Professional Cloud Architect practice questions

230 free questions with answers and explanations.

Practice test
  1. 101.A global e-commerce company is experiencing inconsistent application performance during peak shopping seasons. Their microservices architecture relies heavily on inter-service communication over HTTP/REST. Developers report that individual service instances are often underutilized, but the overall system experiences latency spikes and timeouts. You need to identify a strategy to optimize the inter-service communication efficiency and resource utilization. What approach should you recommend?Analyze and optimize technical and business processes
  2. 102.A healthcare provider is building a new patient portal application on Google Cloud that needs to comply with strict regulatory requirements for data residency and sovereignty. Patient data, including medical records and personal identifiable information (PII), must be stored and processed exclusively within a specific geographic region (e.g., EU-West1) and not leave its borders. Which Google Cloud storage and compute configuration ensures this data residency requirement?Analyze and optimize technical and business processes
  3. 103.A global media company uses Google Cloud Storage (GCS) for storing petabytes of video content, including raw footage, transcoded versions, and archived masters. They need to optimize storage costs while ensuring appropriate access latency for different types of content. Raw footage and transcoded versions are frequently accessed for editing and streaming for the first 90 days, after which they are rarely accessed. Archived masters are accessed only for disaster recovery or rare re-renders, typically less than once a year. Which GCS storage classes should they use for each type of content to meet these requirements?Analyze and optimize technical and business processes
  4. 104.A company is observing that their Google Cloud spend on Compute Engine instances is consistently high, even during off-peak hours. Many of these instances run stateless web applications that experience predictable daily traffic patterns. They have a stable baseline workload but also significant spikes. The current strategy uses on-demand VMs. What is the most effective cost optimization strategy for this scenario?Analyze and optimize technical and business processes
  5. 105.A data engineering team is migrating legacy Extract, Transform, Load (ETL) jobs to Google Cloud. These jobs involve complex dependencies, scheduled execution, and require monitoring and alerting for failures. The team needs a fully managed service that can orchestrate these workflows, integrate with various Google Cloud data services (e.g., BigQuery, Cloud Storage, Cloud Dataflow), and allow for custom Python code execution. Which Google Cloud service is BEST suited for orchestrating these complex data pipelines?Analyze and optimize technical and business processes
  6. 106.A global online gaming company is experiencing significant fluctuations in user traffic, with peak loads during evenings and weekends. Their current infrastructure on Google Cloud uses a fixed number of Compute Engine instances, leading to over-provisioning during off-peak hours and performance degradation during peak times. The company wants to optimize costs while ensuring consistent performance. Which Google Cloud feature would be most effective for this scenario?Analyze and optimize technical and business processes
  7. 107.A large manufacturing company is migrating its legacy ERP system to Google Cloud. The ERP system relies heavily on a relational database that generates vast amounts of data daily, including transactional records, sensor data, and operational logs. This data needs to be extracted, transformed, and loaded (ETL) into a data warehouse for analytics and reporting. The company requires a fully managed, serverless ETL service that can handle petabytes of data, integrate with various data sources, and scale automatically. Which Google Cloud service is best suited for this requirement?Analyze and optimize technical and business processes
  8. 108.A multinational company is migrating its enterprise resource planning (ERP) system to Google Cloud. The ERP system contains sensitive financial and customer data that requires strong encryption at rest and in transit. The company has strict compliance requirements that mandate they maintain control over the encryption keys. Which Google Cloud encryption option should they choose for their data stored in Cloud Storage and databases like Cloud SQL?Analyze and optimize technical and business processes
  9. 109.A healthcare provider is building a new application on Google Cloud that processes sensitive patient data. This application must comply with strict regulatory requirements (e.g., HIPAA) regarding data encryption, access controls, and auditing. The application will use Cloud Storage for data at rest and Cloud KMS for key management. To ensure compliance, which specific Cloud Storage encryption option should be chosen to allow the customer to maintain maximum control over the encryption keys and meet regulatory auditing requirements for key usage?Analyze and optimize technical and business processes
  10. 110.A global SaaS provider is experiencing intermittent performance degradation for its API services, which are backed by a Cloud SQL for MySQL database. Developers report that queries sometimes take much longer than expected, but it's hard to pinpoint the exact cause without detailed insights into database operations. You need to recommend a solution that provides in-depth visibility into database performance, identifies slow queries, and helps optimize the database. Which Google Cloud service should you leverage?Analyze and optimize technical and business processes
  11. 111.A global media company is building a new data analytics platform on Google Cloud. They need to ingest massive volumes of real-time streaming data from various sources (e.g., social media feeds, IoT devices, website clicks) and process it for immediate dashboards, anomaly detection, and long-term archival. The data ingestion must be highly scalable, fault-tolerant, and support heterogeneous data formats. Which Google Cloud service should be used as the primary ingestion layer?Analyze and optimize technical and business processes
  12. 112.A financial services company is migrating its critical trading application to Google Cloud. The application requires extremely low-latency network connectivity (under 1ms round-trip time) between its Compute Engine instances and specific on-premises network devices. The current network architecture uses a VPN tunnel, which introduces noticeable latency. The company needs a dedicated, high-bandwidth connection with a Service Level Agreement (SLA) for availability. Which Google Cloud networking solution should they choose?Analyze and optimize technical and business processes
  13. 113.A data analytics company uses BigQuery for its core data warehousing needs. They have several large tables, one of which stores historical clickstream data from their website. This table is petabytes in size and is queried frequently for aggregate analytics, but most queries only target data from the last 90 days. Older data is accessed infrequently, primarily for compliance and historical trend analysis. The company wants to optimize query performance and reduce storage costs for this table without losing access to historical data. Which BigQuery table optimization strategy should they implement?Analyze and optimize technical and business processes
  14. 114.A global SaaS provider is experiencing intermittent performance degradation for its API services, particularly during peak usage hours. Their current architecture uses Google Kubernetes Engine (GKE) for microservices, Cloud Load Balancing, and Cloud SQL for their primary database. After initial investigation, they suspect that inefficient database queries and connection pooling issues are contributing factors, rather than just raw compute capacity. Which two actions should they prioritize to diagnose and optimize the database performance?Analyze and optimize technical and business processes
  15. 115.A global manufacturing company uses a legacy ERP system hosted on-premises. This system generates large daily reports (several TBs) that are critical for business intelligence. The company wants to migrate the reporting pipeline to Google Cloud to leverage BigQuery for analytics, but the legacy ERP system can only export data as flat files to a local NFS share, and it cannot directly connect to cloud APIs. The data transfer needs to be automated, secure, and handle large volumes efficiently. Which Google Cloud solution should be recommended for ingesting these daily reports into Google Cloud Storage before loading into BigQuery?Analyze and optimize technical and business processes
  16. 116.A global e-commerce company is experiencing inconsistent application performance during peak sales events, leading to customer dissatisfaction and lost revenue. Their microservices-based application is deployed on Google Kubernetes Engine (GKE). They suspect network latency, inefficient inter-service communication, and difficulty in tracing requests across multiple services are the root causes. The company wants to gain better visibility into service-to-service communication, improve traffic management, and implement policies like retries and circuit breakers without modifying application code extensively. Which Google Cloud solution would BEST address these challenges?Analyze and optimize technical and business processes
  17. 117.A global SaaS provider is experiencing intermittent performance degradation for its API services, which are backed by a Cloud SQL for PostgreSQL database. Users report slow response times, especially during peak hours. The database team suspects that inefficient queries and resource contention might be contributing factors but lacks granular visibility into query execution plans, resource utilization at the query level, and historical performance trends. Which Google Cloud Operations Suite tool would provide the MOST effective insights to diagnose and resolve these database performance issues?Analyze and optimize technical and business processes
  18. 118.A global SaaS provider is experiencing intermittent performance degradation for its API services hosted on Google Kubernetes Engine (GKE). Users report slow response times, especially during peak hours. The current monitoring setup provides basic CPU and memory metrics, but the engineering team lacks visibility into database query performance, slow transactions, and connection pool utilization. They need a solution that offers deep insights into their Cloud SQL database performance without requiring extensive manual configuration or custom instrumentation. Which Google Cloud service should they use?Analyze and optimize technical and business processes
  19. 119.A global media company is building a new content delivery platform on Google Cloud. They anticipate highly variable traffic patterns, with significant spikes during major live events and holiday seasons, followed by periods of low activity. The company wants to ensure high availability and responsiveness during peak loads while minimizing costs during off-peak times. They also need to rapidly scale their compute resources up and down based on demand. Which Google Cloud compute strategy is MOST appropriate for this scenario?Analyze and optimize technical and business processes
  20. 120.A data analytics company uses BigQuery for its core data warehousing needs. They have several large tables (tens of terabytes each) that are frequently queried by analysts for various reports and dashboards. They've noticed that queries against these largest tables sometimes perform slowly and incur high costs, especially when analysts don't specify filter conditions. Which BigQuery optimization technique should they implement to improve query performance and reduce costs for these large tables?Analyze and optimize technical and business processes
  21. 121.A large enterprise is migrating its legacy applications to Google Cloud. They have a strict policy that all virtual machines and associated resources must be deployed with specific security configurations, such as disabling external IP addresses, enabling OS Login, and ensuring specific network tags are applied. Manually enforcing these configurations across hundreds of projects and thousands of resources is error-prone. Which Google Cloud service can be used to programmatically define and enforce these security and compliance configurations across the organization?Design for security and compliance
  22. 122.A research institution is deploying a data analytics pipeline on Google Cloud that processes large volumes of anonymized patient data. While the data is anonymized, they are concerned about the potential for re-identification attacks if certain combinations of attributes are exposed. They need a service to automatically identify, classify, and, if necessary, redact or transform sensitive data within their datasets before it's used in analytics. Which Google Cloud service is designed for this purpose?Design for security and compliance
  23. 123.A global pharmaceutical company is building a research data platform on Google Cloud. The platform will store highly sensitive clinical trial data, which must be protected against unauthorized access and modification, ensuring data integrity and non-repudiation. They need to verify the authenticity and integrity of data and logs, especially for audit purposes. Which cryptographic technique, supported by Google Cloud services, is crucial for achieving data integrity and non-repudiation for audit logs and critical data files?Design for security and compliance
  24. 124.A healthcare provider is deploying a new patient records application on Google Cloud. The application will store highly sensitive protected health information (PHI) in BigQuery datasets and needs to ensure that only specific individuals from the 'Medical_Staff' group can decrypt and access this data. They also need to ensure that the keys used for encryption are automatically rotated every 90 days. Which Google Cloud service should be configured to manage these encryption keys and access policies?Design for security and compliance
  25. 125.A global e-commerce company is deploying a new customer portal on Google Cloud. The company must comply with GDPR and CCPA regulations, which require that customer data (personally identifiable information - PII) is not persistently stored outside specific geographic regions. The portal uses Cloud Storage for user-uploaded content and Cloud SQL for customer profiles. How should you design the data storage to ensure compliance with data residency requirements?Design for security and compliance
  26. 126.A software development company uses Artifact Registry to store their container images and Maven artifacts. They need to ensure that all artifacts pushed to the registry are scanned for known vulnerabilities before they can be deployed to production environments. This is a critical step in their secure software supply chain strategy. Which Google Cloud service integrates with Artifact Registry to automatically perform vulnerability scanning on container images?Design for security and compliance
  27. 127.A multinational enterprise is migrating thousands of legacy applications to Google Cloud. They have a strict corporate policy that dictates all new Google Cloud projects must have specific services disabled (e.g., Cloud Shell, App Engine) and must enforce uniform network configurations across all projects. This policy needs to be enforced organization-wide to prevent non-compliant resource deployments. Which Google Cloud service should they use to achieve this consistent, organization-wide policy enforcement?Design for security and compliance
  28. 128.A global media company uses Google Cloud Storage to host vast amounts of video content, images, and documents. They need to ensure the integrity and authenticity of this media content, verifying that it has not been tampered with since its original upload. They also need to allow third-party partners to verify the origin and integrity of specific files without direct access to the storage bucket. Which cryptographic technique should be implemented?Design for security and compliance
  29. 129.A global media conglomerate is migrating its archival video content, including highly sensitive unreleased footage and proprietary intellectual property, to Google Cloud Storage. The company has a strict compliance requirement to demonstrate exclusive control over the encryption keys for this sensitive data. They also need to ensure that the data remains accessible to authorized internal teams for editing and distribution workflows. Which encryption key management solution should be implemented to meet these requirements?Design for security and compliance
  30. 130.A global software company maintains a large repository of container images in Artifact Registry. They need to ensure that all container images deployed to production environments are free from known vulnerabilities and comply with internal security policies before deployment. They also need to automate this scanning process as part of their CI/CD pipeline. Which Google Cloud service should be integrated into their pipeline to achieve this?Design for security and compliance
  31. 131.A public sector agency is migrating its critical applications to Google Cloud. They operate under a zero-trust security model, requiring that all user and service interactions with cloud resources are continuously authenticated, authorized, and encrypted, regardless of network location. They need a service that provides centralized identity management, strong authentication mechanisms (e.g., MFA), and granular authorization across all Google Cloud resources. Which Google Cloud service combination is fundamental to implementing a comprehensive zero-trust security model?Design for security and compliance
  32. 132.A SaaS provider is building a multi-tenant application on Google Cloud. Each tenant's data must be logically isolated from other tenants, and the provider needs to ensure that access to each tenant's data is strictly controlled, even by administrators. They want to use a combination of Google Cloud services to achieve robust logical isolation and access control for tenant data, while minimizing operational overhead. Which combination of services provides the strongest logical isolation and access control for multi-tenant data in Google Cloud?Design for security and compliance
  33. 133.A global e-commerce company is deploying a new customer portal on Google Cloud. The company needs to ensure that all customer data at rest in Cloud Storage buckets is encrypted using keys that they control and manage outside of Google Cloud's infrastructure, while still leveraging Google Cloud Storage for object storage. Which encryption key management approach should they choose?Design for security and compliance
  34. 134.An online gaming company is experiencing frequent DDoS attacks targeting its public-facing game servers hosted on Google Compute Engine. These attacks lead to service unavailability and a poor user experience. The company needs a managed service that can protect its applications from various types of network and application layer DDoS attacks, as well as provide Web Application Firewall (WAF) capabilities to mitigate common web vulnerabilities. Which Google Cloud service should they implement?Design for security and compliance
  35. 135.A large enterprise is migrating its on-premises applications to Google Cloud. They have a strict regulatory requirement to encrypt all data at rest, including database backups and object storage, using customer-managed encryption keys (CMEK) and ensure that key access is auditable. Which Google Cloud service should be used to manage these encryption keys to meet these requirements?Design for security and compliance
  36. 136.A global software company maintains a large repository of container images in Artifact Registry. They have a strict security policy requiring that all container images deployed into production environments must be scanned for known vulnerabilities and approved by a security team before deployment. How can they automate the enforcement of this policy within Google Cloud?Design for security and compliance
  37. 137.A global media company uses Google Cloud Storage to host vast amounts of video content, images, and other media files. They need to ensure the integrity of these files against tampering and detect any unauthorized modifications. They also need to provide a non-repudiable proof of the file's origin. Which cryptographic technique should be used to meet these requirements?Design for security and compliance
  38. 138.A multinational e-commerce company is expanding its operations into new regions. They need to ensure that customer data collected in a specific country (e.g., Germany) is stored and processed exclusively within that country's borders to comply with local data protection regulations. The company uses Cloud Storage for data lakes and BigQuery for analytics. How should they design their Google Cloud environment to guarantee this data residency requirement?Design for security and compliance
  39. 139.A multinational enterprise is migrating thousands of legacy applications to Google Cloud. They need to establish a consistent security policy across all projects and folders within their organization, such as restricting resource creation to specific regions, enforcing specific VM image families, and preventing the use of external IP addresses on VMs. Which Google Cloud service should be used to centrally manage and enforce these organizational-wide policies?Design for security and compliance
  40. 140.A large public sector agency is migrating its highly sensitive citizen data application to Google Cloud. They operate under a 'Zero Trust' security model, requiring that no user or service is implicitly trusted, even if they are within the organization's network. Access to resources must be continuously verified based on context like identity, device health, and location. Which Google Cloud service combination is most appropriate to implement a Zero Trust model for this application?Design for security and compliance
  41. 141.A global bank is migrating its core banking applications to Google Cloud. They have a strict requirement that all data in transit between Google Cloud services (e.g., Compute Engine to Cloud Storage, or BigQuery to Dataflow) must be encrypted by default, without requiring explicit configuration by application developers. This is to ensure a 'secure by default' posture and simplify compliance. How is this requirement met in Google Cloud?Design for security and compliance
  42. 142.A global financial institution is migrating its core banking applications to Google Cloud. They have a strict regulatory requirement to encrypt all data at rest using FIPS 140-2 Level 3 validated hardware security modules (HSMs). The solution must ensure that the encryption keys are never exposed outside of the HSMs. Which Google Cloud service should they use to meet this specific compliance requirement?Design for security and compliance
  43. 143.A defense contractor is migrating sensitive military project data to Google Cloud. They require extremely high network isolation, where data in transit between virtual machines within the same Virtual Private Cloud (VPC) network, even within the same project, must be encrypted. They also need to ensure that this encryption is managed by Google and operates transparently without requiring application-level changes. Which Google Cloud feature provides this level of internal network encryption?Design for security and compliance
  44. 144.A research institution is deploying a data analytics pipeline on Google Cloud that processes sensitive genetic data. They need to comply with strict privacy regulations, which require that personally identifiable information (PII) within the datasets is masked or de-identified before being used for analytics, to prevent re-identification. The institution wants a managed service that can automatically discover and redact or transform sensitive data within various data sources (e.g., BigQuery, Cloud Storage). Which Google Cloud service is designed for this purpose?Design for security and compliance
  45. 145.A multinational enterprise is migrating its legacy applications to Google Cloud. The security team has mandated that all external internet-facing applications must be protected against common web vulnerabilities, including SQL injection, cross-site scripting (XSS), and DDoS attacks. They also need granular control over traffic based on IP addresses and geographic locations. Which Google Cloud service should be implemented to address these requirements?Design for security and compliance
  46. 146.A media company uses Google Cloud for its content delivery platform. They need to ensure that all network traffic between their virtual machines (VMs) in different VPCs within the same Google Cloud organization is encrypted in transit by default, without requiring application-level encryption or manual configuration on each VM. This is critical for protecting sensitive metadata and ensuring compliance. Which Google Cloud networking feature provides automatic, authenticated, and encrypted communication between VMs in different VPCs without additional setup?Design for security and compliance
  47. 147.A multinational e-commerce company is expanding its operations into new regions. They need to ensure that customer data stored in Google Cloud meets the data residency requirements of each specific country, meaning data must physically reside within the borders of that country. The company uses Cloud Storage for storing user-uploaded content and customer profiles. How can the company best achieve this data residency requirement for Cloud Storage?Design for security and compliance
  48. 148.A healthcare provider is building a new application on Google Cloud to store electronic health records (EHR). Due to strict regulatory requirements (e.g., HIPAA), they must ensure that all data at rest and in transit is encrypted, and that the encryption keys are managed in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which Google Cloud service should be used to meet these key management requirements?Design for security and compliance
  49. 149.A defense contractor is migrating sensitive military project data to Google Cloud. They require strict network isolation for their virtual machines (VMs) and other resources, ensuring that no traffic can flow between different projects or even different departments within the same project without explicit, granular control. The network design must prevent accidental exposure and limit the blast radius of any security incidents. Which Google Cloud networking construct is best suited to provide this level of isolation and granular control?Design for security and compliance
  50. 150.A financial services company needs to process sensitive customer transaction data using Google Kubernetes Engine (GKE). They are concerned about the possibility of data exfiltration and want to create a secure perimeter around their GKE clusters and associated Google Cloud resources (e.g., Cloud Storage, BigQuery) that prevents data from leaving the defined perimeter, even if credentials are stolen or misconfigurations occur. Which Google Cloud security offering is designed to address this specific concern?Design for security and compliance