All practice questions
1598 questions
An enterprise organization requires centralized control over network firewall rules across all Google Cloud projects. The security team must enforce a global policy that denies all incoming SSH traffic on TCP port 22 to virtual machines across all projects. Project-level network administrators must still be able to manage application-specific firewall rules for their own workloads without the ability to override or bypass the organization's SSH restriction. Which architectural solution should the cloud architect recommend?
A multinational retail enterprise is designing hybrid connectivity between its on-premises data centers in two distinct metropolitan areas and a primary Google Cloud Virtual Private Cloud (VPC). The architecture requires a sustained peak throughput of 15 Gbps and an enterprise availability SLA of 99.99%. Additionally, the network engineering team intends to peer the primary VPC with a vendor's VPC using VPC Network Peering and expects on-premises hosts to route through the primary VPC into the vendor VPC. Which network architecture should a Cloud Architect recommend?
A global medical device company is architecting a patient telemetry platform on Google Cloud. The solution must enforce a strict Recovery Point Objective (RPO) of zero, maintain a 99.999% availability service level agreement (SLA), and guarantee strong global consistency for transactional data across multiple geographic regions. Furthermore, the frontend HTTP ingestion service consists of lightweight, stateless REST API endpoints that must dynamically scale to zero during idle periods without incurring baseline infrastructure management overhead. Which architecture satisfies these high-availability and technical requirements?
A real-time payment reconciliation API deployed on Google Kubernetes Engine (GKE) has a Service Level Objective (SLO) of successful requests measured over a -day rolling window. During a given -day period, the API receives a total of valid requests. What is the maximum number of failed requests allowed during this period before the service exhausts its error budget?
An engineering team is building an industrial IoT telemetry processing microservice that queries Cloud Bigtable. To validate data access patterns, they need an automated integration testing harness that executes on local developer workstations and CI runners without accessing live Google Cloud resources or needing GCP credentials. Which strategy correctly configures the microservice's client SDKs to interact with a locally started Bigtable emulator?
A global healthcare provider is designing a telemetry ingestion platform on Google Cloud for real-time monitoring of medical devices. The solution must achieve an SLA of 99.99% availability, zero Recovery Point Objective (RPO = 0) for incoming event streams, and seamlessly scale to absorb unpredictable traffic spikes without manual intervention. Additionally, strict security governance mandates that internal application services must be protected against data exfiltration to unauthorized external storage locations, even if service account credentials are compromised. Which architecture best satisfies these technical, availability, and security requirements with minimal operational overhead?
A company needs to connect its on-premises data center to a Google Cloud Virtual Private Cloud (VPC) to support a steady daily transfer requirement of 1.5 Gbps. The connectivity solution must support high availability with a 99.99% Service Level Agreement (SLA) while minimizing overall infrastructure costs. Which hybrid connectivity architecture should you recommend?
A media streaming provider is preparing for a live sports event expected to cause a 10x traffic surge on its I/O-bound metadata API service, which is deployed on Compute Engine Managed Instance Groups (MIGs). During previous high-traffic events, the service experienced request timeouts because CPU-based autoscaling reacted too slowly to memory and network connection bottlenecks, and automated scaling requests were blocked by regional compute resource limits. Which TWO actions should you take to optimize capacity planning and ensure seamless workload scaling during the upcoming event?
Select all that apply
An enterprise financial transaction platform running on Google Cloud maintains a warm standby disaster recovery setup in region `us-east4` to handle regional failures of its primary environment in `us-central1`. Following a catastrophic loss of `us-central1`, the cloud architecture team must initiate the regional failover runbook. Arrange the following execution steps in the correct chronological sequence from first to last.
Drag items to arrange them in the correct order
An organization plans to migrate a single-region, on-premises relational PostgreSQL database to Google Cloud. The application requires standard ACID transactional compliance and predictable performance within a single GCP region, with no requirement for global scale or multi-region availability. Which Google Cloud managed database service should the architect choose to minimize operational complexity and cost?
Match each Google Cloud hybrid connectivity mechanism or network topology pattern to its defining architectural characteristic and deployment requirement.
Click a left item, then click its matching right item
Items
Matches
An enterprise operations team is preparing to update a stateless web application running on a Compute Engine Managed Instance Group (MIG) positioned behind an Internal Application Load Balancer. During previous release cycles, updating the instance template caused service disruption because existing instances were terminated before new instances became fully operational. The team needs to configure a rolling update strategy that guarantees maximum available capacity is preserved throughout the release without incurring service downtime. Which configuration strategy should the cloud architect recommend?
A media publishing enterprise is migrating its legacy digital asset archiving platform from an on-premises data center to Google Cloud. The existing architecture consists of a stateless Java HTTP API service that processes metadata requests and an 8 TB on-premises MySQL relational database. The workload must remain operational throughout a 30-day migration window.
The enterprise wants to eliminate infrastructure management overhead, adopt managed cloud services, and ensure zero-downtime database schema updates during migration. Which TWO architecture and migration strategies should you recommend?
Select all that apply
A renewable energy analytics company uses Terraform to manage its Google Cloud infrastructure across multiple projects. During a recent operational incident, an engineer manually modified server instance types and firewall rules directly in the Google Cloud Console. The automated CI/CD pipeline subsequently failed during execution due to state drift between live resources and version-controlled Terraform code. The cloud architecture team must resolve the configuration drift while ensuring long-term IaC governance and compliance. Which strategy should the cloud architect recommend?
A healthcare enterprise runs its electronic health record (EHR) analytics system on Google Cloud. The primary deployment operates in region `us-central1` using Cloud SQL for PostgreSQL and Compute Engine Managed Instance Groups (MIGs). To meet disaster recovery (DR) objectives of Recovery Time Objective (RTO) under 15 minutes and Recovery Point Objective (RPO) under 1 minute while minimizing baseline idle infrastructure costs, you implement a warm standby pattern in region `us-east4`. You configure a cross-region read replica for Cloud SQL and maintain a minimal scaled-down MIG in `us-east4`. During a simulated regional failover drill in `us-east4`, the Cloud SQL read replica is successfully promoted to primary, but scaling out the DR MIG to handle production traffic fails immediately with instance provisioning errors. What is the most likely root cause of this failure during DR execution?
An automotive manufacturer is implementing a vehicle telemetry diagnostics endpoint deployed within a single Google Cloud region (). The service accepts incoming HTTP REST webhooks from connected vehicles to log maintenance metrics into a standard relational database. Telemetry traffic is highly variable, experiencing sudden traffic surges during morning rush hours and long periods of near-zero activity overnight. Which architectural design meets the availability and regional relational storage requirements while minimizing overall cost and operational overhead?
An enterprise media streaming provider is architecting its core backend services on Google Cloud for global live broadcast events. The system must meet the following technical requirements:
- Achieve a multi-region availability SLA for stateless subscriber entitlement validation requests.
- Ensure zero Recovery Point Objective (RPO) and synchronous multi-region consistency for transactional subscriber entitlement writes during a regional outage.
- Prevent authorized internal identity principals from exfiltrating database content to external Google Cloud projects.
- Minimize operational management overhead for the stateless API compute tier.
Which TWO architectural components should you combine to fulfill these requirements? (Select TWO)
Select all that apply
A company is designing a web application hosted in a single Google Cloud region. The solution requires storing structured relational operational data with full ACID transaction support, as well as storing large volume unstructured user-uploaded media files served over HTTP. Which TWO Google Cloud storage solutions should the architect select to meet these requirements cost-effectively? (Select TWO)
Select all that apply
A healthcare provider is extending its primary on-premises data center to Google Cloud to run high-throughput data analytics on patient records. The hybrid connection requires a predictable bandwidth of at least 8 Gbps with low latency. Additionally, a third-party diagnostics partner operating in a separate VPC is connected to the provider's central hub VPC via VPC Network Peering and needs access to the on-premises database servers. Which network architecture should a Cloud Architect design to satisfy these requirements?
An enterprise financial clearinghouse is architecting a core payment processing backend on Google Cloud. The system must achieve a 99.999% availability SLA, support immediate multi-region failover, and maintain a Recovery Point Objective (RPO) of 0 and a Recovery Time Objective (RTO) of less than 5 seconds for strongly consistent relational transaction records during a total regional outage. The application layer consists of stateless HTTP authorization microservices. Which architectural design meets all technical availability, RPO, and RTO requirements while minimizing operational overhead?