Google Cloud Professional Cloud Architect Practice Exam
Practice questions for the Google Cloud Professional Cloud Architect certification, following exam guide v6.1: designing solutions for business and technical requirements, the Well-Architected Framework, business continuity, disaster recovery and RPO/RTO trade-offs, workload disposition, KPIs and Gemini Cloud Assist; migration planning with Migration Center, Migrate to Virtual Machines, Google Cloud VMware Engine, Database Migration Service, BigQuery Migration Service and Transfer Appliance; compute, storage and database choices including Spanner, AlloyDB, Cloud SQL, Bigtable, Filestore and Cloud Storage replication; hybrid and multicloud networking with Cloud Interconnect, Cross-Cloud Interconnect, Network Connectivity Center, Private Service Connect, Cloud NGFW and Cloud Armor; generative AI and ML solutions on Gemini Enterprise Agent Platform (formerly Vertex AI), including Gemini models, Model Garden, grounding with Agent Search, Pipelines, Provisioned Throughput, Dynamic Workload Scheduler, AI Hypercomputer, Document AI and Gemini Enterprise; security and compliance with IAM, Privileged Access Manager, Cloud KMS, Cloud HSM, Cloud EKM, VPC Service Controls, Identity-Aware Proxy, Chrome Enterprise Premium, Binary Authorization, Model Armor, Sensitive Data Protection, Assured Workloads, HIPAA, PCI DSS and children's privacy; technical and business processes such as CI/CD with Cloud Deploy, postmortems, change and stakeholder management, cost optimization with committed use discounts and BigQuery editions, and chaos engineering; implementation with Apigee, emulators, gcloud and Terraform; and operations excellence with SLO burn-rate alerting, Cloud Profiler, Managed Service for Prometheus, Personalized Service Health and GKE maintenance controls. About 20 questions are self-contained case-study scenarios about four fictional companies. Every question includes a written explanation.
100 questions · 12 free preview
Studying more than one? All Google Cloud exams for $29 · every exam for $79
Free sample questions
- Sample · question 1 · Config Sync GitOps across a cluster fleet
Thornbury Retail operates 25 GKE clusters across four regions. Platform engineers want namespaces, RBAC bindings and network policies to be identical on every cluster, defined in a Git repository, and automatically corrected if someone changes them by hand. What should the architect recommend?
- A.Manifests stored in a Cloud Storage bucket that each team copies from
- B.A nightly script that applies the manifests to each cluster with kubectl and emails a report of any failures
- C.Config Sync, syncing configuration from the Git repository to every fleet clustercorrect
- D.A written checklist of required settings for each cluster owner
Why: Config Sync continuously reconciles clusters against a Git source of truth, applying changes everywhere and reverting manual drift. A nightly kubectl script leaves drift in place for up to a day and needs maintenance. Shared buckets and checklists depend on people applying them consistently.
Open this question on its own page → - Sample · question 2 · Chirp speech model for call transcription
Dunwell Utilities records 40,000 customer service calls a month and wants accurate text transcripts in several languages for quality review and search. The deciding constraint is a managed Google model rather than training its own. Which service should the architect recommend?
- A.Text-to-Speech with a Chirp HD voice
- B.Speech-to-Text with a Chirp model, using batch recognitioncorrect
- C.Cloud Translation API applied directly to the audio files
- D.A custom acoustic model trained from scratch on Compute Engine GPUs with the call recordings
Why: Speech-to-Text converts audio to text, and its Chirp models are Google's large multilingual speech models; batch recognition suits recorded calls. Translation works on text, not audio. Text-to-Speech generates audio from text rather than transcribing it, and training an acoustic model from scratch contradicts the constraint.
Open this question on its own page → - Sample · question 3 · AlloyDB read pools for read scaling
Pevensey Insurance runs AlloyDB for PostgreSQL for its policy platform. Reporting queries during business hours slow down transactional writes on the primary instance. The deciding constraint is to scale reads with minimal application change and no separate replication to manage. What should the architect recommend?
- A.An AlloyDB read pool instance, with reporting connections sent to its endpointcorrect
- B.More vCPUs for the primary instance, added until reporting no longer affects transactional writes
- C.A second AlloyDB cluster kept in sync by a custom replication script
- D.Hourly CSV exports of the tables, queried from Cloud Storage
Why: AlloyDB read pools provide one or more read-only nodes behind a single endpoint that share the cluster's storage, offloading reads from the primary with no replication to operate. Scaling the primary up raises cost and still mixes workloads. Hourly CSV exports and custom replication add staleness and maintenance.
Open this question on its own page → - Sample · question 4 · VM Manager OS patch management
Ashworth Bank runs 1,500 Compute Engine VMs across 40 projects running mixed Linux and Windows. Auditors require monthly OS patching with reports showing compliance for every VM. The deciding constraint is a Google-managed service rather than custom scripts. What should the architect recommend?
- A.Monthly recreation of every VM from a new custom image
- B.Startup scripts that install updates every time a VM reboots
- C.Cloud Scheduler jobs that SSH into each VM, run the update commands and write results to a spreadsheet
- D.VM Manager OS patch management with scheduled patch deployments and compliance reportscorrect
Why: VM Manager OS patch management schedules patch jobs across VM fleets for Linux and Windows and reports patch compliance, meeting both the automation and audit needs. Startup scripts patch only on reboot and give no compliance view. Monthly image rebuilds are disruptive for stateful VMs, and scheduled SSH scripts are custom tooling.
Open this question on its own page → - Sample · question 5 · BigQuery long-term storage pricing
Melrose Analytics keeps five years of event data in BigQuery. Most partitions are older than a year and are never modified, though they are queried occasionally. The finance team asks how to reduce storage costs without changing query patterns. What should the architect explain?
- A.Older partitions must be exported to Cloud Storage Archive class before any storage discount applies to them, then queried as external tables
- B.Old partitions must be copied into a new dataset marked as archival
- C.A long-term storage reservation must be purchased each year to receive the lower rate
- D.Partitions unmodified for 90 consecutive days are billed at the lower long-term rate automatically, with no query impactcorrect
Why: BigQuery automatically applies long-term storage pricing to tables or partitions that have not been modified for 90 consecutive days, and query performance and cost are unchanged. Exporting to Cloud Storage makes the data harder to query. There is no reservation or archival dataset flag to buy or set for this discount.
Open this question on its own page → - Sample · question 6 · Feature Store against training-serving skew
A fraud model at Wyndham Card performs well offline but poorly in production because online feature values are computed differently from the training pipeline. The team wants a single managed source of features for both training and low-latency online serving. What should the architect recommend?
- A.Feature Store on Gemini Enterprise Agent Platform (formerly Vertex AI Feature Store), with features defined over BigQuery and served online from the same definitionscorrect
- B.A Memorystore cache populated by the serving application only
- C.Separate feature logic in the training notebook and in the serving application, reviewed together each quarter
- D.A larger model that is less sensitive to feature differences
Why: Feature Store manages feature definitions over BigQuery data and serves the same features online at low latency, so training and serving use consistent values. Separate implementations are the cause of the skew. A serving-only cache does not align with training data, and a bigger model does not fix inconsistent inputs.
Open this question on its own page → - Sample · question 7 · Autoclass for unpredictable object access
Kirkby Studios stores 900 TB of production assets in Cloud Storage. Some objects are read heavily for weeks and then never again, while others are reopened unpredictably years later. The deciding constraint is lower storage cost without writing or maintaining lifecycle rules. What should the architect recommend?
- A.Set every object to Archive storage class at upload
- B.Lifecycle rules that move every object to Coldline after 30 days and to Archive after one year
- C.Autoclass on the bucket, moving objects between classes based on accesscorrect
- D.Use a multi-region bucket in Standard storage class for everything
Why: Autoclass automatically transitions each object to colder classes when it is not accessed and back to Standard when it is read, which suits unpredictable access without lifecycle rules to maintain. Uploading everything as Archive penalizes the heavily read assets with retrieval costs. Lifecycle rules contradict the constraint, and keeping all data in Standard does not reduce cost.
Open this question on its own page → - Sample · question 8 · Workflows orchestrating serverless steps
Larchmont Insurance's claim intake calls four services in order: a Cloud Run validation service, a Document AI processor, a fraud-scoring API and a notification service, with retries and a conditional branch for high-risk claims. The process must run every 15 minutes. Which TWO services should the architect combine? (Select TWO.)
- A.Managed Service for Apache Airflow (formerly Cloud Composer) with an environment for one small process
- B.Workflows to define the ordered steps, retries and conditional branchcorrect
- C.Dataflow streaming pipelines for each step of the claim process
- D.Cloud Tasks queues chained manually between each pair of services
- E.Cloud Scheduler to start the workflow every 15 minutescorrect
Why: Workflows orchestrates service and API calls with built-in retries, conditions and error handling, and Cloud Scheduler can trigger a workflow on a fixed schedule. Chaining Cloud Tasks queues spreads the logic across services and makes the flow hard to follow. Dataflow is for data processing pipelines, and a managed Airflow environment is heavyweight for a single small process.
Open this question on its own page → - Sample · question 9 · Managed Service for Apache Airflow for complex DAGs
Ravensworth Media already maintains 220 Apache Airflow DAGs on a self-managed server that schedules BigQuery, Spark and external API tasks with complex dependencies. The deciding constraint is to keep the DAG code and stop operating Airflow. What should the architect recommend?
- A.Cloud Scheduler cron jobs replacing the DAGs
- B.Managed Service for Apache Airflow (formerly Cloud Composer)correct
- C.A rewrite of each DAG as a Workflows definition triggered by Cloud Scheduler
- D.A larger Compute Engine VM for the Airflow server
Why: Managed Service for Apache Airflow runs Apache Airflow for you, so existing DAGs move with little change and the team no longer operates the scheduler and workers. Rewriting 220 DAGs in Workflows discards existing code. Cron jobs cannot express complex dependencies, and a larger VM keeps the operational burden.
Open this question on its own page → - Sample · question 10 · Cloud DNS failover routing policy
Ellingham Travel runs its booking site in a primary region with a warm standby in a second region, each behind a regional external Application Load Balancer. The deciding constraint is that DNS should send users to the standby automatically when the primary's health checks fail. Which DNS configuration should the architect use?
- A.A private DNS zone visible only inside the VPC network
- B.Two A records with a very short TTL edited by on-call engineers during outages
- C.A Cloud DNS failover routing policy with health checks on the primary targetcorrect
- D.A weighted round robin routing policy that sends 50% of users to each region at all times
Why: Cloud DNS failover routing policies answer with a primary target while health checks pass and switch to the backup target automatically when they fail. Weighted round robin sends half the traffic to the standby all the time. Manual record edits are slow and error-prone, and a private zone is not visible to internet users.
Open this question on its own page → - Sample · question 11 · Datastream change data capture into BigQuery
Fothergill Foods wants near-real-time analytics in BigQuery on orders stored in a Cloud SQL for MySQL database. The deciding constraints are minimal load on the source database and no custom replication code. What should the architect recommend?
- A.A nightly mysqldump loaded into BigQuery with bq load
- B.Hourly scheduled queries that read the whole orders table through a federated connection to Cloud SQL
- C.Application code that writes every order to both MySQL and BigQuery
- D.A Datastream stream that reads the MySQL binary log and writes changes to BigQuerycorrect
Why: Datastream is a serverless change data capture service that reads the MySQL binary log, which places little load on the source, and replicates changes into BigQuery continuously. Full-table federated reads every hour load the source and are not near real time. Nightly dumps are stale, and dual writes are custom code that can drift out of sync.
Open this question on its own page → - Sample · question 12 · Cloud Asset Inventory IAM policy analysis
Before an audit, Harrowgate Bank's security team must find every principal that has roles granting BigQuery data access anywhere in the organization's 600 projects, including grants inherited from folders. What should the architect recommend?
- A.Cloud Asset Inventory IAM policy search and analysis across the organizationcorrect
- B.Open the IAM page of each project in the console and record the grants
- C.Ask each project owner to submit a spreadsheet of who has access
- D.A query of Admin Activity audit logs for setIamPolicy calls made in the last 30 days across all projects
Why: Cloud Asset Inventory can search IAM policies and analyze effective access across an organization, accounting for inheritance from folders and the organization. Checking 600 projects by hand is slow and misses inherited grants. Recent audit logs only show changes in that window, and owner-submitted spreadsheets are unreliable.
Open this question on its own page →
Like the sample?
Other practice exams
- AnthropicClaude Certified Architect — Foundations100 questions · $19
- CompTIACompTIA Security+ (SY0-701)100 questions · $19
- ISC2CISSP100 questions · $19
- DatabricksDatabricks Data Engineer Associate100 questions · $19
- DatabricksDatabricks Data Engineer Professional100 questions · $19
- Google CloudGoogle Cloud Associate Cloud Engineer100 questions · $19
- Google CloudGoogle Cloud Professional Data Engineer100 questions · $19
- HashiCorpTerraform Associate (004)100 questions · $19
- Microsoft Power BI & FabricPower BI Data Analyst (PL-300)100 questions · $19
- Microsoft Power BI & FabricFabric Analytics Engineer (DP-600)100 questions · $19
- SnowflakeSnowPro Core (COF-C03)250 questions · $19
- SnowflakeSnowPro Advanced: Data Engineer100 questions · $19
- SnowflakeSnowPro Advanced: Architect100 questions · $19
- AWSAWS Cloud Practitioner (CLF-C02)100 questions · $19
- AWSAWS Solutions Architect Associate (SAA-C03)100 questions · $19
- AWSAWS AI Practitioner (AIF-C01)100 questions · $19
- Microsoft AzureAzure Fundamentals (AZ-900)100 questions · $19
- Microsoft AzureAzure Administrator (AZ-104)100 questions · $19
- Microsoft AzureAzure AI Fundamentals (AI-901)100 questions · $19
- Microsoft AzureAzure Solutions Architect Expert (AZ-305)100 questions · $19