Google GCP-PCA Certification Exam Sample Questions

GCP-PCA Braindumps, GCP-PCA Exam Dumps, GCP-PCA Examcollection, GCP-PCA Questions PDF, GCP-PCA Sample Questions, Professional Cloud Architect Dumps, Professional Cloud Architect Official Cert Guide PDF, Professional Cloud Architect VCEWe have prepared Google Professional Cloud Architect (GCP-PCA) certification sample questions to make you aware of actual exam properties. This sample question set provides you with information about the Professional Cloud Architect exam pattern, question formate, a difficulty level of questions and time required to answer each question. To get familiar with Google Cloud Platform - Professional Cloud Architect (GCP-PCA) exam, we suggest you try our Sample Google GCP-PCA Certification Practice Exam in simulated Google certification exam environment.

To test your knowledge and understanding of concepts with real-time scenario based Google GCP-PCA questions, we strongly recommend you to prepare and practice with Premium Google Professional Cloud Architect Certification Practice Exam. The premium Google Professional Cloud Architect certification practice exam helps you identify topics in which you are well prepared and topics in which you may need further training to achieving great score in actual Google Cloud Platform - Professional Cloud Architect (GCP-PCA) exam.

Google GCP-PCA Sample Questions:

01. Auditors have asked for more detail about the applications running in a Google Kubernetes Engine cluster. The team has written a collection agent that reads node-local state and writes custom metrics to the Cloud Monitoring API, and the agent has to be running on every node in the cluster, including nodes the autoscaler adds later.
Which Kubernetes resource should the agent be deployed as?
a) A StatefulSet
b) A ReplicaSet
c) A DaemonSet
d) A CronJob
 
02. A company wants a low-risk first project on Google Cloud. It has roughly 100 TB of log data to move off its own storage, wants to evaluate serverless analytics against those logs, and needs the same data retained as a long-term disaster recovery copy.
Which two steps should the company take?
(Choose two.)
a) Load the logs into Cloud SQL.
b) Load the logs into BigQuery.
c) Import the logs into Cloud Logging.
d) Insert the logs into Bigtable.
e) Upload the log files into Cloud Storage.
 
03. EHR Healthcare has moved a number of applications into containers, and the ad-hoc way images are currently built and passed between teams will not scale. They want a repeatable build and a governed place to keep the resulting images, without adding much operational overhead for developers.
Which two services should you recommend?
(Choose two.)
a) Cloud Build
b) Cloud Storage buckets holding exported image archives
c) Artifact Registry
d) Cloud Run functions
 
04. A public health information website is served from aging hardware in an on-premises data center. Anonymous users worldwide report slow responses, and the site has been receiving denial-of-service traffic that always originates from the same known IP address ranges.
You are moving the site to Google Cloud and must both improve access latency and stop that traffic from entering your VPC network. What should you do?
a) Move the site onto Compute Engine behind a global external Application Load Balancer and block the ranges with VPC firewall rules
b) Move the site onto Compute Engine behind a global external Application Load Balancer and attach a Cloud Armor policy that denies the ranges
c) Move the site into GKE, expose the pods with a Service inside the cluster and apply a network policy
d) Move the site into GKE, expose it with an internal load balancer and put Identity-Aware Proxy in front of it
 
05. An online gaming company is introducing VPC Service Controls. A subset of its projects holds sensitive player data. Developers rely on Cloud Shell for day-to-day work and must keep it, but they are not permitted broad access to the managed services holding that sensitive data.
What should you do?
a) Create a service perimeter around only the projects that hold sensitive data, and leave developer accounts outside it.
b) Place every project in a single service perimeter, and add all developers to an access level for it.
c) Place every project in a single service perimeter, and stop developers from using Cloud Shell.
d) Rely on IAM roles alone to keep developers away from the sensitive managed services, without creating a perimeter.
 
06. A team releases a customer-facing API several times a week. A release must not interrupt requests in flight, and if error rates rise afterwards the team must be able to put every user back on the previous version in a single action rather than waiting for a fleet to roll back instance by instance.
Which release strategy should the architect recommend?
a) A rolling update that replaces instances a few at a time until the whole fleet runs the new version
b) A blue-green release that keeps the previous version running while traffic moves to the new one
c) A recreate strategy that deletes the running instances and starts the new version in their place
d) Deploy each release directly and rely on monitoring alerts to catch problems afterwards
 
07. You are the data compliance officer for a manufacturer of heavy industrial equipment. The company wants to offer personalized product recommendations to its large industrial customers, and the transaction records that would train and drive those recommendations contain personally identifiable information, including credit card details. The recommendation service must not receive that information.
What should you do?
a) Train a Vertex AI AutoML model on the raw records, and give the recommendation service its predictions
b) Keep the records on-premises and generate the recommendations there, so that the personally identifiable information never enters the cloud
c) Build, train and test a recommendation model by hand on the raw records, and publish only anonymous recommendations from it
d) Run the records through Sensitive Data Protection to de-identify the personally identifiable fields before the service reads them
 
08. A healthcare provider is designing a data loss prevention program and will use Sensitive Data Protection (Cloud DLP) to inspect and mask personal data before analysts see it. The design already covers scanning and masking, and the built-in infoTypes have been confirmed to cover the data the client holds.
Which additional step should the architect add to the workflow?
a) Measure the risk that individuals can still be re-identified from the de-identified data
b) Encrypt the masked data at rest once the personal data has been removed from it
c) Load the masked data into BigQuery so that analysts can query it later
d) Write the masked data to a Cloud Storage bucket so that analysts can retrieve it later
 
09. EHR Healthcare's sales employees are a remote workforce who travel between customer locations. Wherever they are, they need access to web-based sales tools hosted in the EHR data center. EHR is retiring its Virtual Private Network infrastructure and wants access to those tools decided by user identity and device context rather than by network location. Every sales employee already signs in with a Google Workspace account.
What should you do?
a) Deploy an external Application Load Balancer in front of the sales tools and write a Cloud Armor policy that allows requests from the sales team's known source addresses.
b) Grant each sales employee's Google Workspace user account the App Engine Viewer predefined role on the project.
c) Create a Google group for the sales tool application, upgrade that group to a security group, and add the sales employees to it.
d) Deploy an Identity-Aware Proxy connector that fronts the sales tool application and authorize the sales employees through it.
 
10. An App Engine application keeps per-user session state on the instance that handles the request. During a phased rollout of a new version, some users report that the application behaves incorrectly when they switch between a mobile device and a desktop, while users who stay on one device see nothing wrong.
What is the most likely cause?
a) The application should be running in the App Engine flexible environment rather than the standard environment.
b) Health checks on the application are misconfigured, so instances are removed while requests are still in flight.
c) Traffic is being split between the versions by IP address, so a user who changes device can be sent to the other version.
d) The application's container image is misconfigured and starts with different settings on some instances.

Answers:

Question: 01
Answer: c
Question: 02
Answer: b, e
Question: 03
Answer: a, c
Question: 04
Answer: b
Question: 05
Answer: a
Question: 06
Answer: b
Question: 07
Answer: d
Question: 08
Answer: a
Question: 09
Answer: d
Question: 10
Answer: c

Note: Please update us by writing an email on feedback@vmexam.com for any error in Google Cloud Platform - Professional Cloud Architect (GCP-PCA) certification exam sample questions

Rating: 4.8 / 5 (86 votes)