Step2Study
IT & TechnologyP-C-ARCH100% Free

Professional Cloud Architect

Practice bank
230 Qs
Real exam
50 Qs
Time limit
120 min
Passing
The Professional Cloud Architect exam assesses your ability to design, develop, and manage robust, secure, scalable, highly available, and dynamic solutions to drive business objectives.

Exam blueprint

Design and plan a cloud solution architecture
30%
Manage and provision solution infrastructure
25%
Design for security and compliance
20%
Analyze and optimize technical and business processes
15%
Manage implementation
10%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 216 min · pass 70% · 230 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Professional Cloud Architect practice test questions

Sample questions from the 230-question bank, with answers and explanations.

All questions
  1. 1. A financial institution is migrating its legacy mainframe applications to Google Cloud. The applications require extremely low latency access to shared file storage, with strict consistency and high IOPS. The data needs to be accessible by multiple Compute Engine instances simultaneously. Which Google Cloud storage service should be recommended?

    Design and plan a cloud solution architecture

    • A. Cloud Bigtable
    • B. Filestore Enterprise
    • C. Persistent Disk
    • D. Cloud Storage Standard
    Show answer

    B. Filestore Enterprise

    Filestore Enterprise provides fully managed, highly available, and scalable Network File System (NFS) storage with extremely low latency and high IOPS, suitable for enterprise applications requiring shared file systems like mainframe migrations.

  2. 2. A startup is building a new social media application and expects rapid, unpredictable growth in user traffic. The application consists of several stateless microservices and needs to automatically scale from zero to handle millions of requests, without requiring developers to manage the underlying infrastructure. They also prioritize cost efficiency by paying only for resources consumed during active use. Which Google Cloud compute service is the best fit?

    Design and plan a cloud solution architecture

    • A. Google Kubernetes Engine (GKE) Autopilot
    • B. App Engine Flexible Environment
    • C. Cloud Run
    • D. Compute Engine with Managed Instance Groups
    Show answer

    C. Cloud Run

    Cloud Run is a serverless platform for stateless containers that automatically scales from zero to meet demand and incurs costs only when requests are being processed. This perfectly aligns with the requirements of rapid, unpredictable growth, minimal infrastructure management, and cost efficiency for stateless microservices.

  3. 3. A financial services company is migrating its on-premises data warehouse to Google Cloud. The current data warehouse is several petabytes in size and requires complex SQL queries for reporting and analytics. The company needs a highly scalable, fully managed, and cost-effective solution that can handle massive datasets and allow for rapid query execution. Which Google Cloud product is the best fit for these requirements?

    Design and plan a cloud solution architecture

    • A. Cloud SQL
    • B. BigQuery
    • C. Cloud Storage
    • D. Cloud Spanner
    Show answer

    B. BigQuery

    BigQuery is a serverless, highly scalable, and cost-effective enterprise data warehouse designed for petabyte-scale analytics, making it ideal for complex SQL queries on large datasets.

  4. 4. A startup is building a new web application with a microservices architecture. They need a highly available, scalable, and fully managed database for their core transactional data. The database must support relational queries, store up to 10 TB of data, and handle sudden spikes in traffic without manual scaling. Which Google Cloud database service should they choose?

    Design and plan a cloud solution architecture

    • A. Bigtable
    • B. Cloud SQL
    • C. Cloud Spanner
    • D. Cloud Firestore
    Show answer

    C. Cloud Spanner

    Cloud Spanner is a globally distributed, strongly consistent, and horizontally scalable relational database service that can handle transactional workloads at petabyte scale. Its automatic sharding and scaling capabilities make it suitable for high-growth applications with unpredictable traffic spikes.

  5. 5. A research institution processes large genomic datasets that are stored in Cloud Storage. These datasets need to be processed by a custom scientific application running on Compute Engine VMs. The application is sensitive to network latency and requires high-throughput access to the data. The institution wants to optimize performance and reduce egress costs when accessing data from Cloud Storage. Which network configuration should be implemented?

    Design and plan a cloud solution architecture

    • A. Enable Private Google Access on the subnet where the VMs are located.
    • B. Use Cloud VPN to connect VMs to Cloud Storage.
    • C. Access Cloud Storage over the public internet.
    • D. Mount Cloud Storage buckets as file systems using Cloud Filestore.
    Show answer

    A. Enable Private Google Access on the subnet where the VMs are located.

    Enabling Private Google Access on the subnet allows VMs without external IP addresses to access Google Cloud services, including Cloud Storage, over Google's internal network. This reduces latency, increases throughput, and eliminates egress costs to the public internet.

  6. 6. A customer is migrating a custom application that currently uses UDP multicast for service discovery between instances. The application needs to maintain this discovery mechanism after migrating to Google Cloud. Which Google Cloud networking component would allow this functionality within a Virtual Private Cloud (VPC) network?

    Design and plan a cloud solution architecture

    • A. VPC Flow Logs
    • B. Shared VPC
    • C. No direct support for UDP multicast in Google Cloud VPC networks.
    • D. Cloud DNS
    Show answer

    C. No direct support for UDP multicast in Google Cloud VPC networks.

    Google Cloud VPC networks do not natively support UDP multicast. Customers typically need to re-architect applications to use unicast communication, such as a centralized discovery service (e.g., Cloud DNS, Consul, ZooKeeper) or a message queue, instead of relying on multicast.

  7. 7. A large pharmaceutical company is migrating its research data, including clinical trial results and genomic sequences, to Google Cloud. This data is critical, highly sensitive, and subject to strict regulatory compliance (e.g., HIPAA, GDPR). The company needs to ensure that data access is restricted to authorized personnel only, and that any attempt to exfiltrate data outside of approved perimeters is prevented. They also want to isolate their sensitive data processing environments from the public internet. Which security control combination should they implement?

    Design and plan a cloud solution architecture

    • A. VPC Service Controls and Context-Aware Access
    • B. VPC Service Controls and Shared VPC
    • C. Cloud Armor and Cloud Data Loss Prevention (DLP)
    • D. Identity and Access Management (IAM) and Security Command Center
    Show answer

    A. VPC Service Controls and Context-Aware Access

    VPC Service Controls create a security perimeter around sensitive data resources, preventing data exfiltration and isolating them from unauthorized networks. Context-Aware Access (part of BeyondCorp Enterprise) then provides granular access control based on user identity, device posture, and location, ensuring only authorized personnel with compliant devices can access the data within the perimeter.

  8. 8. A global company is migrating its legacy content management system (CMS) to Google Cloud. The CMS hosts millions of static assets (images, videos, documents) that are accessed globally by users. They need a storage solution that offers extremely high availability, global access with low latency, and efficient caching at the edge. The content is infrequently updated but frequently read.

    Design and plan a cloud solution architecture

    • A. Cloud Storage Regional bucket with external HTTP(S) Load Balancer
    • B. Cloud SQL with Cloud CDN
    • C. Filestore Enterprise with Cloud VPN
    • D. Cloud Storage Multi-Regional bucket with Cloud CDN
    Show answer

    D. Cloud Storage Multi-Regional bucket with Cloud CDN

    A Cloud Storage Multi-Regional bucket provides high availability and global access for static assets. Integrating it with Cloud CDN ensures low-latency delivery to global users through edge caching, which is ideal for infrequently updated and frequently read content.

  9. 9. A media company needs to store a vast archive of video files (hundreds of petabytes) that are accessed very infrequently, perhaps once a year for compliance audits or rare content requests. The primary concern is minimizing storage costs while ensuring long-term durability. Which Google Cloud Storage class is most appropriate?

    Design and plan a cloud solution architecture

    • A. Cloud Storage Archive
    • B. Cloud Storage Standard
    • C. Cloud Storage Coldline
    • D. Cloud Storage Nearline
    Show answer

    A. Cloud Storage Archive

    Cloud Storage Archive is designed for long-term data archiving with very infrequent access (less than once a year). It offers the lowest storage cost, making it ideal for hundreds of petabytes of rarely accessed video archives.

  10. 10. A client is migrating an on-premises application that relies heavily on a high-performance, low-latency block storage solution for its database. The database requires consistent IOPS and throughput, and the data must be highly durable. The application is sensitive to storage performance fluctuations. Which Google Cloud storage option should you recommend to meet these requirements?

    Design and plan a cloud solution architecture

    • A. Persistent Disk Extreme (SSD)
    • B. Persistent Disk Balanced (SSD)
    • C. Filestore Basic SSD
    • D. Cloud Storage Standard class
    Show answer

    A. Persistent Disk Extreme (SSD)

    Persistent Disk Extreme (SSD) is designed for the highest performance, lowest latency, and most consistent IOPS/throughput among Google Cloud's block storage options, making it ideal for highly sensitive databases.

  11. 11. A global software company is developing a new microservices application using containers on Google Cloud. They need a solution that automates the deployment, scaling, and management of these containerized applications across multiple clusters in different regions. The solution must also provide advanced features like service discovery, load balancing, and self-healing capabilities. Which Google Cloud service should they choose?

    Design and plan a cloud solution architecture

    • A. Compute Engine
    • B. Cloud Run
    • C. App Engine Standard
    • D. Google Kubernetes Engine (GKE)
    Show answer

    D. Google Kubernetes Engine (GKE)

    Google Kubernetes Engine (GKE) is a managed Kubernetes service that provides a robust platform for deploying, managing, and scaling containerized applications. It offers built-in features like service discovery, load balancing, self-healing, and multi-cluster management, which are essential for a complex microservices architecture.

  12. 12. A global manufacturing company needs to collect and process large volumes of real-time sensor data from its factories worldwide. This data needs to be ingested continuously, transformed, and then stored in a data warehouse for analytics. The solution must be highly scalable, fault-tolerant, and support both streaming and batch processing paradigms. Which Google Cloud services should be used to build this data pipeline?

    Design and plan a cloud solution architecture

    • A. Cloud SQL, Cloud Functions, Looker
    • B. Cloud IoT Core, Cloud Spanner, Cloud Data Studio
    • C. Cloud Storage, Cloud Dataproc, BigQuery
    • D. Cloud Pub/Sub, Cloud Dataflow, BigQuery
    Show answer

    D. Cloud Pub/Sub, Cloud Dataflow, BigQuery

    Cloud Pub/Sub is ideal for ingesting real-time streaming data. Cloud Dataflow provides a fully managed service for executing Apache Beam pipelines, supporting both streaming and batch processing for data transformation. BigQuery is the scalable data warehouse for analytics.

  13. 13. A research institution processes highly sensitive genomic data and uses custom-built, open-source tools for analysis. These tools are containerized and require access to GPUs for accelerated processing. The institution needs to run these jobs in a secure, isolated environment, with minimal operational overhead for managing the underlying infrastructure. They also need to ensure that the compute resources are provisioned on-demand and scale automatically. Which Google Cloud service should they choose?

    Design and plan a cloud solution architecture

    • A. Compute Engine with GPU-enabled VMs
    • B. Cloud Run for Anthos
    • C. Google Kubernetes Engine (GKE) Standard
    • D. GKE Autopilot
    Show answer

    D. GKE Autopilot

    GKE Autopilot provides a fully managed Kubernetes experience, handling node provisioning, scaling, and upgrades with minimal operational overhead. It supports GPU workloads and offers a secure, isolated environment for containerized applications, perfectly matching the research institution's requirements.

  14. 14. A research institution processes highly sensitive genomic data and uses custom-built, open-source machine learning models. They need a compute environment that provides fine-grained control over the underlying infrastructure, including specific GPU types and custom kernel modules. The workloads are long-running and require consistent performance, but the institution also wants to optimize costs by leveraging committed use discounts. Which Google Cloud compute option should you recommend?

    Design and plan a cloud solution architecture

    • A. Cloud Run with custom container images
    • B. Compute Engine with custom machine types and GPUs
    • C. Cloud Functions with custom runtimes
    • D. GKE Autopilot with GPU enabled
    Show answer

    B. Compute Engine with custom machine types and GPUs

    Compute Engine provides the most granular control over VM instances, allowing selection of specific GPU types and installation of custom kernel modules. This level of customization, combined with committed use discounts for cost optimization, makes it ideal for specialized research workloads.

  15. 15. A research institution processes highly sensitive genomic data and uses custom-built, open-source machine learning models. They need a compute environment that offers strong isolation, precise control over resource allocation, and predictable performance for their specialized, security-critical workloads. The institution also wants to minimize operational overhead for managing the underlying infrastructure. Which GKE mode should they choose?

    Design and plan a cloud solution architecture

    • A. GKE Standard with preemptible VMs
    • B. GKE Standard with custom node pools
    • C. GKE Standard with sole-tenant nodes
    • D. GKE Autopilot
    Show answer

    B. GKE Standard with custom node pools

    GKE Standard with custom node pools provides the necessary control over node types, resource allocation, and isolation needed for specialized, security-critical workloads while still benefiting from GKE's orchestration capabilities. Autopilot abstracts away too much control, preemptible VMs are not for predictable performance, and sole-tenant nodes are for extreme isolation needs often with licensing, not the primary solution for 'precise control over resource allocation' in this context.

  16. 16. A global online gaming company is experiencing rapid growth and needs to scale its backend services to handle millions of concurrent users. Their current architecture relies on a custom-built, stateful session management service that frequently accesses an in-memory key-value store. The company requires very low latency access (sub-millisecond) to this data, high availability across regions, and automatic scaling capabilities. Which Google Cloud service should you recommend for their session management data store?

    Design and plan a cloud solution architecture

    • A. Cloud SQL for PostgreSQL
    • B. Memorystore for Redis Cluster
    • C. Cloud Spanner
    • D. Bigtable
    Show answer

    B. Memorystore for Redis Cluster

    Memorystore for Redis Cluster provides a fully managed, in-memory key-value store with sub-millisecond latency, high availability, and horizontal scaling across multiple regions, perfectly suiting the demands of a global online gaming session management service.

  17. 17. A healthcare provider is migrating sensitive patient data to Google Cloud. The data must be encrypted at rest and in transit, and access must be restricted based on the principle of least privilege. The provider also needs to demonstrate compliance with HIPAA regulations. Which combination of Google Cloud security features should be implemented?

    Design and plan a cloud solution architecture

    • A. Customer-Managed Encryption Keys (CMEK) for Cloud Storage and databases, VPC Service Controls for data exfiltration prevention, and Cloud IAM for granular access control.
    • B. Google-Managed Encryption Keys (GMEK) for all data, Security Command Center for vulnerability scanning, and Shared VPC for network isolation.
    • C. Cloud Key Management Service (KMS) for all encryption, Cloud Armor for DDoS protection, and Cloud Audit Logs for compliance reporting.
    • D. Customer-Supplied Encryption Keys (CSEK) for Cloud Storage, Identity-Aware Proxy (IAP) for application access, and Cloud DLP for data scanning.
    Show answer

    A. Customer-Managed Encryption Keys (CMEK) for Cloud Storage and databases, VPC Service Controls for data exfiltration prevention, and Cloud IAM for granular access control.

    CMEK provides customer control over encryption keys, VPC Service Controls creates a security perimeter against data exfiltration, and Cloud IAM enforces least privilege. This combination directly addresses encryption, access control, and compliance needs for sensitive data like HIPAA.

  18. 18. A multinational corporation is migrating its sensitive human resources (HR) application to Google Cloud. The application stores highly confidential employee data. The company's compliance requirements mandate that all data at rest must be encrypted with customer-managed encryption keys (CMEK) and regularly rotated. Additionally, access to this data must be strictly controlled and audited. Which Google Cloud service combination should be used to store the application's data?

    Design and plan a cloud solution architecture

    • A. Cloud SQL with customer-managed encryption keys (CMEK) and Cloud Audit Logs
    • B. BigQuery with default encryption and Identity and Access Management (IAM)
    • C. Cloud Storage with customer-supplied encryption keys (CSEK)
    • D. Firestore with Google-managed encryption keys and VPC Service Controls
    Show answer

    A. Cloud SQL with customer-managed encryption keys (CMEK) and Cloud Audit Logs

    Cloud SQL supports CMEK for data at rest, allowing customer control over encryption keys and rotation. Cloud Audit Logs provide a comprehensive audit trail of access to the data, satisfying the strict control and auditing requirements for sensitive HR data.

  19. 19. A global company requires a disaster recovery (DR) strategy for its critical application hosted on Google Cloud. The application must be restored and fully operational within 4 hours (RTO) and should not lose more than 15 minutes of data (RPO). The application uses Compute Engine instances, regional persistent disks, and a Cloud SQL database. Which DR strategy would meet these requirements most cost-effectively?

    Design and plan a cloud solution architecture

    • A. Backup and restore to a different region.
    • B. Snapshot persistent disks and export Cloud SQL backups to Cloud Storage in a different region.
    • C. Active-active deployment across multiple regions.
    • D. Active-passive deployment in a different region.
    Show answer

    D. Active-passive deployment in a different region.

    An active-passive (warm standby) deployment in a different region involves maintaining a scaled-down, ready-to-go environment. This can meet an RTO of 4 hours by scaling up and redirecting traffic. For an RPO of 15 minutes, Cloud SQL's high availability or cross-region replicas and persistent disk replication (or frequent snapshots) can ensure minimal data loss. This is generally more cost-effective than active-active while still meeting the RTO/RPO.

  20. 20. A company is migrating its existing monolithic application to Google Cloud and plans to re-architect it into microservices. Each microservice will be deployed as a container. The company needs an orchestration platform that provides automatic scaling, self-healing capabilities, and efficient resource utilization across a cluster of nodes. Which Google Cloud service is the most appropriate for this scenario?

    Design and plan a cloud solution architecture

    • A. App Engine Standard
    • B. Google Kubernetes Engine (GKE)
    • C. Cloud Run
    • D. Compute Engine
    Show answer

    B. Google Kubernetes Engine (GKE)

    Google Kubernetes Engine (GKE) is a fully managed Kubernetes service that excels at orchestrating containerized applications, providing features like automatic scaling, self-healing, and efficient resource management for microservices architectures.

  21. 21. A retail company is migrating its inventory management system to Google Cloud. The system relies on a PostgreSQL database that is critical for daily operations and has strict uptime requirements. They need a fully managed database service that offers high availability, automatic backups, and simplified patching, allowing their team to focus on application development rather than database administration. Which Google Cloud service should they choose?

    Design and plan a cloud solution architecture

    • A. BigQuery
    • B. Compute Engine with self-managed PostgreSQL
    • C. Cloud Spanner
    • D. Cloud SQL for PostgreSQL
    Show answer

    D. Cloud SQL for PostgreSQL

    Cloud SQL for PostgreSQL is a fully managed relational database service that provides high availability, automatic backups, and simplified patching, significantly reducing operational overhead for critical transactional databases.

  22. 22. A global e-commerce company is experiencing inconsistent performance and high latency for its web application, which serves customers worldwide. The application is currently hosted in a single Google Cloud region. The company wants to improve user experience by reducing latency and ensuring high availability across different geographic locations. Which Google Cloud networking product should they use to distribute traffic globally and route users to the closest healthy backend?

    Design and plan a cloud solution architecture

    • A. Internal HTTP(S) Load Balancer
    • B. Global External HTTP(S) Load Balancer
    • C. Network Load Balancer
    • D. SSL Proxy Load Balancer
    Show answer

    B. Global External HTTP(S) Load Balancer

    To improve user experience globally by reducing latency and ensuring high availability, the company needs a global load balancing solution that can route traffic to the closest healthy backend. The Global External HTTP(S) Load Balancer is designed precisely for this purpose, offering global distribution and content-based routing.

  23. 23. A large enterprise needs to ensure that all network traffic between their Google Cloud VPC networks and their on-premises data centers is inspected by a centralized set of firewalls for security and compliance. They want to avoid routing all traffic through a single, potentially bottlenecked location and instead distribute the inspection load across multiple firewall instances. Which Google Cloud networking pattern should they implement?

    Design and plan a cloud solution architecture

    • A. Direct Interconnect with route-based VPN
    • B. Hybrid Network Firewall Inspection with Gateway Load Balancer and third-party firewalls
    • C. VPC Network Peering with custom route advertisements
    • D. Shared VPC with centralized firewall VMs and Cloud VPN
    Show answer

    B. Hybrid Network Firewall Inspection with Gateway Load Balancer and third-party firewalls

    Hybrid Network Firewall Inspection, leveraging Gateway Load Balancer with third-party virtual firewalls, is designed for this exact scenario. It allows traffic to be transparently redirected to a pool of firewall VMs for inspection, distributing the load and preventing bottlenecks, while maintaining a centralized inspection point for hybrid connectivity.

  24. 24. A media streaming company needs to store petabytes of video content that is frequently accessed for the first 30 days after upload, then rarely accessed for archival purposes, but must be retrieved within minutes if requested. The company wants to optimize storage costs while meeting these access patterns. Which Google Cloud Storage class or combination of classes should they use?

    Design and plan a cloud solution architecture

    • A. Nearline storage for the first 30 days, then migrate to Archive storage.
    • B. Coldline storage for all data.
    • C. Standard storage for all data.
    • D. Standard storage for the first 30 days, then migrate to Coldline storage.
    Show answer

    D. Standard storage for the first 30 days, then migrate to Coldline storage.

    Standard storage is ideal for frequently accessed data (first 30 days). Coldline storage is cost-effective for data accessed less than once a month but with retrieval in minutes, fitting the archival needs after the initial high-access period. Archive storage has higher retrieval latency.

  25. 25. A company is migrating its monolithic application to Google Cloud and wants to refactor it into microservices using containers. They need a managed solution that provides high scalability, automatic healing, and simplifies cluster operations. Which Google Cloud service should they choose for deploying their microservices?

    Design and plan a cloud solution architecture

    • A. Cloud Run.
    • B. Google Kubernetes Engine (GKE).
    • C. Compute Engine with Docker installed on individual VMs.
    • D. App Engine Flexible Environment.
    Show answer

    B. Google Kubernetes Engine (GKE).

    Google Kubernetes Engine (GKE) is a fully managed service for deploying, managing, and scaling containerized applications. It provides high scalability, automatic healing, and simplifies cluster operations, making it ideal for microservices architectures.

Professional Cloud Architect flashcards

Tap a card to flip it. 137 flashcards in the full deck.

  • Filestore Enterprise

    Flip card

    A fully managed, highly available, and scalable Network File System (NFS) service on Google Cloud, designed for enterprise workloads.

    • Shared file storage (NFS)
    • Extremely low latency and high IOPS
    • Regional availability with zone-level replication
    Study this card →
  • Cloud Run

    Flip card

    A fully managed, serverless platform for deploying and scaling containerized applications. It automatically scales from zero to handle traffic and charges only for the resources consumed during active requests.

    • Serverless container execution
    • Scales automatically from zero
    • Pay-per-use billing (cost-efficient)
    Study this card →
  • BigQuery

    Flip card

    A fully managed, serverless, and highly scalable enterprise data warehouse that enables super-fast SQL queries using the processing power of Google's infrastructure.

    • Petabyte-scale analytics
    • Serverless and fully managed
    • Columnar storage for optimal query performance
    Study this card →
  • Cloud Spanner

    Flip card

    A globally distributed, strongly consistent, and horizontally scalable relational database service designed for transactional workloads at petabyte scale and high availability.

    • Globally distributed with strong consistency
    • Horizontally scalable (automatic sharding)
    • Relational model with SQL support
    Study this card →
  • Private Google Access

    Flip card

    A feature that allows VMs with only internal IP addresses (no external IP) to reach Google APIs and services, such as Cloud Storage and BigQuery, over Google's internal network.

    • Enables private communication to Google services
    • Bypasses the public internet
    • Reduces egress costs and improves performance
    Study this card →
  • Google Cloud VPC Multicast Support

    Flip card

    Google Cloud's Virtual Private Cloud (VPC) networks do not natively support UDP multicast traffic.

    • VPC networks are unicast-only
    • Multicast applications require re-architecture
    • Alternatives include centralized discovery services (DNS, Consul)
    Study this card →
  • VPC Service Controls + Context-Aware Access

    Flip card

    A powerful combination of Google Cloud security controls to create secure perimeters around sensitive data (VPC Service Controls) and enforce granular access based on user context (Context-Aware Access).

    • VPC Service Controls prevent data exfiltration and isolate services.
    • Context-Aware Access (BeyondCorp) provides identity- and context-based authorization.
    • Ideal for highly regulated industries and sensitive data workloads.
    Study this card →
  • Cloud Storage Multi-Regional + Cloud CDN

    Flip card

    A combination of Google Cloud services for highly available, globally accessible, and low-latency delivery of static content.

    • Cloud Storage Multi-Regional provides geo-redundancy and high availability.
    • Cloud CDN caches content at Google's edge locations worldwide.
    • Ideal for static assets, media, and web content with global users.
    Study this card →
  • Cloud Storage Archive

    Flip card

    A Google Cloud Storage class optimized for long-term data archiving with very infrequent access (less than once a year) at the lowest storage cost.

    • Lowest storage costs among all classes
    • Designed for data accessed less than once a year
    • Higher data retrieval costs and latency compared to other classes
    Study this card →
  • Persistent Disk Extreme (SSD)

    Flip card

    A Google Cloud block storage option offering the highest IOPS and throughput performance, lowest latency, and guaranteed performance for mission-critical applications and databases.

    • Highest performance tier of Persistent Disk.
    • Guaranteed IOPS and throughput, provisioned independently of disk size.
    • Ideal for transactional databases, data warehouses, and high-performance computing (HPC).
    Study this card →
  • Google Kubernetes Engine (GKE)

    Flip card

    A managed service for deploying, managing, and scaling containerized applications using Kubernetes, offering automated operations and advanced orchestration features.

    • Managed Kubernetes clusters
    • Automated deployment, scaling, healing
    • Service discovery and load balancing
    Study this card →
  • Streaming Data Pipeline

    Flip card

    A series of interconnected services designed to ingest, process, and analyze data in real-time as it is generated, typically involving messaging, processing, and storage components.

    • Ingestion: Pub/Sub for high-throughput messaging.
    • Processing: Dataflow for unified streaming/batch transformations.
    • Storage: BigQuery for scalable analytical data warehousing.
    Study this card →
  • GKE Autopilot

    Flip card

    A fully managed mode of Google Kubernetes Engine (GKE) where Google manages the cluster's underlying infrastructure, including nodes, scaling, and upgrades.

    • Minimizes operational overhead for Kubernetes clusters.
    • Automatically provisions and scales nodes based on workload.
    • Supports various workloads, including those requiring GPUs.
    Study this card →
  • Compute Engine with Customization

    Flip card

    Google Cloud's Infrastructure-as-a-Service (IaaS) offering, allowing users to create and run virtual machines with extensive customization options for machine types, GPUs, storage, and operating systems.

    • Provides the highest level of control over underlying infrastructure.
    • Supports various GPU types and custom kernel modules for specialized workloads.
    • Offers committed use discounts for significant cost savings on stable workloads.
    Study this card →
  • GKE Standard Node Pools

    Flip card

    In GKE Standard mode, node pools allow users to define groups of nodes with specific machine types, disk sizes, and other configurations, providing granular control over the underlying compute resources.

    • User-managed nodes in GKE Standard
    • Customizable machine types, GPUs, disks
    • Essential for precise resource allocation
    Study this card →
  • Memorystore for Redis Cluster

    Flip card

    A fully managed Google Cloud service providing a highly available, scalable, and low-latency in-memory data store compatible with Redis Cluster, ideal for caching, session management, and real-time analytics.

    • Sub-millisecond latency for reads and writes.
    • Horizontal scaling with Redis Cluster protocol compatibility.
    • High availability with automatic failover.
    Study this card →
  • VPC Service Controls

    Flip card

    A Google Cloud feature that creates security perimeters around sensitive data to mitigate data exfiltration risks.

    • Creates security perimeters for Google Cloud services
    • Restricts data movement between perimeters and outside
    • Prevents unauthorized access from outside the perimeter
    Study this card →
  • Customer-Managed Encryption Keys (CMEK)

    Flip card

    An encryption option in Google Cloud where customers provide and manage their own encryption keys, which are then used by Google Cloud services to encrypt data at rest.

    • Provides greater control over encryption keys and key rotation.
    • Keys are managed in Cloud Key Management Service (KMS).
    • Used by many Google Cloud services for data at rest encryption.
    Study this card →
  • RTO & RPO

    Flip card

    Recovery Time Objective (RTO) is the maximum acceptable downtime after a disaster. Recovery Point Objective (RPO) is the maximum acceptable data loss after a disaster. These define DR strategy requirements.

    • RTO: How quickly you must recover.
    • RPO: How much data you can afford to lose.
    • Lower RTO/RPO typically means higher cost and complexity.
    Study this card →
  • Cloud SQL

    Flip card

    A fully managed relational database service for MySQL, PostgreSQL, and SQL Server, offering high availability, automatic backups, replication, and simplified patching.

    • Fully managed relational database
    • Supports MySQL, PostgreSQL, SQL Server
    • High availability and automatic backups
    Study this card →
  • Global External HTTP(S) Load Balancer

    Flip card

    A global, proxy-based Layer 7 load balancer for HTTP(S) traffic that distributes requests to backends in different regions, routing users to the closest healthy instance.

    • Global reach, single IP address
    • Layer 7 (HTTP/S) traffic
    • Routes to closest healthy backend
    Study this card →
  • Hybrid Network Firewall Inspection

    Flip card

    An architectural pattern on Google Cloud that uses Gateway Load Balancer to transparently redirect and distribute hybrid network traffic (on-prem to cloud) to a pool of virtual firewall appliances for centralized security inspection.

    • Uses Gateway Load Balancer for transparent redirection
    • Distributes inspection load across multiple firewall VMs
    • Centralized inspection for hybrid connectivity
    Study this card →
  • Cloud Storage Classes

    Flip card

    Google Cloud Storage offers various storage classes (Standard, Nearline, Coldline, Archive) to optimize cost and performance based on data access frequency and retrieval time requirements.

    • Standard: Frequent access, lowest retrieval cost.
    • Nearline: Approx. once a month access, 30-day minimum, seconds-level retrieval.
    • Coldline: Less than once a month access, 90-day minimum, minutes-level retrieval.
    Study this card →
  • Dedicated Interconnect

    Flip card

    A physical, direct connection between your on-premises data center and Google's network, offering private, high-bandwidth, and low-latency connectivity, bypassing the public internet.

    • Physical direct connection
    • Highest bandwidth and lowest latency
    • Bypasses public internet for increased security and performance
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.