Professional Cloud Architect Free Practice Questions — Page 2
Question 6
Your company uses a custom-built application running on a Compute Engine virtual machine (VM). This application processes real-time sales data and writes it to a zonal Persistent Disk. A recent internal audit requires that you implement a backup and recovery plan to protect against zonal failures. Your company has a strict policy that all backup data must be retained for at least 90 days and stored in a separate project with limited access. You need to implement a fully automated backup solution that meets these requirements with minimal operational overhead. What should you do?
A. Write a script to create daily backups of the Persistent Disk. Copy the backups to a different zone and apply a label to each snapshot to indicate the deletion date.
B. Use gcloud commands to create snapshots of the Persistent Disk. Store the snapshots in a regional Cloud Storage bucket and configure a lifecycle rule to delete objects older than 90 days.
C. Create a snapshot schedule to automatically create Persistent Disk snapshots and use a script to move and store them in a multi-regional Cloud Storage bucket.
D. Use the Backup and Disaster Recovery (DR) service to create a backup plan. Configure the backup plan to take daily snapshots and store them in a backup vault with a 90-day retention policy.
Show Answer
Correct Answer: D
Explanation: The requirement is for a fully automated backup solution with minimal operational overhead, 90‑day retention, protection from zonal failures, and storage in a separate project with restricted access. The Backup and Disaster Recovery (DR) service is a managed Google Cloud service designed for this purpose. It supports automated backup plans, enforced retention policies, and backup vaults that can reside in a different project with fine‑grained IAM controls. This eliminates custom scripting, ensures compliance with audit requirements, and provides reliable recovery from zonal failures.
Question 6
You are deploying a highly confidential data processing workload on Google Cloud. Your company’s compliance framework mandates that cryptographic keys used for encrypting data at rest must be generated and stored exclusively within a validated Hardware Security Module (HSM). You want to use a fully integrated Google Cloud managed service to handle the lifecycle and usage of these keys. What should you do?
A. Use Customer-Supplied Encryption Keys (CSEK) by providing your on-premises generated key with each API request.
B. Import your on-premises HSM key material into a Cloud KMS key with the SOFTWARE protection level.
C. Create a new key in Cloud Key Management Service (Cloud KMS) with the HSM protection level.
D. Configure Cloud External Key Manager (Cloud EKM) to connect to your on-premises HSM.
Show Answer
Correct Answer: C
Explanation: The requirement is that keys are generated and stored exclusively inside a validated HSM, while using a fully managed and integrated Google Cloud service. Creating a Cloud KMS key with the HSM protection level ensures the key material is generated within Google‑managed, FIPS 140‑2 Level 3 certified HSMs and never leaves them in plaintext. Cloud KMS manages the full lifecycle and integrates natively with Google Cloud services. Other options either rely on customer‑supplied keys, software‑based protection, or externally managed HSMs, which do not meet the stated requirements.
Question 7
You manage a highly distributed, hybrid- and multi-cloud IT environment, and your developers rely heavily on Prometheus for their workflows. You need a cloud-based, highly scalable, low-maintenance enterprise solution that supports Prometheus Query Language (PromQL) queries, quick metric viewing, and efficient issue diagnosis. What should you do?
A. Deploy a Prometheus operator in your existing Kubernetes and Serverless setup across multi-cloud environments.
B. Set up Cloud Monitoring as a single pane of glass across multi-cloud environments.
C. Enable Google Cloud Managed Service for Prometheus to monitor and alert on your workloads at scale.
D. Build a SaaS-based, Prometheus-compatible solution to display metrics for each cloud in a customizable way.
Show Answer
Correct Answer: C
Explanation: The requirement is for a cloud-based, highly scalable, low-maintenance enterprise solution that natively supports PromQL, integrates with existing Prometheus workflows, and works across hybrid and multi-cloud environments. Google Cloud Managed Service for Prometheus is a fully managed, scalable service that supports PromQL, requires minimal operational overhead, and is designed for large-scale, distributed environments. Option A increases operational burden, B does not fully preserve native Prometheus/PromQL workflows, and D is unnecessarily complex and costly to build and maintain.
Question 7
You are monitoring Google Kubernetes Engine (GKE) clusters in a Cloud Monitoring workspace. As a Site Reliability Engineer (SRE), you need to triage incidents quickly. What should you do?
A. 1. Navigate the predefined dashboards in the Cloud Monitoring workspace. 2. Add metrics and create alert policies.
B. 1. Write a shell script that gathers metrics from GKE nodes, and publish these metrics to a Pub/Sub topic. 2. Export the data to BigQuery. and make a Data Studio dashboard.
C. 1. Create a custom dashboard in the Cloud Monitoring workspace for each incident. 2. Add metrics and create alert policies.
D. 1. Navigate the predefined dashboards in the Cloud Monitoring workspace. 2. Create custom metrics and install alerting software on a Compute Engine instance.
Show Answer
Correct Answer: A
Explanation: For fast incident triage in GKE, SRE best practice is to rely on Cloud Monitoring’s predefined (curated) dashboards, which already surface key signals for clusters, nodes, and workloads. These dashboards provide immediate visibility without setup overhead. From there, adding relevant metrics and creating alert policies in the same workspace supports proactive detection and response. The other options introduce unnecessary complexity, custom work, or delay, which is unsuitable for rapid triage.
Question 8
Company Overview -
KnightMotives is a car manufacturer specializing in autonomous, self-driving vehicles, including Battery Electric Vehicles (BEVs), hybrids and traditional internal combustion engine (ICE) vehicles. While KnightMotives has made strides with the in-vehicle experience in their BEV fleet, the hybrid and ICE vehicles have yet to implement these new systems and are viewed poorly by critics and drivers. The lack of modern in-vehicle technology in hybrid and ICE vehicles has resulted in declining sales and customer satisfaction.
KnightMotives wants to modernize the consumer experience across all vehicles within five years Artificial Intelligence offers a unique opportunity to revolutionize the in-vehicle experience, as well as the shopping buying and service/maintenance experience. Investment in this new technology will require a shift in financial priorities on a global scale.
KnightMotives also wants to improve their online ordering system, which is unreliable. Systems for customers to build their vehicle online for acquisition through a dealer are not delivering the data or reliability that dealers need, causing. A strain in the relationship between KnightMotives and dealers. Service technicians and sales staff need better tooling to enhance dealer successes, including built-to-order vehicles.
Solution Concept -
KnightMotives wants to shift from manufacturing cars to creating a complete and compelling “automotive experience.” Then strategy prioritizes delivering a consistent experience across all models, developing AI-powered features, generating new revenue from data monetization, adopting a digital focus to differentiate their brand from competitors, and developing better tools for mechanics and salespeople.
Existing Technical Environment -
KnightMotives's IT is largely on-premises with some applications on major cloud platforms. Their supply chain runs on an outdated mainframe, and Enterprise Resource Planning (ERP) is also outdated, making new promotions and dealer discounts difficult to implement. Dealers have no budget for new equipment. There is fragmentation across vehicles with multiple code bases, and significant technical debt from supporting backwards compatibility. Network connectivity to manufacturing plants and vehicle connectivity in rural areas are challenges.
Business Requirements -
Key business requirements include fostering a personalized relationship with the driver and delivering a cohesive experience across all models. Creating a better build-to-order model will reduce time on the lot and provide transparency for both dealers and customers. Additionally, KnightMotives seeks to monetize corporate data to finance new technology investments, as their current AI infrastructure is obsolete and corporate data remains siloed. Security is a paramount concern due to past data breaches Adherence to European Union (EU) data protection regulations, especially for emerging autonomous platforms, is critical.
KnightMotives plans to make significant investments in fully autonomous driving capabilities, with initial implementation targeting regions with favorable regulatory environments. Prioritizing employee upskilling, attracting top-tier talent, and fostering better communication between business and technical teams are also critical objectives.
Technical Requirements -
• Modernizing the in-vehicle experience includes developing a consistent user experience (UX) that seamlessly integrates AI-powered features across all models, updating in-vehicle hardware and software in legacy models to support new UX features and AI capabilities, and ensuring reliable network connectivity, especially in rural areas, to support real-time AI features and data transmission.
• Network upgrades are necessary to support increased data traffic and improve connectivity between plants and headquarters.
• IT infrastructure modernization requires adopting a hybrid cloud strategy to leverage the benefits of both on-premises and cloud infrastructure, and gradually modernizing or replacing legacy systems to improve efficiency and agility.
• Autonomous vehicle development and testing requires investing in cutting-edge AI and machine learning technologies, building a robust simulation environment, and ensuring compliance with evolving regulations related to autonomous vehicles.
• Data monetization and insights requires implementing a robust data management platform, strict data security and privacy measures, and a scalable AI/ML infrastructure.
• Increased focus on security and risk management involves implementing a comprehensive security framework to protect against cyber threats and data breaches, developing an incident response plan, and providing security awareness training to employees.
• Providing a delightful experience for dealers and customers requires improving the online build-to-order system; developing modern dealer tools to streamline dealer operations, including sales, service, and inventory management; and implementing a comprehensive Customer Relationship Management (CRM) system to track customer interactions personalize experiences, and improve customer satisfaction.
Executive Statement -
KnightMotives is committed to enhancing safety and saving lives by leveraging an extensive body of data — encompassing driving, road conditions, behavioral studies, and crash safety statistics — to create compelling digital experiences for drivers. Our AI consistently outperforms national safety statistics, ensuring the unique and coveted KnightMotives experience is aligned across all our vehicle models.
Michael Knight, KnightMotives CEO
For this question, refer to the KnightMotives Automotive case study. As part of its cloud strategy. KnightMotives wants to move its virtual machines (VMs) into Google Cloud. These VMs contain applications, database instances, and file servers. In the future, KnightMotives intends to modernize their landscape by adopting cloud native technologies on Google Cloud. During modernization, minimal latency and operational overhead between the old and new landscape will be crucial. You need to design the cloud architecture for the VM environment on Google Cloud while ensuring a future modernization track will meet the technical requirements. What should you do?
A. Create a Shared Virtual Private Cloud (VPC). and migrate the VMs to Compute Engine in a new project. During modernization, deploy each modernized workload in a dedicated Google Cloud project with its own VPC. Connect the two VPCs via an on-premises VPN.
B. Create a Shared Virtual Private Cloud (VPC). Migrate the VMs to Compute Engine in a new project. During modernization, deploy each modernized workload in a dedicated Google Cloud project using the Shared VPC.
C. Create a single private cloud on Google Cloud VMware Engine. Migrate the VMs using VMware HCX. During modernization, deploy the modernized workloads in a single Google Cloud project using a single VP
D. Create a single private cloud on Google Cloud VMware Engine. Migrate the VMs using VMware HCX. During modernization, deploy each modernized workload in a dedicated Google Cloud project with its own VPC.
Show Answer
Correct Answer: B
Explanation: A Shared VPC allows KnightMotives to migrate existing VMs to Compute Engine while keeping low-latency, private connectivity between legacy VM-based workloads and newly modernized, cloud‑native services. Using a Shared VPC across multiple projects enables strong isolation and independent lifecycle management for modernized workloads, centralized networking and security controls, and minimal operational overhead compared to VPN-based VPC‑to‑VPC connectivity. This architecture also aligns with a hybrid-cloud and future modernization strategy without locking the company into VMware-based infrastructure.
Question 8
Your organization uses Google Kubernetes Engine (GKE) and Amazon Elastic Kubernetes Service (EKS) to manage a complex Kubernetes environment across multiple cloud providers. You need to deploy a solution that streamlines configuration management, enforces security policies, and ensures consistent application deployment across all of the environments. You want to follow Google-recommended practices. What should you do?
A. Leverage Argo CD for GitOps-based continuous delivery and Open Policy Agent (OPA) for policy enforcement, and develop a controller for multi-cluster configuration management.
B. Deploy Crossplane for managing cloud resources as Kubernetes objects, FluxCD for GitOps-based configuration synchronization, and Kyverno for policy enforcement.
C. Deploy Kustomize for configuration customization, Config Sync with multiple Git repositories, and a script to enforce security policies.
D. Utilize Config Sync as part of GKE to synchronize configurations from a centralized repository, and utilize Policy Controller to enforce policies using OPA Gatekeeper.
Show Answer
Correct Answer: D
Explanation: Google-recommended practices for managing multi-cluster Kubernetes environments across clouds are centered on GKE Enterprise (Anthos). Config Sync provides GitOps-based configuration management from a single source of truth across GKE and non-GKE clusters (including EKS), while Policy Controller (based on OPA Gatekeeper) enforces consistent security and compliance policies declaratively. Together, they directly address streamlined configuration management, policy enforcement, and consistent deployments using Google-supported tooling. Other options either rely on non-Google stacks, require custom scripting/controllers, or do not provide integrated, enterprise-grade multi-cluster governance.
Question 9
Your organization is implementing a new cloud-native application on Google Cloud and needs to ensure compliance with the ISO/IEC 27001 framework. You want to leverage Google Cloud’s security reports and documentation to support your ISO/IEC 27001 audit process. What should you do?
A. Engage an independent auditor to conduct an ISO/IEC 27001 audit of your organization's Google Cloud implementation.
B. Download the ISO/IEC 27001 report for Google Cloud through internet search.
C. Review the Compliance Reports Manager for information about ISO/IEC 27001 compliance and related documentation on obtaining reports through your Google Cloud account.
D. Utilize the Cloud Audit Logs service for accessing and requesting the ISO/IEC 27001 reports.
Show Answer
Correct Answer: C
Explanation: To support an ISO/IEC 27001 audit using Google Cloud–provided evidence, you should use Google Cloud’s Compliance Reports Manager. This is the official service where Google makes third‑party audit reports (including ISO/IEC 27001) available to customers under NDA through their Cloud Console. An internet search is not appropriate, Cloud Audit Logs are unrelated to compliance certifications, and hiring an independent auditor does not leverage Google Cloud’s existing security reports.
Question 9
Your organization is going to migrate applications to Kubernetes and use managed cloud services to deploy applications. Your team is new to Kubernetes and wants to quickly onboard engineers. You want to reduce operational overhead, so the engineering team can focus on developing consumer requirements instead of maintaining the infrastructure. What should you do?
A. Package your application into a Docker image, and deploy it to Kubernetes on Compute Engine.
B. Leverage Cloud Build to create a container image, and deploy it automatically to Kubernetes on Compute Engine.
C. Assess application and dependencies for containerization Develop a migration strategy for deployment to GKE in Standard mode.
D. Assess application and dependencies for containerization. Develop a migration strategy for deployment to GKE in Autopilot mode.
Show Answer
Correct Answer: D
Explanation: The goal is fast onboarding for a Kubernetes‑new team while minimizing operational overhead. GKE Autopilot offloads cluster and node management, applies best‑practice security defaults, and uses a pay‑per‑pod model, letting engineers focus on application development instead of infrastructure. Standard GKE or Compute Engine–based options require significantly more operational management.
Question 10
Company Overview -
KnightMotives is a car manufacturer specializing in autonomous, self-driving vehicles, including Battery Electric Vehicles (BEVs), hybrids and traditional internal combustion engine (ICE) vehicles. While KnightMotives has made strides with the in-vehicle experience in their BEV fleet, the hybrid and ICE vehicles have yet to implement these new systems and are viewed poorly by critics and drivers. The lack of modern in-vehicle technology in hybrid and ICE vehicles has resulted in declining sales and customer satisfaction.
KnightMotives wants to modernize the consumer experience across all vehicles within five years Artificial Intelligence offers a unique opportunity to revolutionize the in-vehicle experience, as well as the shopping buying and service/maintenance experience. Investment in this new technology will require a shift in financial priorities on a global scale.
KnightMotives also wants to improve their online ordering system, which is unreliable. Systems for customers to build their vehicle online for acquisition through a dealer are not delivering the data or reliability that dealers need, causing. A strain in the relationship between KnightMotives and dealers. Service technicians and sales staff need better tooling to enhance dealer successes, including built-to-order vehicles.
Solution Concept -
KnightMotives wants to shift from manufacturing cars to creating a complete and compelling “automotive experience.” Then strategy prioritizes delivering a consistent experience across all models, developing AI-powered features, generating new revenue from data monetization, adopting a digital focus to differentiate their brand from competitors, and developing better tools for mechanics and salespeople.
Existing Technical Environment -
KnightMotives's IT is largely on-premises with some applications on major cloud platforms. Their supply chain runs on an outdated mainframe, and Enterprise Resource Planning (ERP) is also outdated, making new promotions and dealer discounts difficult to implement. Dealers have no budget for new equipment. There is fragmentation across vehicles with multiple code bases, and significant technical debt from supporting backwards compatibility. Network connectivity to manufacturing plants and vehicle connectivity in rural areas are challenges.
Business Requirements -
Key business requirements include fostering a personalized relationship with the driver and delivering a cohesive experience across all models. Creating a better build-to-order model will reduce time on the lot and provide transparency for both dealers and customers. Additionally, KnightMotives seeks to monetize corporate data to finance new technology investments, as their current AI infrastructure is obsolete and corporate data remains siloed. Security is a paramount concern due to past data breaches Adherence to European Union (EU) data protection regulations, especially for emerging autonomous platforms, is critical.
KnightMotives plans to make significant investments in fully autonomous driving capabilities, with initial implementation targeting regions with favorable regulatory environments. Prioritizing employee upskilling, attracting top-tier talent, and fostering better communication between business and technical teams are also critical objectives.
Technical Requirements -
• Modernizing the in-vehicle experience includes developing a consistent user experience (UX) that seamlessly integrates AI-powered features across all models, updating in-vehicle hardware and software in legacy models to support new UX features and AI capabilities, and ensuring reliable network connectivity, especially in rural areas, to support real-time AI features and data transmission.
• Network upgrades are necessary to support increased data traffic and improve connectivity between plants and headquarters.
• IT infrastructure modernization requires adopting a hybrid cloud strategy to leverage the benefits of both on-premises and cloud infrastructure, and gradually modernizing or replacing legacy systems to improve efficiency and agility.
• Autonomous vehicle development and testing requires investing in cutting-edge AI and machine learning technologies, building a robust simulation environment, and ensuring compliance with evolving regulations related to autonomous vehicles.
• Data monetization and insights requires implementing a robust data management platform, strict data security and privacy measures, and a scalable AI/ML infrastructure.
• Increased focus on security and risk management involves implementing a comprehensive security framework to protect against cyber threats and data breaches, developing an incident response plan, and providing security awareness training to employees.
• Providing a delightful experience for dealers and customers requires improving the online build-to-order system; developing modern dealer tools to streamline dealer operations, including sales, service, and inventory management; and implementing a comprehensive Customer Relationship Management (CRM) system to track customer interactions personalize experiences, and improve customer satisfaction.
Executive Statement -
KnightMotives is committed to enhancing safety and saving lives by leveraging an extensive body of data — encompassing driving, road conditions, behavioral studies, and crash safety statistics — to create compelling digital experiences for drivers. Our AI consistently outperforms national safety statistics, ensuring the unique and coveted KnightMotives experience is aligned across all our vehicle models.
Michael Knight, KnightMotives CEO
For this question, refer to the KnightMotives Automotive case study. KnightMotives has developed and deployed a model on Vertex AI that can provide personalized recommendations in the new car configuration application. Customers will receive optional equipment recommendations that best suit their persona. Previous usage data from the car configuration application has been used for model training features. You know from past experience that customer behavior can change over time. For example, in times of economic certainty and rising stock markets, customers tend to purchase more expensive options. You want to detect when customer behavior gradually changes over time so you can adjust the model. What should you do?
A. Configure Model Monitoring, and select training-serving skew detection.
B. Configure Model Monitoring, and select prediction drift detection.
C. Configure Dataplex auto data quality on the prediction request data features using row-level rules.
D. Configure Dataplex auto data quality on the prediction request data features using aggregate rules.
Show Answer
Correct Answer: B
Explanation: The goal is to detect gradual changes in customer behavior over time so the model can be adjusted. This is a classic case of concept drift, where the statistical relationship between inputs and predictions changes. Vertex AI Model Monitoring’s prediction drift detection is designed to identify shifts in the distribution of predictions compared to a baseline, signaling changing user behavior patterns. Training-serving skew focuses on differences between training and serving feature distributions, and Dataplex data quality rules check data correctness rather than behavioral change, so they are not the right fit.
Question 11
A retail company s most critical application is its online payment processing system. The business has a requirement that the system must be able to survive a complete zonal outage while minimizing cost. You need a design solution that can handle a zonal failure. What should you do?
A. Deploy the application in an active-active configuration using managed instance groups (MIGs) in two different regions, fronted by a global external HTTP(S) Load Balancer and backed by a multi-regional database like Spanner.
B. Deploy the application on a regional MIG to provide high availability across multiple zones in the primary region.
C. Configure the regional MIG to use only Spot VMs to aggressively minimize operational costs while maintaining high availability.
D. Deploy the application on Compute Engine instances across multiple regions, and rely on daily snapshots for recovery to achieve the lowest possible cost.
Show Answer
Correct Answer: B
Explanation: The requirement is to survive a complete *zonal* outage, not a regional outage, while minimizing cost. A regional Managed Instance Group automatically distributes instances across multiple zones within a single region, providing zonal fault tolerance at much lower cost and complexity than a multi‑region active‑active design. Option A over‑engineers the solution for a regional failure and increases cost. Options C and D either reduce reliability or fail to meet availability requirements.
$19
Get all 305 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.