Google Professional Cloud Architect Google Certified Professional – Cloud Architect (GCP) Online Training
Google Professional Cloud Architect Online Training
The questions for Professional Cloud Architect were last updated at Jul 20,2025.
- Exam Code: Professional Cloud Architect
- Exam Name: Google Certified Professional – Cloud Architect (GCP)
- Certification Provider: Google
- Latest update: Jul 20,2025
You have been engaged by your client to lead the migration of their application infrastructure to GCP. One of their current problems is that the on-premises high performance SAN is requiring frequent and expensive upgrades to keep up with the variety of workloads that are identified as follows: 20TB of log archives retained for legal reasons; 500 GB of VM boot/data volumes and templates; 500 GB of image thumbnails; 200 GB of customer session state data that allows customers to restart sessions even if off-line for several days.
Which of the following best reflects your recommendations for a cost-effective storage allocation?
- A . Local SSD for customer session state datA. Lifecycle-managed Cloud Storage for log archives, thumbnails, and VM boot/data volumes.
- B . Memcache backed by Cloud Datastore for the customer session state datA. Lifecycle-managed Cloud
Storage for log archives, thumbnails, and VM boot/data volumes. - C . Memcache backed by Cloud SQL for customer session state datA. Assorted local SSD-backed instances for VM boot/data volumes. Cloud Storage for log archives and thumbnails.
- D . Memcache backed by Persistent Disk SSD storage for customer session state datA. Assorted local SSDbacked instances for VM boot/data volumes. Cloud Storage for log archives and thumbnails.
Your company has an application deployed on Anthos clusters (formerly Anthos GKE) that is running multiple microservices. The cluster has both Anthos Service Mesh and Anthos Config Management configured. End users inform you that the application is responding very slowly. You want to identify the microservice that is causing the delay .
What should you do?
- A . Use the Service Mesh visualization in the Cloud Console to inspect the telemetry between the microservices.
- B . Use Anthos Config Management to create a ClusterSelector selecting the relevant cluster. On the Google Cloud Console page for Google Kubernetes Engine, view the Workloads and filter on the cluster. Inspect the configurations of the filtered workloads.
- C . Use Anthos Config Management to create a namespaceSelector selecting the relevant cluster namespace. On the Google Cloud Console page for Google Kubernetes Engine, visit the workloads and filter on the namespace. Inspect the configurations of the filtered workloads.
- D . Reinstall istio using the default istio profile in order to collect request latency. Evaluate the telemetry between the microservices in the Cloud Console.
Your company pushes batches of sensitive transaction data from its application server VMs to Cloud Pub/Sub for processing and storage .
What is the Google-recommended way for your application to authenticate to the required Google Cloud services?
- A . Ensure that VM service accounts are granted the appropriate Cloud Pub/Sub IAM roles.
- B . Ensure that VM service accounts do not have access to Cloud Pub/Sub, and use VM access scopes to
grant the appropriate Cloud Pub/Sub IAM roles. - C . Generate an OAuth2 access token for accessing Cloud Pub/Sub, encrypt it, and store it
in Cloud Storage for access from each VM. - D . Create a gateway to Cloud Pub/Sub using a Cloud Function, and grant the Cloud Function service account the appropriate Cloud Pub/Sub IAM roles.
Your company pushes batches of sensitive transaction data from its application server VMs to Cloud Pub/Sub for processing and storage .
What is the Google-recommended way for your application to authenticate to the required Google Cloud services?
- A . Ensure that VM service accounts are granted the appropriate Cloud Pub/Sub IAM roles.
- B . Ensure that VM service accounts do not have access to Cloud Pub/Sub, and use VM access scopes to
grant the appropriate Cloud Pub/Sub IAM roles. - C . Generate an OAuth2 access token for accessing Cloud Pub/Sub, encrypt it, and store it
in Cloud Storage for access from each VM. - D . Create a gateway to Cloud Pub/Sub using a Cloud Function, and grant the Cloud Function service account the appropriate Cloud Pub/Sub IAM roles.
Your company pushes batches of sensitive transaction data from its application server VMs to Cloud Pub/Sub for processing and storage .
What is the Google-recommended way for your application to authenticate to the required Google Cloud services?
- A . Ensure that VM service accounts are granted the appropriate Cloud Pub/Sub IAM roles.
- B . Ensure that VM service accounts do not have access to Cloud Pub/Sub, and use VM access scopes to
grant the appropriate Cloud Pub/Sub IAM roles. - C . Generate an OAuth2 access token for accessing Cloud Pub/Sub, encrypt it, and store it
in Cloud Storage for access from each VM. - D . Create a gateway to Cloud Pub/Sub using a Cloud Function, and grant the Cloud Function service account the appropriate Cloud Pub/Sub IAM roles.
Your company pushes batches of sensitive transaction data from its application server VMs to Cloud Pub/Sub for processing and storage .
What is the Google-recommended way for your application to authenticate to the required Google Cloud services?
- A . Ensure that VM service accounts are granted the appropriate Cloud Pub/Sub IAM roles.
- B . Ensure that VM service accounts do not have access to Cloud Pub/Sub, and use VM access scopes to
grant the appropriate Cloud Pub/Sub IAM roles. - C . Generate an OAuth2 access token for accessing Cloud Pub/Sub, encrypt it, and store it
in Cloud Storage for access from each VM. - D . Create a gateway to Cloud Pub/Sub using a Cloud Function, and grant the Cloud Function service account the appropriate Cloud Pub/Sub IAM roles.
Your company pushes batches of sensitive transaction data from its application server VMs to Cloud Pub/Sub for processing and storage .
What is the Google-recommended way for your application to authenticate to the required Google Cloud services?
- A . Ensure that VM service accounts are granted the appropriate Cloud Pub/Sub IAM roles.
- B . Ensure that VM service accounts do not have access to Cloud Pub/Sub, and use VM access scopes to
grant the appropriate Cloud Pub/Sub IAM roles. - C . Generate an OAuth2 access token for accessing Cloud Pub/Sub, encrypt it, and store it
in Cloud Storage for access from each VM. - D . Create a gateway to Cloud Pub/Sub using a Cloud Function, and grant the Cloud Function service account the appropriate Cloud Pub/Sub IAM roles.
Your company pushes batches of sensitive transaction data from its application server VMs to Cloud Pub/Sub for processing and storage .
What is the Google-recommended way for your application to authenticate to the required Google Cloud services?
- A . Ensure that VM service accounts are granted the appropriate Cloud Pub/Sub IAM roles.
- B . Ensure that VM service accounts do not have access to Cloud Pub/Sub, and use VM access scopes to
grant the appropriate Cloud Pub/Sub IAM roles. - C . Generate an OAuth2 access token for accessing Cloud Pub/Sub, encrypt it, and store it
in Cloud Storage for access from each VM. - D . Create a gateway to Cloud Pub/Sub using a Cloud Function, and grant the Cloud Function service account the appropriate Cloud Pub/Sub IAM roles.
Your company pushes batches of sensitive transaction data from its application server VMs to Cloud Pub/Sub for processing and storage .
What is the Google-recommended way for your application to authenticate to the required Google Cloud services?
- A . Ensure that VM service accounts are granted the appropriate Cloud Pub/Sub IAM roles.
- B . Ensure that VM service accounts do not have access to Cloud Pub/Sub, and use VM access scopes to
grant the appropriate Cloud Pub/Sub IAM roles. - C . Generate an OAuth2 access token for accessing Cloud Pub/Sub, encrypt it, and store it
in Cloud Storage for access from each VM. - D . Create a gateway to Cloud Pub/Sub using a Cloud Function, and grant the Cloud Function service account the appropriate Cloud Pub/Sub IAM roles.
Migrate all virtual machines into Compute Engine.