Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Google Cloud Architect Professional Professional-Cloud-Architect Exam Questions

Page: 1 / 24 Total 346 questions

Want more questions? Get Premium Access.

Question 1

Your agricultural division is experimenting with fully autonomous vehicles.

You want your architecture to promote strong security during vehicle operation.

Which two architecture should you consider?

Choose 2 answers:

Correct Answer: A. Treat every micro service call between modules on the vehicle as untrusted.; C. Use a trusted platform module (TPM) and verify firmware and binaries on boot.

Question 2

For this question, refer to the Mountkirk Games case study.

Mountkirk Games wants to set up a real-time analytics platform for their new game. The new platform must meet their technical requirements. Which combination of Google technologies will meet all of their requirements?

Correct Answer: B. Cloud Dataflow, Cloud Storage, Cloud Pub/Sub, and BigQuery
Explanation:

A real time requires Stream / Messaging so Pub/Sub, Analytics by Big Query.

Ingest millions of streaming events per second from anywhere in the world with Cloud Pub/Sub, powered by Google's unique, high-speed private network. Process the streams with Cloud Dataflow to ensure reliable, exactly-once, low-latency data transformation. Stream the transformed data into BigQuery, the cloud-native data warehousing service, for immediate analysis via SQL or popular visualization tools.

From scenario: They plan to deploy the game's backend on Google Compute Engine so they can capture streaming metrics, run intensive analytics.

Requirements for Game Analytics Platform

Dynamically scale up or down based on game activity

Process incoming data on the fly directly from the game servers

Process data that arrives late because of slow mobile networks

Allow SQL queries to access at least 10 TB of historical data

Process files that are regularly uploaded by users' mobile devices

Use only fully managed services


Question 3

You are analyzing and defining business processes to support your startup's trial usage of GCP, and you don't yet know what consumer demand for your product will be. Your manager requires you to minimize GCP

service costs and adhere to Google best practices. What should you do?

Correct Answer: D. Utilize free tier and committed use discounts. Provide training to the team about service cost management.
Explanation:

https://cloud.google.com/docs/enterprise/best-practices-for-enterprise-organizations#billing_and_management


Question 4

For this question, refer to the TerramEarth case study.

You start to build a new application that uses a few Cloud Functions for the backend. One use case requires a Cloud Function func_display to invoke another Cloud Function func_query. You want func_query only to accept invocations from func_display. You also want to follow Google's recommended best practices. What should you do?

Correct Answer: B. Make func_query 'Require authentication.' Create a unique service account and associate it to func_display. Grant the service account invoker role for func_query. Create an id token in func_display and include the token to the request when invoking func_query.
Explanation:

https://cloud.google.com/functions/docs/securing/authenticating#authenticating_function_to_function_calls


Question 5

You need to upload files from your on-premises environment to Cloud Storage. You want the files to be

encrypted on Cloud Storage using customer-supplied encryption keys. What should you do?

Correct Answer: A. Supply the encryption key in a .boto configuration file. Use gsutil to upload the files.
Explanation:

https://cloud.google.com/storage/docs/encryption/customer-supplied-keys#gsutil


Question 6

For this question, refer to the Helicopter Racing League (HRL) case study. Recently HRL started a new regional

racing league in Cape Town, South Africa. In an effort to give customers in Cape Town a better user

experience, HRL has partnered with the Content Delivery Network provider, Fastly. HRL needs to allow traffic

coming from all of the Fastly IP address ranges into their Virtual Private Cloud network (VPC network). You are

a member of the HRL security team and you need to configure the update that will allow only the Fastly IP

address ranges through the External HTTP(S) load balancer. Which command should you use?

Correct Answer: C. Apply a VPC firewall rule on port 443 for Fastly IP address ranges.
Explanation:

D18912E1457D5D1DDCBD40AB3BF70D5D

Question 7

As part of implementing their disaster recovery plan, your company is trying to replicate their production

MySQL database from their private data center to their GCP project using a Google Cloud VPN connection.

They are experiencing latency issues and a small amount of packet loss that is disrupting the replication. What should they do?

Correct Answer: B. Configure a Google Cloud Dedicated Interconnect.

Question 8

Your organization is going to migrate applications to Kubernetes and use managed cloud services to deploy applications. Your team is new to Kubernetes and wants to quickly onboard engineers. You want to reduce operational overhead, so the engineering team can focus on developing consumer requirements instead of maintaining the infrastructure. What should you do?

Correct Answer: D. Assess application and dependencies for containerization. Develop a migration strategy for deployment to GKE in Autopilot mode.
Explanation:

According to GKE documentation, GKE Autopilot is the recommended mode for teams that want a 'hands-off' Kubernetes experience with the lowest possible operational overhead. In Autopilot mode, Google Cloud manages the entire underlying infrastructure, including the control plane, node provisioning, security hardening, and scaling.

For a team that is 'new to Kubernetes,' GKE Standard (Option C) would require them to manually manage node pools, choose machine types, and handle OS upgrades---tasks that distract from 'developing consumer requirements.' Options A and B involve managing Kubernetes manually on Compute Engine, which represents the highest possible operational burden.

GKE Autopilot automatically applies best practices for security and resource management. It implements a per-pod billing model, meaning you only pay for the resources (CPU, memory, storage) requested by your pods, rather than paying for unused node capacity. This aligns with the business goal of maximizing developer focus on features while Google handles the complexities of cluster management, ensuring a faster onboarding process for the engineering team.


Question 9

For this question, refer to the Cymbal Retail case study. Cymbal wants you to connect their on-premises systems to Google Cloud while maintaining secure communication between their on-premises and cloud environments You want to follow Google's recommended approach to ensure the most secure and manageable solution. What should you do?

Correct Answer: C. Configure a Cloud VPN gateway and establish a VPN tunnel Configure firewall rules to restrict access to specific resources and services based on IP addresses and ports.
Explanation:

According to Google Cloud Hybrid Connectivity documentation, Cloud VPN is the standard and recommended solution for establishing a secure, encrypted connection over the public internet between an on-premises network and a Google Cloud VPC. This aligns with Cymbal's requirement for 'secure communication' while maintaining manageability. Unlike SSH tunnels (Option B), which are fragile and difficult to scale at an enterprise level, Cloud VPN utilizes IPsec protocols to create a stable and encrypted site-to-site tunnel.

+1

To satisfy the 'secure and manageable' criteria, the implementation must include strictly defined VPC Firewall Rules. This ensures the principle of least privilege is applied, restricting on-premises systems to only the necessary cloud resources and ports required for their specific business functions. VPC Peering (Option D) is technically incorrect here as it is designed for connecting two VPCs within the cloud, not for on-premises to cloud connectivity. A Bastion Host (Option A) provides a secure gateway for administrative login (SSH/RDP) but does not provide the transparent, network-level connectivity required for the automated 'legacy file-based integrations' and 'data transfers' mentioned in Cymbal's environment. By using Cloud VPN with granular firewalling, Cymbal achieves a secure extension of their data center into Google Cloud.


Question 10

You are developing your microservices application on Google Kubernetes Engine. During testing, you want to validate the behavior of your application in case a specific microservice should suddenly crash. What should you do?

Correct Answer: B. Use Istio's fault injection on the particular microservice whose faulty behavior you want to simulate.
Explanation:

Microservice runs on all nodes. The Micro service runs on Pod, Pod runs on Nodes. Nodes is nothing but Virtual machines. Once deployed the application microservices will get deployed across all Nodes. Destroying one node may not mimic the behaviour of microservice crashing as it may be running in other nodes.

link: https://istio.io/latest/docs/tasks/traffic-management/fault-injection/


Question 11

For this question, refer to the Mountkirk Games case study. Mountkirk Games wants to migrate from their current analytics and statistics reporting model to one that meets their technical requirements on Google Cloud Platform.

Which two steps should be part of their migration plan? (Choose two.)

Correct Answer: A. Evaluate the impact of migrating their current batch ETL code to Cloud Dataflow.; B. Write a schema migration plan to denormalize data for better performance in BigQuery.
Explanation:

https://cloud.google.com/bigquery/docs/loading-data#loading_denormalized_nested_and_repeated_data


Question 12

Your company uses the Firewall Insights feature in the Google Network Intelligence Center. You have several firewall rules applied to Compute Engine instances. You need to evaluate the efficiency of the applied firewall ruleset. When you bring up the Firewall Insights page in the Google Cloud Console, you notice that there are no log rows to display. What should you do to troubleshoot the issue?

Correct Answer: B. Enable Firewall Rules Logging for the firewall rules you want to monitor.

Question 13

Your team plans to use Vertex AI to develop and deploy machine learning models for various use cases for fraud detection, product recommendations, and customer churn prediction. You want to enhance the security posture of the Vertex AI and Workbench environment by restricting data exfiltration. What should you do?

Correct Answer: C. Create a service perimeter and include aiplatform.googleapis.com and notebooks.googleapis.com as protected services.
Explanation:

According to the Google Cloud Security Foundations Guide and VPC Service Controls (VPC-SC) documentation, the most effective way to prevent data exfiltration is to establish a service perimeter. This perimeter creates a virtual boundary that prevents sensitive data from being moved to unauthorized projects or outside the Google Cloud network.

For the Vertex AI environment specifically, the two critical services that must be protected are aiplatform.googleapis.com (the core Vertex AI API) and notebooks.googleapis.com (which governs Vertex AI Workbench instances). Including these in a service perimeter ensures that data within the Cymbal Retail project cannot be copied to external Cloud Storage buckets or other unauthorized APIs, even if a user has valid IAM permissions.

Option A is incorrect because ml.googleapis.com is the legacy AI Platform API, and document.googleapis.com (Document AI) does not cover the broader Vertex AI or Workbench environment. Option B (VPC Flow Logs) provides visibility but is a detective control, not a preventative one against exfiltration. Option D (Private Google Access) allows internal IPs to reach Google APIs but does not restrict where that data can go once the connection is made. Therefore, Option C provides the robust, enterprise-grade security required for sensitive data like fraud detection and customer churn models.


Question 14

You are running a cluster on Kubernetes Engine to serve a web application. Users are reporting that a specific part of the application is not responding anymore. You notice that all pods of your deployment keep restarting after 2 seconds. The application writes logs to standard output. You want to inspect the logs to find the cause of the issue. Which approach can you take?

Correct Answer: B. Review the Stackdriver logs for the specific Kubernetes Engine container that is serving the unresponsive part of the application.

Question 15

Your company uses Google Kubernetes Engine (GKE) as a platform for all workloads. Your company has a single large GKE cluster that contains batch, stateful, and stateless workloads. The GKE cluster is configured with a single node pool with 200 nodes. Your company needs to reduce the cost of this cluster but does not want to compromise availability. What should you do?

Correct Answer: C. Configure CPU and memory limits on the namespaces in the cluster. Configure all Pods to have a CPU and memory limits.
Explanation:

One way to reduce the cost of a Google Kubernetes Engine (GKE) cluster without compromising availability is to use horizontal pod autoscalers (HPA) and node auto scaling. HPA allows you to automatically scale the number of Pods in a deployment based on the resource usage of the Pods. By configuring HPA for stateless workloads and for compatible stateful workloads, you can ensure that the number of Pods is automatically adjusted based on the actual resource usage, which can help to reduce costs. Node auto scaling allows you to automatically add or remove nodes from the node pool based on the resource usage of the cluster. By configuring node auto scaling, you can ensure that the cluster has the minimum number of nodes needed to meet the resource requirements of the workloads, which can also help to reduce costs.