Google PCA Practice Question: Managing Implementation and Ensuring Solution and Operations Reliability
Your team operates a production e-commerce application on a managed instance group (MIG) that serves traffic through a global external Application Load Balancer. During a new release, the team wants to deploy the new version to a small subset of instances and then progressively increase traffic to it while monitoring error rates, with the ability to immediately roll back if errors spike. The new version is already built as a custom image. Which approach should you use?
⚠ Common exam trap
The trap here is assuming that a rolling update with maxSurge and maxUnavailable is equivalent to a canary release, when rolling updates replace instances in place and cannot route a precise percentage of user traffic to a new version.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a second MIG with the new image, add it as a backend to the existing backend service with a small capacity, and gradually shift traffic between the two MIGs using weighted traffic distribution in the backend service.
The requirement is a controlled canary with progressive traffic shifting and fast rollback. Weighted traffic distribution on a backend service allows two MIGs, each running a different image, to receive defined percentages of live traffic. You can start small, watch error rates, increase the weight, and set it back to zero if problems appear. Other approaches either replace instances in place or rely on DNS, which lacks the precision and quick reversibility needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new global external Application Load Balancer with a separate backend service pointing only to the new image, and use Cloud DNS weighted routing to send 10% of users to the new load balancer.
Why it's wrong here
Cloud DNS weighted routing operates at the DNS layer and is subject to client and resolver caching, so traffic proportions are approximate and rollback is slow. Creating a second load balancer also duplicates frontend configuration and TLS management. This approach adds complexity and does not provide the precise, quickly reversible traffic split available within a single backend service.
- ✓
Create a second MIG with the new image, add it as a backend to the existing backend service with a small capacity, and gradually shift traffic between the two MIGs using weighted traffic distribution in the backend service.
Why this is correct
Weighted traffic distribution on a backend service lets you send a controlled percentage of user traffic to a new MIG while keeping the rest on the stable version. Monitoring error rates and adjusting weights gives progressive rollout and instant rollback by setting the new backend weight to zero. This matches canary release requirements without rebuilding instances.
- ✗
Perform an in-place update of the MIG template to the new image with a very small maxUnavailable, and rely on the load balancer health checks to remove unhealthy instances automatically.
Why it's wrong here
Updating the instance template changes all instances toward the new version rather than isolating a subset for canary testing. Health checks only detect instances that fail probes; they do not measure application error rates or business metrics. This method cannot hold a stable version alongside a new version for comparison, so controlled progressive rollout and immediate rollback are not achievable.
- ✗
Use a rolling update with maxSurge and maxUnavailable set to 50% so that half the instances are replaced at once, then wait for health checks to pass before continuing.
Why it's wrong here
A rolling update replaces instances in place and does not give you percentage-based user traffic control. Setting maxSurge and maxUnavailable to 50% increases blast radius because half the capacity can be unavailable or updated simultaneously. It also cannot route a small, measurable slice of live traffic to the new version, so it does not satisfy the gradual canary requirement.
Go deeper
Related to this question
Learn chapter
Load Balancing and Autoscaling
Key term
Instance group
An instance group is a collection of virtual machine instances that are managed as a single unit for scaling, load balancing, and lifecycle management in cloud computing.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.