Courseiva

Google PCA Practice Question: Managing Implementation and Ensuring Solution and Operations Reliability

Your team operates a production e-commerce application on a managed instance group (MIG) that serves traffic through a global external Application Load Balancer. During a new release, the team wants to deploy the new version to a small subset of instances and then progressively increase traffic to it while monitoring error rates, with the ability to immediately roll back if errors spike. The new version is already built as a custom image. Which approach should you use?

⚠ Common exam trap

The trap here is assuming that a rolling update with maxSurge and maxUnavailable is equivalent to a canary release, when rolling updates replace instances in place and cannot route a precise percentage of user traffic to a new version.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a second MIG with the new image, add it as a backend to the existing backend service with a small capacity, and gradually shift traffic between the two MIGs using weighted traffic distribution in the backend service.

The requirement is a controlled canary with progressive traffic shifting and fast rollback. Weighted traffic distribution on a backend service allows two MIGs, each running a different image, to receive defined percentages of live traffic. You can start small, watch error rates, increase the weight, and set it back to zero if problems appear. Other approaches either replace instances in place or rely on DNS, which lacks the precision and quick reversibility needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new global external Application Load Balancer with a separate backend service pointing only to the new image, and use Cloud DNS weighted routing to send 10% of users to the new load balancer.

    Why it's wrong here

    Cloud DNS weighted routing operates at the DNS layer and is subject to client and resolver caching, so traffic proportions are approximate and rollback is slow. Creating a second load balancer also duplicates frontend configuration and TLS management. This approach adds complexity and does not provide the precise, quickly reversible traffic split available within a single backend service.

  • ✓

    Create a second MIG with the new image, add it as a backend to the existing backend service with a small capacity, and gradually shift traffic between the two MIGs using weighted traffic distribution in the backend service.

    Why this is correct

    Weighted traffic distribution on a backend service lets you send a controlled percentage of user traffic to a new MIG while keeping the rest on the stable version. Monitoring error rates and adjusting weights gives progressive rollout and instant rollback by setting the new backend weight to zero. This matches canary release requirements without rebuilding instances.

  • ✗

    Perform an in-place update of the MIG template to the new image with a very small maxUnavailable, and rely on the load balancer health checks to remove unhealthy instances automatically.

    Why it's wrong here

    Updating the instance template changes all instances toward the new version rather than isolating a subset for canary testing. Health checks only detect instances that fail probes; they do not measure application error rates or business metrics. This method cannot hold a stable version alongside a new version for comparison, so controlled progressive rollout and immediate rollback are not achievable.

  • ✗

    Use a rolling update with maxSurge and maxUnavailable set to 50% so that half the instances are replaced at once, then wait for health checks to pass before continuing.

    Why it's wrong here

    A rolling update replaces instances in place and does not give you percentage-based user traffic control. Setting maxSurge and maxUnavailable to 50% increases blast radius because half the capacity can be unavailable or updated simultaneously. It also cannot route a small, measurable slice of live traffic to the new version, so it does not satisfy the gradual canary requirement.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.