Courseiva

PCA · topic practice

Manage implementation of cloud architecture practice questions

This domain covers deploying and enforcing the architecture you designed: provisioning resources with Deployment Manager or Terraform, enforcing org policy and labels, configuring VPC networking (Cloud NAT, firewall rules, Private Google Access), and controlling access with VPC Service Controls and IAM. Questions are scenario-based, asking which actions meet a stated constraint or which configuration causes a described failure.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Manage implementation of cloud architecture

What the exam tests

What to know about Manage implementation of cloud architecture

You must be able to choose concrete controls: Organization Policy constraints for labels, VPC Service Controls for data boundaries, Cloud NAT port tuning for outbound connectivity, and BigQuery partitioning/clustering for cost. The single most important thing is matching the enforcement mechanism to the requirement, not just describing the desired outcome.

Enforcing mandatory Compute Engine labels via Organization Policy constraints or custom constraints

Diagnosing Cloud NAT port exhaustion and allocation failures on private instances

Using VPC Service Controls perimeters to restrict data exfiltration across project boundaries

Reducing BigQuery cost with partitioning, clustering, and query result caching

Watch out for

Common Manage implementation of cloud architecture exam traps

  • ▸Assuming Cloud NAT failures are routing or firewall issues instead of checking port allocation and minimum ports per VM.
  • ▸Believing VPC Service Controls encrypts data or replaces IAM; it only restricts access to services inside the perimeter.
  • ▸Trying to enforce labels with a script or startup script instead of an Organization Policy constraint that blocks non-compliant creation.

Practice set

Manage implementation of cloud architecture questions

20 questions · select your answer, then reveal the explanation

An organization is running a stateful workload on Compute Engine with a single persistent disk. They want to migrate to a regional persistent disk for higher availability. The disk is 500 GB and currently 80% full. They need zero downtime during the migration. What is the recommended approach?

You are designing a CI/CD pipeline for a containerized application on Google Cloud. The application is built with Cloud Build, stored in Container Registry, and deployed to GKE. The team wants to ensure that only images that pass vulnerability scanning are deployed. What should you do?

A company runs a data analytics platform on Google Cloud using BigQuery, Dataflow, and Cloud Storage. They notice that Dataflow jobs are failing with 'out of memory' errors for certain large pipelines. The pipelines process variable amounts of data, sometimes spiking 10x normal. Which strategy should they use to handle these spikes cost-effectively?

Which TWO statements are true about Google Cloud HTTPS Load Balancers?

You are reviewing an IAM policy for a Cloud Storage bucket. Alice is a member of the data-team group. What level of access does Alice have to objects in this bucket?

Exhibit

Refer to the exhibit.
```
{
  "bindings": [
    {
      "role": "roles/storage.objectViewer",
      "members": [
        "user:alice@example.com",
        "serviceAccount:sa-bucket@project.iam.gserviceaccount.com"
      ]
    },
    {
      "role": "roles/storage.objectAdmin",
      "members": [
        "group:data-team@example.com"
      ]
    }
  ]
}
```

Your company runs a critical application on Google Kubernetes Engine (GKE) in us-central1. The application consists of a frontend deployment with 3 replicas and a backend statefulset with 5 replicas using persistent volumes (SSD). Recently, the team noticed that during a regional outage in us-central1, the application became completely unavailable. They want to design a multi-region architecture that can survive a regional failure with RPO of 1 hour and RTO of 30 minutes. The application is stateless on the frontend but the backend stores critical data on persistent disks. The backend can operate in a read-only mode from a secondary region if needed. They have a limited budget and want to minimize ongoing costs. Which approach should they take?

An organization has deployed a multi-region Cloud Spanner instance for a global application. The application is experiencing high latency for read requests from a specific region. The team has verified that the application is using stale reads and the data distribution is even. What is the most likely cause of the high latency?

A company is designing a disaster recovery plan for a critical application running on Compute Engine. The application uses a PostgreSQL database and stores files on persistent disks. The recovery time objective (RTO) is 4 hours, and the recovery point objective (RPO) is 1 hour. Which two actions should the company take?

A company is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that the cluster can automatically scale based on custom metrics, such as the number of pending requests per pod. Which two steps should they take? (Choose TWO)

A developer runs the command above and sees the output. The cluster has one node pool with 3 nodes, each of type e2-standard-4 (4 vCPU, 16 GB RAM). The application requires at least 2 GB of memory per pod and the cluster has 10 pods that need to be scheduled. The developer also notices that the node pool autoscaling is enabled with a minimum of 1 and maximum of 5 nodes. However, the cluster is unable to schedule all pods. What is the most likely cause?

Exhibit

Refer to the exhibit.

```
$ gcloud container clusters describe my-cluster --zone us-central1-a --format 'table(name, nodeConfig.machineType, nodePools[].initialNodeCount, nodePools[].config.machineType)'
NAME: my-cluster
MASTER_VERSION: 1.28.5-gke.2000
NODE_CONFIG_MACHINE_TYPE: e2-standard-4
NODE_POOLS: [0].initialNodeCount: 3
NODE_POOLS: [0].config.machineType: e2-standard-4
```

A large e-commerce company runs a multi-tier application on Google Cloud. The frontend is served by a global HTTP Load Balancer with a backend service pointing to a managed instance group (MIG) of nginx web servers. The application tier consists of a regional internal TCP/UDP load balancer distributing traffic to a MIG of Java application servers. The database tier uses Cloud SQL for PostgreSQL in a failover replica configuration. The architecture is deployed in the us-central1 region across three zones. Recently, the operations team noticed intermittent 502 Bad Gateway errors from the frontend load balancer during peak traffic hours. The errors last for a few minutes and then recover. The team suspects the application tier is overwhelmed. They need to implement a solution that can handle traffic spikes without manual intervention. Which course of action should they take?

An organization has a multi-regional deployment of a stateful application on GKE using regional persistent disks. They need to implement disaster recovery with an RPO of less than 1 hour and RTO of 30 minutes. What is the most cost-effective approach?

A DevOps team is building a CI/CD pipeline for a microservices application deployed on Google Kubernetes Engine. They want to ensure that each microservice can be deployed independently without affecting other services. Which strategy should they use?

Question 14hardmultiple choice
Open the full VLAN trunking answer →

An organization needs to connect an on-premises data center to Google Cloud using Dedicated Interconnect with a 10 Gbps link. They require high availability and want to achieve 99.99% SLA. What is the minimum number of VLAN attachments and Interconnect connections needed?

A company is using Cloud Armor with HTTP Load Balancing to protect a web application. They want to block traffic from specific IP ranges for all requests except those that include a valid reCAPTCHA token. Which Cloud Armor rule configuration should they use?

Which TWO statements about Google Cloud VPC firewall rules are correct? (Choose two.)

Which TWO methods can be used to provide secure access to a private Google Kubernetes Engine (GKE) cluster from the internet? (Choose two.)

What is the most likely reason the NetworkPolicy is not taking effect?

Exhibit

Refer to the exhibit.

gcloud container clusters describe prod-cluster --region us-central1
...
networkPolicy:
  enabled: true
  provider: CALICO
...

The cluster is using Calico network policies. A developer deploys a manifest that defines a NetworkPolicy that allows ingress from pods with label 'app: frontend' but the traffic is still blocked. The pod logs show no network error but the connection times out.

Why did the VM resource fail while the disk succeeded?

Exhibit

Refer to the exhibit.

gcloud deployment-manager deployments describe my-deployment
---
id: '12345'
name: my-deployment
manifest: manifest-123
state: DEPLOYED
resources:
- name: my-vm
  type: compute.v1.instance
  properties:
    machineType: zones/us-central1-a/machineTypes/n1-standard-1
    networkInterfaces:
    - network: global/networks/default
  currentStatus: FAILED
- name: my-disk
  type: compute.v1.disk
  properties:
    zone: us-central1-a
    sizeGb: 10
  currentStatus: SUCCESS

A company has a requirement to store application logs for 7 years for compliance. They are using Cloud Logging. What is the most cost-effective way to retain logs?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage implementation of cloud architecture sessions

Start a Manage implementation of cloud architecture only practice session

Every question in these sessions is drawn from the Manage implementation of cloud architecture domain — nothing else.

Related practice questions

Related PCA topic practice pages

Move into related areas when this topic feels solid.

Analysing and Optimising Technical and Business Processes practice questions

Analysing and Optimising Technical and Business Processes practice questions for PCA.

Managing Implementation and Ensuring Solution and Operations Reliability practice questions

Targeted PCA practice covering Managing Implementation and Ensuring Solution and Operations Reliability.

Managing and Provisioning a Solution Infrastructure practice questions

Practise PCA questions linked to Managing and Provisioning a Solution Infrastructure.

Designing for Security and Compliance practice questions

Work through PCA questions on Designing for Security and Compliance.

Design for security and compliance practice questions

Design for security and compliance practice questions for PCA.

Design and plan a cloud solution architecture practice questions

Work through PCA questions on Design and plan a cloud solution architecture.

Manage and provision cloud infrastructure practice questions

Manage and provision cloud infrastructure practice questions for PCA.

Analyze and optimize technical and business processes practice questions

Analyze and optimize technical and business processes practice questions for PCA.

Ensure solution and operations reliability practice questions

Sharpen your PCA knowledge of Ensure solution and operations reliability.

Manage implementation of cloud architecture practice questions

Work through PCA questions on Manage implementation of cloud architecture.

PCA fundamentals practice questions

Practise PCA questions linked to PCA fundamentals.

PCA scenario practice questions

Work through PCA questions on PCA scenario.

Frequently asked questions

What does the PCA exam test about Manage implementation of cloud architecture?
You must be able to choose concrete controls: Organization Policy constraints for labels, VPC Service Controls for data boundaries, Cloud NAT port tuning for outbound connectivity, and BigQuery partitioning/clustering for cost. The single most important thing is matching the enforcement mechanism to the requirement, not just describing the desired outcome.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage implementation of cloud architecture questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage implementation of cloud architecture domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCA topics?
Use the topic links above to move to related areas, or go back to the PCA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCA exam covers. They are not copied from any real exam or dump site.