Google PROFESSIONAL CLOUD ARCHITECT
Q: 1
You have an outage in your Compute Engine managed instance group: all instance keep restarting
after 5 seconds. You have a health check configured, but autoscaling is disabled. Your colleague, who
is a Linux expert, offered to look into the issue. You need to make sure that he can access the VMs.
What should you do?
Options
Q: 2
TerramEarth has a legacy web application that you cannot migrate to cloud. However, you still want
to build a cloud-native way to monitor the application. If the application goes down, you want the
URL to point to a "Site is unavailable" page as soon as possible. You also want your Ops team to
receive a notification for the issue. You need to build a reliable solution for minimum cost
What should you do?
Options
Q: 3
You deploy your custom Java application to Google App Engine. It fails to deploy and gives you the
following stack trace.
What should you do?
What should you do?Options
Q: 4
For this question, refer to the Dress4Win case study.
As part of Dress4Win's plans to migrate to the cloud, they want to be able to set up a managed
logging and monitoring system so they can handle spikes in their traffic load. They want to ensure
that:
• The infrastructure can be notified when it needs to scale up and down to handle the ebb and flow
of usage throughout the day
• Their administrators are notified automatically when their application reports errors.
• They can filter their aggregated logs down in order to debug one piece of the application across
many hosts
Which Google StackDriver features should they use?
Options
Q: 5
For this question, refer to the TerramEarth case study.
TerramEarth's CTO wants to use the raw data from connected vehicles to help identify approximately
when a vehicle in the development team to focus their failure. You want to allow analysts to centrally
query the vehicle dat
a. Which architecture should you recommend?
A)
B)
C)
D)

B)
C)
D)

Options
Q: 6
You are using Cloud SQL as the database backend for a large CRM deployment. You want to scale as
usage increases and ensure that you don’t run out of storage, maintain 75% CPU usage cores, and
keep replication lag below 60 seconds. What are the correct steps to meet your requirements?
Options
Q: 7
For this question, refer to the Mountkirk Games case study.
Mountkirk Games wants to set up a continuous delivery pipeline. Their architecture includes many
small services that they want to be able to update and roll back quickly. Mountkirk Games has the
following requirements:
• Services are deployed redundantly across multiple regions in the US and Europe.
• Only frontend services are exposed on the public internet.
• They can provide a single frontend IP for their fleet of services.
• Deployment artifacts are immutable.
Which set of products should they use?
Options
Q: 8
You need to develop procedures to test a disaster plan for a mission-critical application. You want to
use
Google-recommended practices and native capabilities within GCP.
What should you do?
Options
Q: 9
Your company is moving 75 TB of data into Google Cloud. You want to use Cloud Storage and follow
Googlerecommended practices. What should you do?
Options
Q: 10
Your company operates nationally and plans to use GCP for multiple batch workloads, including
some that are not time-critical. You also need to use GCP services that are HIPAA-certified and
manage service costs.
How should you design to meet Google best practices?
Options
Q: 11
You are working in a highly secured environment where public Internet access from the Compute
Engine VMs is not allowed. You do not yet have a VPN connection to access an on-premises file
server. You need to install specific software on a Compute Engine instance. How should you install the
software?
Options
Q: 12
You are deploying an application on App Engine that needs to integrate with an on-premises
database. For security purposes, your on-premises database must not be accessible through the
public Internet. What should you do?
Options
Q: 13
Your customer wants to do resilience testing of their authentication layer. This consists of a regional
managed instance group serving a public REST API that reads from and writes to a Cloud SQL
instance.
What should you do?
Options
Q: 14
Your customer wants to capture multiple GBs of aggregate real-time key performance indicators
(KPIs) from their game servers running on Google Cloud Platform and monitor the KPIs with low
latency. How should they capture the KPIs?
Options
Q: 15
You have an App Engine application that needs to be updated. You want to test the update with
production traffic before replacing the current application version.
What should you do?
Options
Q: 16
All compute Engine instances in your VPC should be able to connect to an Active Directory server on
specific ports. Any other traffic emerging from your instances is not allowed. You want to enforce this
using VPC firewall rules.
How should you configure the firewall rules?
Options
Q: 17
You need to evaluate your team readiness for a new GCP project. You must perform the evaluation
and create a skills gap plan incorporates the business goal of cost optimization. Your team has
deployed two GCP projects successfully to date. What should you do?
Options
Q: 18
Your BigQuery project has several users. For audit purposes, you need to see how many queries each
user ran in the last month.
Options
Q: 19
Your organization has decided to restrict the use of external IP addresses on instances to only
approved instances. You want to enforce this requirement across all of your Virtual Private Clouds
(VPCs). What should you do?
Options
Q: 20
You have an application that will run on Compute Engine. You need to design an architecture that
takes into account a disaster recovery plan that requires your application to fail over to another
region in case of a regional outage. What should you do?
Options
Q: 21
Your company is designing its application landscape on Compute Engine. Whenever a zonal outage
occurs, the application should be restored in another zone as quickly as possible with the latest
application dat
a. You need to design the solution to meet this requirement. What should you do?
Options
Q: 22
Your company has an application deployed on Anthos clusters (formerly Anthos GKE) that is running
multiple microservices. The cluster has both Anthos Service Mesh and Anthos Config Management
configured. End users inform you that the application is responding very slowly. You want to identify
the microservice that is causing the delay. What should you do?
Options
Q: 23
You need to deploy an application on Google Cloud that must run on a Debian Linux environment.
The application requires extensive configuration in order to operate correctly. You want to ensure
that you can install Debian distribution updates with minimal manual intervention whenever they
become available. What should you do?
Options
Q: 24
You team needs to create a Google Kubernetes Engine (GKE) cluster to host a newly built application
that requires access to third-party services on the internet. Your company does not allow any
Compute Engine instance to have a public IP address on Google Cloud. You need to create a
deployment strategy that adheres to these guidelines. What should you do?
Options
Q: 25
You need to design a solution for global load balancing based on the URL path being requested. You
need to ensure operations reliability and end-to-end in-transit encryption based on Google best
practices.
What should you do?
Options
Q: 26
You are using a single Cloud SQL instance to serve your application from a specific zone. You want to
introduce high availability. What should you do?
Options
Q: 27
Your company captures all web traffic data in Google Analytics 260 and stores it in BigQuery. Each
country has its own dataset. Each dataset has multiple tables. You want analysts from each country
to be able to see and query only the data for their respective countries.
How should you configure the access rights?
Options
Q: 28
You need to deploy a stateful workload on Google Cloud. The workload can scale horizontally, but
each instance needs to read and write to the same POSIX filesystem. At high load, the stateful
workload needs to support up to 100 MB/s of writes. What should you do?
Options
Q: 29
Your company uses Google Kubernetes Engine (GKE) as a platform for all workloads. Your company
has a single large GKE cluster that contains batch, stateful, and stateless workloads. The GKE cluster
is configured with a single node pool with 200 nodes. Your company needs to reduce the cost of this
cluster but does not want to compromise availability. What should you do?
Options
Q: 30
Your company is building a new architecture to support its data-centric business focus. You are
responsible for setting up the network. Your company’s mobile and web-facing applications will be
deployed on-premises, and all data analysis will be conducted in GCP. The plan is to process and load
7 years of archived .csv files totaling 900 TB of data and then continue loading 10 TB of data daily. You
currently have an existing 100-MB internet connection.
What actions will meet your company’s needs?
Options
Q: 31
Your company wants to start using Google Cloud resources but wants to retain their on-premises
Active
Directory domain controller for identity management. What should you do?
Options
Q: 32
Your web application must comply with the requirements of the European Union’s General Data
Protection Regulation (GDPR). You are responsible for the technical architecture of your web
application. What should you do?
Options
Q: 33
You are working at an institution that processes medical dat
a. You are migrating several workloads onto Google Cloud. Company policies require all workloads to
run on physically separated hardware, and workloads from different clients must also be separated
You created a sole-tenant node group and added a node for each client. You need to deploy the
workloads on these dedicated hosts. What should you do?
Options
Q: 34
Your company recently acquired a company that has infrastructure in Google Cloud. Each company
has its own Google Cloud organization Each company is using a Shared Virtual Private Cloud (VPC) to
provide network connectivity tor its applications Some of the subnets used by both companies
overlap In order for both businesses to integrate, the applications need to have private network
connectivity. These applications are not on overlapping subnets. You want to provide connectivity
with minimal re-engineering. What should you do?
Options
Q: 35
For this question, refer to the Mountkirk Games case study.
Mountkirk Games has deployed their new backend on Google Cloud Platform (GCP). You want to
create a thorough testing process for new versions of the backend before they are released to the
public. You want the testing environment to scale in an economical way. How should you design the
process?
Options
Question 1 of 35