Courseiva

PCA · topic practice

Manage and provision cloud infrastructure practice questions

This domain covers deploying and configuring Google Cloud resources: GKE workload identity, Cloud SQL high availability, CMEK and key rotation, and matching Cloud Monitoring and Cloud Logging tools to their purpose. Questions are scenario-based, asking you to pick the correct configuration, IAM binding, or managed service for a stated requirement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Manage and provision cloud infrastructure

What the exam tests

What to know about Manage and provision cloud infrastructure

Be able to select and configure the right managed service for a stated requirement: Workload Identity for GKE API access, regional Cloud SQL for failover, CMEK with rotation for encryption, and the correct Monitoring or Logging tool. The key is matching the requirement to the exact feature.

Binding Kubernetes service accounts to IAM service accounts via GKE Workload Identity Federation for keyless API access

Configuring Cloud SQL for MySQL with a regional instance and automatic failover to a standby zone

Encrypting Cloud Storage objects with CMEK in Cloud KMS and setting rotation schedules

Selecting Cloud Monitoring metrics, uptime checks, alerting policies, and Cloud Logging sinks for observability

Watch out for

Common Manage and provision cloud infrastructure exam traps

  • ▸Choosing service account JSON keys for GKE pods instead of Workload Identity, which avoids key management and rotation entirely.
  • ▸Picking a zonal Cloud SQL instance for high availability; automatic failover requires a regional instance with a standby.
  • ▸Assuming CMEK rotation re-encrypts existing objects; Cloud KMS rotates future key versions while old data stays under prior versions.

Practice set

Manage and provision cloud infrastructure questions

20 questions · select your answer, then reveal the explanation

Question 1hardmulti select
Read the full VPN explanation →

Which THREE components are required to set up a private connection between an on-premises network and a VPC using Cloud VPN? (Choose three.)

An administrator creates a GKE cluster with the command above. After deployment, the cluster has 3 nodes, but the node pool autoscaler never scales up even under load. What is the most likely reason?

Exhibit

Refer to the exhibit.

gcloud container clusters create my-cluster \
    --zone us-central1-a \
    --num-nodes 3 \
    --machine-type e2-medium \
    --disk-size 100 \
    --image-type cos_containerd \
    --enable-autoscaling \
    --min-nodes 1 \
    --max-nodes 5 \
    --node-locations us-central1-a,us-central1-b,us-central1-f
Question 3mediummultiple choice
Read the full NAT/PAT explanation →

A startup is deploying a microservices application on Google Kubernetes Engine (GKE) with a regional cluster. They have services that need to communicate with each other and also with external APIs. The cluster uses VPC-native routing. They have enabled Cloud NAT to allow outbound internet access for nodes without external IPs. However, the development team reports that some pods cannot reach the external APIs, while others can. All pods are in the same namespace and are not using any network policies. The pods that fail have the annotation 'cloud.google.com/gke-nat-ips' set to a list of static IP addresses. The pods that work do not have this annotation. What is the most likely cause of the failure?

A company is migrating its on-premises application to Google Cloud. The application requires low-latency access to a shared filesystem that can be mounted by multiple Compute Engine instances across different zones. Which storage solution should they use?

A company wants to enable a new DevOps team to have read-only access to logs in the default Cloud Logging bucket for their project, but prevent them from modifying log views or creating linked datasets in BigQuery. Which two IAM roles should be granted to the team?

A company runs an e-commerce platform on Google Cloud. The application is deployed on Google Kubernetes Engine (GKE) with a regional cluster (us-central1, three zones). The frontend service is exposed via an HTTP Load Balancer with Cloud CDN. Recently, during a flash sale, users experienced high latency and occasional 502 errors. The backend service is a Java application that reads from Cloud Spanner. The team has observed that Spanner CPU utilization averaged 65% during the sale, with a few spikes to 80%. The number of frontend pods was auto-scaled to 50, each running on n1-standard-2 nodes. The node pool is set to autoscale up to 100 nodes. The errors appear to correlate with periods of high CPU on the nodes, but not always. What is the most likely cause and recommended action?

Question 7hardmultiple choice
Open the full BGP breakdown →

A Cloud Router BGP session is flapping. The logs show 'Interface flapping due to changes in the underlying network'. What is the most likely cause?

Which THREE factors should be considered when selecting a machine series for a Compute Engine instance running a memory-intensive batch job?

Which TWO statements are true about Cloud Load Balancing?

A developer wants to automate the creation of a Google Cloud project with a specific VPC and firewall rules. Which tool should they use?

An organization needs to ensure that only Compute Engine instances with a specific label can access a Cloud Storage bucket. Which policy type should be used?

A DevOps engineer notices that a GKE cluster has nodes that are frequently preempted. They want to reduce costs but maintain resilience. What should they do?

Which TWO features help reduce costs for batch processing workloads on Compute Engine?

Refer to the exhibit. What is the effect of this IAM policy on a Cloud Storage bucket?

Exhibit

{
  "bindings": [
    {
      "role": "roles/storage.objectViewer",
      "members": [
        "user:alice@example.com",
        "domain:example.com"
      ]
    }
  ]
}

Refer to the exhibit. A developer wants to SSH into instance-1 from their local machine. Which command should they use?

Exhibit

NAME       ZONE        MACHINE_TYPE  PREEMPTIBLE  INTERNAL_IP   EXTERNAL_IP
instance-1 us-central1-a n1-standard-4 true        10.128.0.2    35.184.0.1
instance-2 us-central1-b n1-standard-4 false       10.128.0.3    35.184.0.2

Refer to the exhibit. Which statement is true about this Deployment Manager template?

Exhibit

resources:
- name: my-vm
  type: compute.v1.instance
  properties:
    zone: us-central1-a
    machineType: zones/us-central1-a/machineTypes/n1-standard-4
    disks:
    - deviceName: boot
      type: PERSISTENT
      boot: true
      autoDelete: true
      initializeParams:
        sourceImage: projects/debian-cloud/global/images/family/debian-10
    networkInterfaces:
    - network: global/networks/default
      accessConfigs:
      - name: External NAT
        type: ONE_TO_ONE_NAT

A company has two VPC networks in the same project: vpc-a (us-central1) and vpc-b (us-east1). They want to allow communication between instances in these VPCs using internal IPs. Which action should they take?

Question 18hardmultiple choice
Review the full subnetting walkthrough →

A company uses a Shared VPC hosted in a common project (host project) to centralize network management. A service project team needs to create a Compute Engine instance with a specific static internal IP address from the Shared VPC subnet. What IAM permissions should be granted to the service project's Compute Engine default service account?

A developer needs to grant public read access to all objects in a Cloud Storage bucket named 'my-public-assets'. What is the simplest way to achieve this?

A company is experiencing high latency in their VPC. They enabled VPC Flow Logs to capture metadata but need to analyze the logs for traffic patterns. Which Google Cloud service should they use to query and analyze VPC Flow Logs?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage and provision cloud infrastructure sessions

Start a Manage and provision cloud infrastructure only practice session

Every question in these sessions is drawn from the Manage and provision cloud infrastructure domain — nothing else.

Related practice questions

Related PCA topic practice pages

Move into related areas when this topic feels solid.

Analysing and Optimising Technical and Business Processes practice questions

Analysing and Optimising Technical and Business Processes practice questions for PCA.

Managing Implementation and Ensuring Solution and Operations Reliability practice questions

Targeted PCA practice covering Managing Implementation and Ensuring Solution and Operations Reliability.

Managing and Provisioning a Solution Infrastructure practice questions

Practise PCA questions linked to Managing and Provisioning a Solution Infrastructure.

Designing for Security and Compliance practice questions

Work through PCA questions on Designing for Security and Compliance.

Design for security and compliance practice questions

Design for security and compliance practice questions for PCA.

Design and plan a cloud solution architecture practice questions

Work through PCA questions on Design and plan a cloud solution architecture.

Manage and provision cloud infrastructure practice questions

Manage and provision cloud infrastructure practice questions for PCA.

Analyze and optimize technical and business processes practice questions

Analyze and optimize technical and business processes practice questions for PCA.

Ensure solution and operations reliability practice questions

Sharpen your PCA knowledge of Ensure solution and operations reliability.

Manage implementation of cloud architecture practice questions

Work through PCA questions on Manage implementation of cloud architecture.

PCA fundamentals practice questions

Practise PCA questions linked to PCA fundamentals.

PCA scenario practice questions

Work through PCA questions on PCA scenario.

Frequently asked questions

What does the PCA exam test about Manage and provision cloud infrastructure?
Be able to select and configure the right managed service for a stated requirement: Workload Identity for GKE API access, regional Cloud SQL for failover, CMEK with rotation for encryption, and the correct Monitoring or Logging tool. The key is matching the requirement to the exact feature.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage and provision cloud infrastructure questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage and provision cloud infrastructure domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCA topics?
Use the topic links above to move to related areas, or go back to the PCA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCA exam covers. They are not copied from any real exam or dump site.