All practice questions
1598 questions
A fintech enterprise is designing a hybrid network architecture to connect its on-premises transactional data center to a Google Cloud Virtual Private Cloud (VPC) hosting microservices across two GCP regions. The connection must support a aggregate throughput of 2 Gbps, mandate IPsec encryption for all data in transit over the wire, and automatically handle failover across both regions. The company does not reside in a Google Cloud colocation facility. Which TWO architectural options should the lead cloud architect select to fulfill these requirements?
Select all that apply
An enterprise organization needs to connect its primary on-premises data center to a Google Cloud Virtual Private Cloud (VPC) network. The workload requires a sustained throughput of 15 Gbps with a high availability (HA) SLA of 99.99%. Which hybrid networking architecture should a Cloud Architect recommend to satisfy these requirements?
An enterprise logistics provider is architecting a mission-critical fleet tracking solution on Google Cloud. The application requires global high availability with a target SLA of uptime, zero Recovery Point Objective (), and sub-second failover across continental regions for write-heavy relational transactions. Additionally, the network architecture requires high-throughput hybrid connectivity from on-premises data centers exceeding per link, along with strict perimeter security to prevent data exfiltration. Which TWO architectural decisions should the cloud architect implement to meet these requirements? (Select TWO)
Select all that apply
A global gaming company is preparing for the launch of a new multiplayer game. The matchmaking service is deployed on Compute Engine Managed Instance Groups (MIGs) and communicates heavily over network sockets with minimal CPU overhead per connection. Historical load testing reveals that as concurrent player connections double, instance memory usage and active TCP socket connections saturate long before CPU utilization reaches 30%. What should you do to ensure the workload scales effectively during peak launch traffic while staying within Google Cloud resource limits?
An international media organization is migrating its digital asset management platform to Google Cloud. The architecture requires a single-region relational database (400 GB size) for content metadata that supports standard SQL queries and high availability (HA). Additionally, the organization needs to transfer 800 TB of legacy video archives from an on-premises data center to Cloud Storage Coldline within a 2-week migration window, but their available internet connection bandwidth is capped at 100 Mbps.
To minimize baseline operational costs while satisfying all technical and timeframe requirements, which TWO architectural decisions should you recommend? (Select TWO.)
Select all that apply
An enterprise DevOps team needs to collect high-severity application logs across all projects within a Google Cloud folder and publish them to a centralized Pub/Sub topic for real-time automated incident response. The solution must capture only error-level logs and adhere strictly to Google Cloud security best practices and least-privilege access. Which TWO actions should the team take to implement this logging architecture?
Select all that apply
An enterprise operating a multi-folder Google Cloud resource hierarchy needs to stream all Data Access audit logs and Security Command Center (SCC) Premium findings to a third-party SIEM hosted on Google Kubernetes Engine (GKE). The security architecture must adhere to the principle of least privilege and ensure zero log loss. What is the correct sequence of steps to implement this centralized logging and threat export pipeline?
Drag items to arrange them in the correct order
A media streaming company is preparing for a live global festival expected to draw five times its standard user traffic. The event processing pipeline consumes messages from Cloud Pub/Sub using a Compute Engine Managed Instance Group (MIG). Which TWO capacity planning and auto-scaling configurations should the Cloud Architect implement to ensure operational reliability during peak load? (Select TWO)
Select all that apply
A multinational retail enterprise is configuring connectivity between its main on-premises data center and a multi-region Google Cloud Virtual Private Cloud (VPC). The workload requires 15 Gbps of dedicated bandwidth, high availability backed by a 99.99% Service Level Agreement (SLA), and mandatory end-to-end IPsec encryption over private network paths. Which TWO architectural steps must be implemented together to satisfy all technical and SLA requirements?
Select all that apply
A global autonomous transportation enterprise is designing a hybrid network architecture to connect diverse operational sites to Google Cloud. Match each hybrid connectivity requirement on the left with the most appropriate Google Cloud networking solution on the right.
Click a left item, then click its matching right item
Items
Matches
An online retail enterprise is migrating a stateless REST API service to Google Cloud. The workload experiences unpredictable traffic spikes during flash sale events but remains idle for extended periods overnight. The primary business goals are to minimize infrastructure costs by eliminating payment for idle compute capacity and to reduce operational overhead for an engineering team with no Kubernetes experience. Which architectural solution should a Cloud Architect recommend?
A retail enterprise is designing hybrid connectivity between its primary on-premises data center and Google Cloud. The architecture requires transferring continuous backup data streams at a rate of 12 Gbps. Additionally, multiple project VPC networks need to communicate centrally with on-premises services without relying on non-supported routing behaviors between VPC networks. Which TWO architectural decisions should the cloud architect implement to fulfill these requirements? (Select TWO.)
Select all that apply
A regulatory compliance audit requires a healthcare organization to capture all Google Cloud Data Access audit logs across all projects and securely retain them for seven years. The solution must ensure that log data is encrypted using customer-managed encryption keys (CMEK) and protected against premature deletion or tampering by any privileged user, including organization admins. In which chronological order should a Cloud Security Architect perform the required implementation steps?
Drag items to arrange them in the correct order
A DevOps engineering team is evaluating their CI/CD pipeline in Google Cloud to ensure secure deployments to Google Kubernetes Engine (GKE). Which of the following security practices should the team incorporate into their software development lifecycle and Cloud Build pipeline? (Select TWO.)
Select all that apply
An enterprise gaming studio manages its multi-region multiplayer backend infrastructure using Terraform across multiple Google Cloud projects. The cloud architecture team needs to establish a secure Infrastructure as Code (IaC) governance model. The model must prevent concurrent deployment state corruption, eliminate security risks associated with exporting service account keys, and ensure any manual out-of-band infrastructure changes are rapidly identified. Which TWO actions should the lead architect mandate to achieve these requirements?
Select all that apply
A financial platform hosts its mission-critical transactions API on Compute Engine Managed Instance Groups (MIGs) behind an External HTTP(S) Load Balancer. The engineering team is planning a zero-downtime blue-green deployment for a major application version that includes database schema changes. To ensure high availability and prevent deployment pipeline failures during the environment cutover, which TWO architectural and operational steps must the team implement?
Select all that apply
An enterprise architecture team is implementing a centralized compliance auditing strategy across their Google Cloud Organization. They need to export all admin activity and data access audit logs from multiple production projects into a single BigQuery dataset hosted in a dedicated security monitoring project. To meet strict security governance guidelines, they must grant minimal necessary permissions to the automated export mechanism. Which configuration approach correctly fulfills these compliance and least-privilege requirements?
An e-commerce enterprise is reviewing its Google Cloud architecture to eliminate technical debt accumulated during a rapid cloud migration. The audit identified two core issues: simple stateless HTTP microservices are running on a custom Google Kubernetes Engine (GKE) cluster requiring heavy administrative maintenance, and a single-region relational database is running on Cloud Spanner, causing excessive operational cost. Which TWO architectural refactoring decisions directly mitigate this technical debt? (Select TWO answers)
Select all that apply
An enterprise organization is establishing an automated, highly reliable Infrastructure as Code (IaC) continuous integration and deployment pipeline using Cloud Build and Terraform to provision multi-region production environments on Google Cloud. The architecture must guarantee state safety, strictly enforce security guardrails before resource creation, and prevent deployment rollouts if operational verification fails. In what sequential order should the pipeline execute these environment provisioning steps?
Drag items to arrange them in the correct order
A regulatory compliance framework requires a media streaming enterprise to maintain full control over the lifecycle and rotation schedules of encryption keys protecting sensitive API secrets stored in Secret Manager. The regulatory standard mandates that keys must reside in FIPS 140-2 Level 3 validated hardware security modules (HSMs) managed within Google Cloud, and key management administrative duties must be strictly separated from key usage permissions assigned to services. Which security architecture fulfills these compliance and least-privilege requirements?