.googleapis.com/instance` resource type and can require label keys or values using CEL (Common Expression Language) syntax.

Exam trap

The trap here is that candidates often choose reactive solutions (like Cloud Functions or alerts) because they seem simpler, but the exam emphasizes preventive enforcement using Organization Policy constraints for compliance-driven requirements.

How to eliminate wrong answers

Option A is wrong because Cloud Audit Logs and metric-based alerts are reactive — they only detect non-compliant instances after creation, not prevent them, and do not enforce the policy automatically. Option B is wrong because a Cloud Function that listens for instance creation events and adds labels is also reactive; it can fail or be bypassed, and the instance is created without labels initially, violating the policy. Option C is wrong because removing the default `compute.instances.create` permission would prevent all instance creation, not just unlabeled ones, and a custom IAM role cannot enforce label requirements at creation time — it only controls who can create instances, not what labels they must include.

49
MCQeasy

A company is migrating a monolithic application to Google Cloud. They want to minimize changes to the application code while taking advantage of Cloud Run for serverless containers. Which approach should they take?

A.Deploy the application to App Engine standard environment with automatic scaling.
B.Lift and shift the application to Compute Engine instances behind a load balancer.
C.Refactor the application into microservices and deploy each as a separate Cloud Run service.
D.Use Cloud Run by packaging the existing application as a container and listening on a web server.
AnswerD

Cloud Run accepts any container listening on the port defined by the PORT environment variable, so packaging the monolith unchanged and binding its existing web server satisfies the minimal-code-change constraint. No rewrite to functions or event-driven handlers is needed; the container contract alone enables serverless hosting.

Why this answer

Cloud Run can run any containerized application that listens on HTTP requests on port 8080. By packaging the existing monolithic application as a container and adding a lightweight web server (e.g., Express, Flask, or Nginx), the company can deploy it to Cloud Run with minimal code changes, leveraging serverless scaling and pay-per-use pricing without refactoring into microservices.

Exam trap

Google Cloud often tests the misconception that serverless containers require microservices architecture, but Cloud Run can run any containerized application, including a monolithic one, as long as it listens for HTTP requests.

How to eliminate wrong answers

Option A is wrong because App Engine standard environment requires the application to conform to specific runtime constraints (e.g., Java Servlet, Python WSGI) and does not support arbitrary containers, so it would likely require significant code changes. Option B is wrong because lifting and shifting to Compute Engine instances behind a load balancer does not minimize changes but also fails to take advantage of serverless containers, requiring manual management of VMs, scaling, and patching. Option C is wrong because refactoring the monolithic application into microservices is a major architectural change that contradicts the requirement to minimize changes to the application code.

50
MCQhard

A company runs a stateful application on a single Compute Engine instance with a persistent disk. They need to ensure that the application can recover quickly in case of a zone failure. The recovery point objective (RPO) is 5 minutes, and the recovery time objective (RTO) is 15 minutes. Which approach should they take?

A.Use a regional persistent disk with the instance, and configure the application to failover to a standby instance in another zone using a startup script that attaches the disk.
B.Create a snapshot schedule for the persistent disk every 5 minutes, and in case of failure, create a new instance from the latest snapshot in another zone.
C.Set up a Cloud SQL instance with high availability, and migrate the application to use Cloud SQL.
D.Use a managed instance group with autoscaling across multiple zones, and store application state on a Cloud Storage bucket mounted via Cloud Storage FUSE.
AnswerA

A regional persistent disk replicates data synchronously across two zones, providing an RPO of near zero. In case of zone failure, you can attach the disk to a standby instance in the other zone. With automation, failover can be achieved within the 15-minute RTO. This meets both RPO and RTO requirements.

Why this answer

A regional persistent disk synchronously replicates data across two zones, ensuring an RPO of zero. By automating failover to a standby instance in the other zone, you can achieve the 15-minute RTO. This is the most suitable solution for a stateful application requiring zone failure recovery.

The other options either do not meet the RPO/RTO or require significant application changes.

Exam trap

The trap here is assuming that frequent snapshots can meet a 5-minute RPO, but snapshot frequency is limited and restore times may exceed the RTO.

51
MCQeasy

A company wants to store customer transaction logs for 7 years for compliance. The logs are accessed rarely but must be retrievable within 24 hours. Which storage option is most cost-effective?

A.Cloud Storage Archive class
B.Cloud Storage Nearline class
C.Cloud Storage Coldline class
D.Cloud Storage Standard class
AnswerA

Archive class offers the lowest storage price for data retained years and rarely read, with retrieval typically within hours, comfortably meeting the 24-hour deadline. Nearline or Coldline cost more per gigabyte for this access pattern.

Why this answer

Cloud Storage Archive class is the most cost-effective option for data that is accessed rarely and requires retrieval within 24 hours. Archive class offers the lowest storage cost among Google Cloud Storage classes, with a default retrieval time of 12 hours, which comfortably meets the 24-hour requirement. This makes it ideal for long-term compliance retention of transaction logs that are infrequently accessed.

Exam trap

Google Cloud often tests the misconception that Coldline is the cheapest storage class, but Archive class actually has the lowest storage cost, with retrieval times up to 24 hours, making it the correct choice for rarely accessed data with flexible retrieval requirements.

How to eliminate wrong answers

Option B (Cloud Storage Nearline class) is wrong because it is designed for data accessed less than once a month, with a 30-day minimum storage duration, and its storage cost is higher than Archive, making it less cost-effective for 7-year retention. Option C (Cloud Storage Coldline class) is wrong because it targets data accessed less than once a quarter, with a 90-day minimum storage duration, and its storage cost is higher than Archive, so it is not the most cost-effective for rarely accessed logs. Option D (Cloud Storage Standard class) is wrong because it is optimized for frequently accessed data with no minimum storage duration and has the highest storage cost, making it prohibitively expensive for long-term archival of rarely accessed logs.

52
Multi-Selecteasy

What are two best practices for designing a scalable Kubernetes architecture on GKE?

Select 2 answers
A.Use StatefulSets for stateless applications
B.Disable Cluster Autoscaler
C.Enable horizontal pod autoscaling
D.Use node pools with different machine types
E.Use a single zone cluster
AnswersC, D

Horizontal pod autoscaling adjusts replica counts dynamically based on observed CPU, memory or custom metrics, so the cluster absorbs traffic spikes without manual intervention. This directly satisfies the scalability requirement by matching capacity to demand, preventing both resource starvation under load and idle waste during quiet periods.

Why this answer

Option C is correct because enabling Horizontal Pod Autoscaling (HPA) lets GKE automatically adjust the number of pod replicas based on metrics such as CPU utilization or custom metrics, which is essential for handling variable load in a scalable architecture. Option D is correct because using multiple node pools with different machine types allows you to right-size workloads, isolate resource-intensive or specialized workloads (e.g., GPU, memory-optimized), and scale each pool independently, improving both efficiency and scalability. Option A is incorrect because StatefulSets are designed for stateful applications requiring stable network identities and persistent storage, not stateless workloads, which are better served by Deployments.

Option B is incorrect because disabling the Cluster Autoscaler prevents nodes from being added or removed automatically as demand changes, undermining scalability. Option E is incorrect because a single-zone cluster concentrates resources in one zone, reducing availability and limiting the ability to scale resiliently across zones.

Exam trap

Google Cloud often tests the misconception that StatefulSets are interchangeable with Deployments for stateless apps, or that disabling Cluster Autoscaler simplifies management, but the trap here is that candidates may overlook the need for multi-zonal clusters and autoscaling mechanisms to achieve true scalability and resilience in GKE.

53
Multi-Selecthard

Which THREE actions can help reduce costs for a BigQuery workload that runs frequent, ad-hoc analytical queries on a large dataset?

Select 3 answers
A.Enable automatic schema detection to avoid manual schema definition.
B.Partition the table by a date or timestamp column.
C.Create materialized views for common aggregation queries.
D.Use clustering on columns frequently used in filter clauses.
E.Use flat-rate pricing with reserved slots.
AnswersB, C, D

Partitioning by date or timestamp prunes scanned data, so ad-hoc analytical queries read only relevant partitions rather than the full table. This directly reduces bytes processed, and BigQuery bills on-demand queries by data scanned, satisfying the cost-reduction requirement for frequent large-dataset analysis.

Why this answer

Option B is correct because partitioning the table by a date or timestamp column lets BigQuery prune irrelevant partitions, so ad-hoc queries that filter on that column scan far less data and incur lower on-demand query costs. Option C is correct because materialized views precompute and cache the results of common aggregation queries, so repeated ad-hoc aggregations read the much smaller materialized view instead of rescanning the full large dataset. Option D is correct because clustering on columns frequently used in filter clauses co-locates related data in storage blocks, allowing BigQuery to skip blocks that don't match the filter and further reduce bytes scanned.

Option A is not correct because automatic schema detection only simplifies loading data and has no effect on query cost. Option E is not correct because flat-rate pricing with reserved slots provides predictable capacity billing rather than reducing the cost of a sporadic ad-hoc query workload, which is typically cheaper on on-demand pricing.

Exam trap

Google Cloud often tests the distinction between cost-reduction techniques that reduce bytes scanned (partitioning, clustering, materialized views) versus pricing model choices (flat-rate vs. on-demand), leading candidates to mistakenly select flat-rate pricing as a cost-saving action for ad-hoc queries.

54
MCQmedium

A company is using Cloud Load Balancing with backend services across multiple regions. They notice that traffic is not being evenly distributed and some backends are overloaded. Which configuration should they check?

A.Session affinity settings
B.Firewall rules
C.Cloud CDN caching
D.Health check frequency
AnswerA

Session affinity pins each client to one backend for the session's duration, so new connections bypass least-loaded selection and concentrate on whichever backend the client first reached. Checking this setting satisfies the stem's uneven distribution constraint: disabling or shortening affinity restores per-connection balancing across regional backends.

Why this answer

Session affinity (sticky sessions) directs all requests from a single client to the same backend instance. If enabled, this can cause uneven load distribution because certain clients may generate disproportionately more traffic, overloading their pinned backends while others remain underutilized. Disabling or properly configuring session affinity allows the load balancer to distribute requests based on its default algorithm (e.g., round-robin or least-connections), improving balance across backends.

Exam trap

Google Cloud often tests the misconception that health checks or firewall rules are responsible for load distribution, when in fact session affinity is the primary configuration that can cause uneven traffic patterns by overriding the default balancing algorithm.

How to eliminate wrong answers

Option B is wrong because firewall rules control allowed traffic to/from backends but do not influence how the load balancer distributes incoming requests among healthy instances. Option C is wrong because Cloud CDN caching reduces load on backends by serving cached content at edge locations, but it does not affect the distribution of requests that reach the load balancer's backend pool. Option D is wrong because health check frequency determines how often the load balancer probes backend health, affecting failover speed but not the balancing algorithm or distribution of traffic among healthy backends.

55
MCQhard

A company runs a batch processing application on Compute Engine that reads data from Cloud Storage and writes results to BigQuery. The application runs on a managed instance group (MIG) with autoscaling. Recently, job failures occurred because instances could not authenticate to BigQuery. You need to ensure that the instances have the necessary permissions without embedding credentials in the application. What should you do?

A.Enable the BigQuery API on the project and grant the Compute Engine default service account the BigQuery Data Editor role.
B.Generate a service account key file and store it in Cloud Storage. Configure the application to download the key at startup and use it for authentication.
C.Create a service account with the BigQuery Data Editor role and assign it to the MIG as the instance service account.
D.Use Application Default Credentials (ADC) by setting the GOOGLE_APPLICATION_CREDENTIALS environment variable to point to a JSON key file stored on each instance's local SSD.
AnswerC

Assigning a service account with the necessary BigQuery permissions to the MIG allows all instances to authenticate automatically via the metadata server. This eliminates the need to embed credentials and follows best practices for IAM. The BigQuery Data Editor role provides the required write access to datasets.

Why this answer

Assigning a dedicated service account with the BigQuery Data Editor role to the managed instance group allows instances to obtain credentials from the metadata server, adhering to security best practices. This avoids key management and ensures least privilege. The other options either use insecure key files or grant excessive permissions to the default service account.

Exam trap

The trap here is thinking that you must use a service account key file for authentication, but Compute Engine instances can use their attached service account via the metadata server.

56
MCQhard

A company uses Cloud Bigtable for time-series data. They experience high latency and uneven load distribution across nodes. What is the most likely cause?

A.The data is stored in a single column family
B.The app is using strong reads instead of eventual consistency
C.The table has a single row key pattern that causes hot spotting
D.The cluster has too many nodes
AnswerC

Bigtable shards rows by row-key range, so a monotonically increasing or otherwise uniform key pattern funnels all writes to one tablet, creating hot spotting. That concentrated load explains both the uneven node distribution and the elevated latency.

Why this answer

Cloud Bigtable partitions data by row key range and distributes tablets across nodes. A single row key pattern (e.g., monotonically increasing timestamps) causes all writes to target the same tablet, creating a hot spot. This leads to uneven load distribution and high latency because one node is overwhelmed while others remain idle.

Exam trap

Google Cloud often tests the misconception that column families or read consistency levels are the root cause of performance issues, when in fact row key design is the primary driver of load distribution in Bigtable.

How to eliminate wrong answers

Option A is wrong because storing data in a single column family does not cause uneven load distribution; column families affect storage and read performance but not row key distribution. Option B is wrong because strong reads (read-after-write consistency) add latency but do not cause uneven load distribution across nodes; the issue is about write hot spotting, not read consistency. Option D is wrong because having too many nodes would reduce load per node, not increase latency or cause uneven distribution; the cluster would be over-provisioned, not hot-spotted.

57
MCQhard

A company runs multiple microservices on Cloud Run. Each service uses a Serverless VPC Access connector to connect to a shared Cloud Memorystore for Redis instance (standard tier) in a VPC network. The Redis instance is configured with a firewall rule that allows TCP connections on port 6379 from the VPC connector's subnet (10.8.0.0/28). After a recent code update, the order-service fails to connect to Redis, while the user-service continues to work. The error logs in order-service show 'connection refused'. The engineer verifies that both services use the same VPC connector, the same Redis instance IP, and the same service account. The VPC connector's metrics show no errors. What is the most likely cause?

A.The order-service is deployed in a different region than the Redis instance.
B.The order-service code now attempts to connect to Redis on port 6380.
C.The VPC connector is out of memory.
D.The Redis instance has reached its maximum number of connections.
AnswerB

Redis standard tier listens on TCP 6379, so a firewall rule permitting only that port would refuse a connection on 6380. The unchanged user-service confirms the connector and instance are healthy, isolating the port change in order-service code.

Why this answer

The order-service successfully connects to the same Redis instance before the code update. After the update, it fails with 'connection refused', while the user-service still works. Since both services share the same networking configuration and the firewall only allows port 6379, the most likely cause is that the order-service code now attempts to connect on a different port (e.g., 6380) that is not allowed by the firewall.

Other options would affect both services or are inconsistent with the symptoms.

58
MCQeasy

A company wants to store backup data that is accessed rarely but must be available for retrieval within minutes. Which Cloud Storage class is appropriate?

A.Standard
B.Nearline
C.Coldline
D.Archive
AnswerB

Nearline suits data accessed less than once a month but requiring retrieval within seconds, offering lower storage cost than Standard while meeting the minutes-level availability constraint; Coldline and Archive impose longer minimum durations and higher retrieval latency.

Why this answer

Nearline storage is designed for data accessed less than once a month but requires retrieval within minutes, making it ideal for backup data that needs quick availability. It offers lower cost than Standard storage while still supporting sub-minute retrieval times, aligning with the scenario's access and latency requirements.

Exam trap

Google Cloud often tests the distinction between 'retrieval within minutes' and 'retrieval within hours' to confuse candidates into selecting Coldline or Archive, assuming 'rarely accessed' automatically means the cheapest option, but the key is the specific retrieval time requirement.

How to eliminate wrong answers

Option A is wrong because Standard storage is for frequently accessed data (e.g., multiple times per month) and costs more, making it unsuitable for rarely accessed backups. Option C is wrong because Coldline storage is for data accessed less than once a quarter, with retrieval times that can be minutes to hours, but it is optimized for even colder data than Nearline, and its cost structure (including retrieval fees) is less appropriate for backups needing consistent minute-level access. Option D is wrong because Archive storage is for long-term retention with retrieval times typically in hours (e.g., 1-12 hours), not minutes, and is intended for data that is accessed extremely rarely, such as regulatory archives.

59
MCQhard

A retail company runs a stateful batch application on a managed instance group. The application writes intermediate results to the boot disk of each VM and takes several hours to complete. The operations team wants rolling updates that replace instances with a new image, but must guarantee that no in-flight job is interrupted. Which configuration should you recommend?

A.Set the update type to proactive, configure a maximum surge, and rely on the managed instance group's health checks to drain connections.
B.Convert the workload to a regional managed instance group and enable autoscaling based on CPU utilization during the rollout.
C.Set the update type to opportunistic and rely on the instance template's automatic restart policy.
D.Use stateful managed instance group configuration with a replacement policy, and set the update type to opportunistic so instances are only replaced when you deliberately delete them.
AnswerD

Stateful MIGs preserve per-instance names, disks, and metadata, and with an opportunistic update the group does not automatically replace instances during a rollout. You control replacement timing by deleting or recreating specific instances after their jobs complete, which guarantees no in-flight batch work is interrupted while still allowing eventual image updates.

Why this answer

A stateful managed instance group combined with an opportunistic update gives the operations team explicit control over when each instance is replaced. Because replacements occur only when an instance is deliberately deleted or recreated, the team can wait for each batch job to finish, update the image on the template, and then replace instances one at a time without interrupting work.

Exam trap

The trap here is thinking that proactive rolling updates plus health checks will gracefully wait for long-running work, when health checks only govern traffic serving and not job completion.

60
Multi-Selectmedium

An organization wants to monitor network traffic between VMs in a VPC for troubleshooting. Which TWO services can provide this?

Select 2 answers
A.Cloud Audit Logs
B.Packet Mirroring (Network Intelligence Center)
C.VPC Flow Logs
D.Cloud Monitoring
E.Cloud Logging
AnswersB, C

Packet Mirroring clones selected VM instance traffic, including full packet payloads, and forwards it to a collector for deep inspection. This satisfies the troubleshooting requirement because it exposes actual packet contents between VMs, unlike metadata-only flow records.

Why this answer

Packet Mirroring (Network Intelligence Center) (B) is correct because it captures full packet payloads from specified VM instances in a VPC and forwards them to a collector instance for deep troubleshooting and analysis of traffic between VMs. VPC Flow Logs (C) is correct because it records IP flow information (5-tuple, bytes, packets, timestamps) for traffic to and from VM instances, subnets, and VPCs, providing visibility into network traffic patterns for troubleshooting. Cloud Audit Logs (A) only records administrative and data-access API activity, not network traffic between VMs.

Cloud Monitoring (D) collects metrics and uptime checks but does not capture network flow or packet-level traffic data. Cloud Logging (E) stores and queries log entries but is not itself a network traffic capture service.

Exam trap

Google Cloud often tests the distinction between services that capture raw packet data (Packet Mirroring) versus those that log only metadata or metrics (VPC Flow Logs). Candidates may incorrectly think only one is correct, but both can be used for troubleshooting network traffic between VMs, depending on the depth of information needed.

61
MCQeasy

A developer needs to deploy a stateful application that requires persistent storage across pod restarts in Google Kubernetes Engine. Which resource should they use?

A.ConfigMap
B.EmptyDir
C.Secret
D.PersistentVolumeClaim
AnswerD

A PersistentVolumeClaim requests durable storage from a PersistentVolume, decoupling the pod lifecycle from the data. This satisfies the stem's requirement that storage survive pod restarts, unlike emptyDir or container filesystems, which are ephemeral and lose contents when a pod is terminated or rescheduled.

Why this answer

A PersistentVolumeClaim (PVC) is the correct resource because it allows a pod to request persistent storage that survives pod restarts. In GKE, a PVC binds to a PersistentVolume (PV), which can be backed by Compute Engine persistent disks, ensuring data remains available even if the pod is rescheduled or restarted.

Exam trap

The trap here is that candidates confuse ephemeral volumes (EmptyDir) with persistent storage, or assume ConfigMaps/Secrets can store application data, when in fact they are for configuration and secrets only.

How to eliminate wrong answers

Option A is wrong because a ConfigMap is used to inject configuration data (e.g., environment variables, files) into pods, not for persistent storage. Option B is wrong because an EmptyDir volume is ephemeral—it is created when a pod starts and is deleted when the pod is removed, so data does not persist across pod restarts. Option C is wrong because a Secret is designed to store sensitive data (e.g., passwords, tokens) and is not a storage volume for application data.

62
Multi-Selecthard

A company is designing a highly available architecture for a stateful application on Compute Engine. They need to protect against zonal failures. Which THREE steps should they take?

Select 3 answers
A.Store session state in memory
B.Use a global load balancer with health checks
C.Use a single zone instance group
D.Use persistent disks with regional persistent disks
E.Use a managed instance group across multiple zones
AnswersB, D, E

A global external load balancer with health checks distributes traffic across healthy backends in multiple zones, automatically removing instances from a failed zone. This satisfies the zonal-failure requirement by redirecting users to surviving zones without manual intervention.

Why this answer

Option B is correct because a global external Application Load Balancer (or global external proxy Network Load Balancer) with health checks distributes traffic across healthy backends in multiple zones and automatically stops routing to unhealthy instances, providing resilience against a zonal failure. Option D is correct because regional persistent disks synchronously replicate data between two zones in the same region, so a stateful application's data remains available if one zone fails. Option E is correct because a managed instance group (MIG) spread across multiple zones maintains capacity and automatically recreates instances in surviving zones when a zone becomes unavailable.

Option A is wrong because storing session state only in memory ties the state to a single instance and is lost on failure, breaking high availability. Option C is wrong because a single-zone instance group has no protection against a zonal outage.

Exam trap

A common misconception is that in-memory session state (Option A) is sufficient for high availability, but it fails because state is lost on instance failure; instead, external session stores (e.g., Cloud Memorystore or Cloud Spanner) are needed for stateful applications on Google Cloud.

63
MCQeasy

A developer is trying to deploy a Compute Engine instance from a Cloud Build step. The build fails with the above error. What is the problem?

A.The project has exceeded its service account quota.
B.The Cloud Build service account lacks 'compute.instances.create' permission.
C.Cloud Build does not have the 'iam.serviceAccounts.actAs' permission on the default compute service account.
D.The developer's personal account does not have permission to use Cloud Build.
AnswerC

Creating an instance that runs as the default compute service account requires the caller to hold iam.serviceAccounts.actAs on that account. Cloud Build's service account lacks this binding, so the deployment step fails authorisation even though other Compute permissions may be present.

Why this answer

The error occurs because Cloud Build needs to impersonate the Compute Engine default service account to create a VM instance. The Cloud Build service account requires the 'iam.serviceAccounts.actAs' permission on the target service account to delegate its identity. Without this permission, the build step fails even if the Cloud Build service account has 'compute.instances.create' permission.

Exam trap

Google Cloud often tests the subtle distinction between having resource-level permissions (like 'compute.instances.create') and the 'actAs' permission required to impersonate a service account, leading candidates to incorrectly choose the missing resource permission.

How to eliminate wrong answers

Option A is wrong because service account quotas are separate from IAM permissions; exceeding a quota would produce a different error (e.g., 'quota exceeded'), not a permission denied error. Option B is wrong because the error message specifically indicates an 'actAs' permission issue, not a missing 'compute.instances.create' permission; if that were the problem, the error would reference 'compute.instances.create' directly. Option D is wrong because Cloud Build uses its own service account for execution, not the developer's personal account; the error is about the Cloud Build service account's permissions, not the developer's.

64
MCQeasy

A company stores sensitive data in Cloud Storage and wants to enforce encryption at rest using customer-managed keys. Which Google Cloud service should they use to manage the keys?

A.Cloud HSM
B.Secret Manager
C.Cloud KMS
D.IAM
AnswerC

Cloud KMS provides customer-managed encryption keys (CMEK) that satisfy the requirement for encryption at rest with keys the company controls. It integrates directly with Cloud Storage, letting you manage key rotation, IAM permissions and audit logging through a centralised keyring, rather than relying on Google-managed keys.

Why this answer

Cloud KMS (Key Management Service) is the correct choice because it is the native Google Cloud service for managing cryptographic keys, including customer-managed encryption keys (CMEK). It allows you to create, rotate, and control access to keys used to encrypt data at rest in Cloud Storage, and it integrates directly with Cloud Storage's CMEK feature. Cloud HSM is a hardware-backed key management option but is built on top of Cloud KMS, not a separate service for key management.

Exam trap

The trap here is that candidates confuse Cloud HSM as a separate key management service, but Cloud HSM is actually a hardware-backed key storage option that requires Cloud KMS for key management, not a replacement for it.

How to eliminate wrong answers

Option A is wrong because Cloud HSM is a hardware security module service that provides FIPS 140-2 Level 3 validated key storage, but it is an add-on to Cloud KMS, not a standalone key management service; you still use Cloud KMS to manage the keys stored in HSM. Option B is wrong because Secret Manager is designed to store and manage secrets such as API keys, passwords, and certificates, not for managing encryption keys used for data at rest in Cloud Storage. Option D is wrong because IAM (Identity and Access Management) is a service for managing access control and permissions, not for creating, storing, or managing encryption keys.

65
MCQhard

A company runs a critical application on a managed instance group (MIG) with autoscaling enabled. The application experiences sudden traffic spikes, and the team wants to ensure that new instances are added quickly while maintaining cost efficiency. They also want to avoid over-provisioning. Which autoscaling metric should they use?

A.CPU utilization
B.Custom metric based on memory usage
C.Cloud Pub/Sub queue depth
D.HTTP load balancing serving capacity
AnswerD

HTTP load balancing serving capacity is a metric that measures the utilization of the load balancer's backend capacity. It directly reflects the incoming traffic and can trigger scaling based on the actual load, allowing quick response to traffic spikes. This metric is ideal for web applications behind an HTTP(S) load balancer, as it scales based on the number of requests and avoids over-provisioning by matching capacity to demand.

Why this answer

HTTP load balancing serving capacity is the best metric for scaling a web application behind an HTTP(S) load balancer because it directly measures the load on the backend instances. It enables rapid scaling in response to traffic spikes and helps maintain cost efficiency by avoiding over-provisioning. Other metrics may not accurately reflect the incoming traffic or may introduce delays.

Exam trap

The trap here is assuming that CPU utilization is always the most responsive metric for autoscaling, but for web applications behind a load balancer, serving capacity provides a more direct and immediate signal of traffic load.

Ready to test yourself?

Try a timed practice session using only Manage Implementation questions.