dc dotCreds
Professional Cloud Architect

Google Cloud Architect Practice Test

Start a free 30-question Google Cloud Architect daily set with source-backed explanations, local progress, and a fresh rotation every morning.

30 daily web questions Source-backed explanations 7-day score history Questions updated at Apr 13, 2026, 8:24 PM CDT
Google Cloud Architect icon

Google Cloud Architect

Professional Cloud Architect

Why this page works

  • Thirty focused questions every day
  • Source links on every explanation
  • Local progress saved automatically
  • Email sync path ready for later
  • Apps provide deeper drills when available
Today's 30 Google Cloud Architect questions

Use this Google Cloud Architect practice test to review Google Professional Cloud Architect. Questions rotate daily and each explanation links to the source used to validate the answer.

Today’s Set
30 questions
Daily set rotates at 10:00 AM local time
Progress
0/30
Answered on this page session
Accuracy
0%
Loading countdown…

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily Google PCA practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

150 verified questions are currently in the live bank. Questions updated at Apr 13, 2026, 8:24 PM CDT. The daily set rotates at 10:00 AM local time, and each explanation links back to the source used to write it. Use the web set for quick practice, then switch to the app when available for larger banks and deeper review.

Official exam resources

Use these official Google resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.

Need adjacent Google practice pages too? Google practice hub.

Question 1 of 30
Objective 2.2 Managing and Provisioning a Cloud Solution Infrastructure

When designing a global load balancing solution for an application with high traffic, which Google Cloud service should be used to ensure low latency and high availability?

Concept tested: Managing and Provisioning a Cloud Solution Infrastructure

A. Incorrect: Google Cloud CDN is incorrect because it does not answer this stem as directly as Global Load Balancing.

B. Correct: Global Load Balancing is the correct answer because global Load Balancing is designed for distributing traffic across multiple regions, ensuring low latency and high availability. The wrong answers are useful review cues: Cloud CDN caches content at the edge; Cloud DNS manages DNS zones and records, while Compute Engine provides virtual machines and infrastructure control, but they do not match this stem as directly as Global Load Balancing.

C. Incorrect: Cloud DNS is incorrect because it does not answer this stem as directly as Global Load Balancing.

D. Incorrect: Compute Engine is incorrect because it does not answer this stem as directly as Global Load Balancing.

Why this matters: This matters because architecture questions ask you to match availability, latency, and recovery requirements to the feature designed for that job.
Question 2 of 30
Objective 3.6 Designing for Security and Compliance

Which Google Cloud service should be used to securely manage remote access to applications running on Compute Engine instances without exposing them directly to the internet?

Concept tested: Designing for Security and Compliance

A. Incorrect: Cloud IAM Roles is incorrect because it does not answer this stem as directly as Identity-Aware Proxy.

B. Correct: Identity-Aware Proxy is the correct answer because identity-Aware Proxy (IAP) is designed for secure remote access to applications hosted on Google Cloud, ensuring that the application itself does not need to be exposed directly to the internet. The wrong answers are useful review cues: IAM controls identity and permission relationships; Workload Identity Federation lets external identities access Google Cloud without long-lived service account keys, while service account impersonation lets one principal act as a service account when permitted, but they do not match this stem as directly as Identity-Aware Proxy.

C. Incorrect: Workload Identity Federation is incorrect because it does not answer this stem as directly as Identity-Aware Proxy.

D. Incorrect: Service Account Impersonation is incorrect because it does not answer this stem as directly as Identity-Aware Proxy.

Why this matters: This matters because Zero Trust questions test whether identity, device, and access risk are verified before Microsoft 365 resources are allowed.
Question 3 of 30
Objective 1.12 Designing and Planning a Cloud Solution Architecture

When designing an observability strategy for a cloud-based application, which of the following is essential to ensure that future improvements can be made based on real-time data?

Concept tested: Designing and Planning a Cloud Solution Architecture

A. Incorrect: Implementing detailed logging only is incorrect because it does not answer this stem as directly as Setting up comprehensive metrics and alerts.

B. Correct: Setting up comprehensive metrics and alerts is the correct answer because comprehensive metrics and alerts provide the necessary insights to identify issues and opportunities for improvement in real-time. The wrong answers are useful review cues: Implementing detailed logging only is a related option that does not directly answer this stem; Disabling all third-party monitoring tools is a related option that does not directly answer this stem, while performance optimization focuses on workload responsiveness and efficiency, but they do not match this stem as directly as Setting up comprehensive metrics and alerts.

C. Incorrect: Disabling all third-party monitoring tools is incorrect because it does not answer this stem as directly as Setting up comprehensive metrics and alerts.

D. Incorrect: Focusing solely on user interface performance is incorrect because it does not answer this stem as directly as Setting up comprehensive metrics and alerts.

Why this matters: This matters because Designing and Planning a Cloud Solution Architecture questions test whether Setting up comprehensive metrics and alerts fits the scenario's constraints, not just whether the term sounds familiar.
Question 4 of 30
Objective 5.1 Managing Implementation

In the event of an unexpected incident during application rollout, what is the primary action operations teams should take to ensure service continuity?

Concept tested: Managing Implementation

A. Correct: Immediately roll back to the previous stable version is the correct answer because immediately roll back to the previous stable version. Rolling back to a previously stable version ensures service continuity while the issue is investigated. The wrong answers are useful review cues: Continue deploying new versions regardless of issues. is a related option that does not directly answer this stem; root-cause work identifies how an incident began and why it happened, while Restart all affected services manually without investigation. is a related option that does not directly answer this stem, but they do not match this stem as directly as Immediately roll back to the previous stable version..

B. Incorrect: Continue deploying new versions regardless of issues is incorrect because it does not answer this stem as directly as Immediately roll back to the previous stable version..

C. Incorrect: Pause all deployments and investigate the root cause is incorrect because it does not answer this stem as directly as Immediately roll back to the previous stable version..

D. Incorrect: Restart all affected services manually without investigation is incorrect because it does not answer this stem as directly as Immediately roll back to the previous stable version..

Why this matters: This matters because resilient design depends on choosing decoupling services when workloads need buffering, retries, or asynchronous processing.
Question 5 of 30
Objective 4.3 Analyzing and Optimizing Technical and Business Processes

In the context of business continuity, what is the primary goal of implementing a disaster recovery strategy?

Concept tested: Analyzing and Optimizing Technical and Business Processes

A. Incorrect: Minimize data storage costs is incorrect because it does not answer this stem as directly as Ensure uninterrupted service availability.

B. Incorrect: Increase employee productivity is incorrect because it does not answer this stem as directly as Ensure uninterrupted service availability.

C. Incorrect: Reduce network bandwidth usage is incorrect because it does not answer this stem as directly as Ensure uninterrupted service availability.

D. Correct: Ensure uninterrupted service availability is the correct answer because the main objective of a disaster recovery strategy is to ensure that services remain available during and after a disaster. The wrong answers are useful review cues: Minimize data storage costs is a related option that does not directly answer this stem; Increase employee productivity is a related option that does not directly answer this stem, while Reduce network bandwidth usage is a related option that does not directly answer this stem, and they do not match this stem as directly as Ensure uninterrupted service availability.

Why this matters: This matters because architecture questions ask you to match availability, latency, and recovery requirements to the feature designed for that job.
Question 6 of 30
Objective 6.3 Ensuring Solution and Operations Excellence

Which feature of Google Cloud Logging should you use to monitor user activity across multiple projects?

Concept tested: Ensuring Solution and Operations Excellence

A. Incorrect: Log routing with a single sink is incorrect because it does not answer this stem as directly as Cloud Audit Logs for all projects..

B. Incorrect: Custom logs in each project is incorrect because it does not answer this stem as directly as Cloud Audit Logs for all projects..

C. Correct: Cloud Audit Logs for all projects is the correct answer because cloud Audit Logs for all projects. Cloud Audit Logs provide comprehensive monitoring of user activity across Google Cloud resources, including multiple projects, which is essential for compliance and security audits. The wrong answers are useful review cues: Log routing with a single sink. is a related option that does not directly answer this stem; Custom logs in each project. is a related option that does not directly answer this stem, while Unified logging service. is a related option that does not directly answer this stem, but they do not match this stem as directly as Cloud Audit Logs for all projects..

D. Incorrect: Unified logging service is incorrect because it does not answer this stem as directly as Cloud Audit Logs for all projects..

Why this matters: This matters because Ensuring Solution and Operations Excellence questions test whether Cloud Audit Logs for all projects fits the scenario's constraints, not just whether the term sounds familiar.
Question 7 of 30
Objective 2.5 Managing and Provisioning a Cloud Solution Infrastructure

Which Compute Engine machine family is designed for memory-intensive workloads?

Concept tested: Managing and Provisioning a Cloud Solution Infrastructure

A. Incorrect: Shared-core machine family is incorrect because it does not answer this stem as directly as Memory-optimized machine family.

B. Correct: Memory-optimized machine family is the correct answer because compute Engine machine-family documentation identifies memory-optimized machines for workloads that need high memory capacity. The wrong answers are useful review cues: Shared-core machine family is a related option that does not directly answer this stem; Storage bucket class is a related option that does not directly answer this stem, while Cloud Run runs serverless containers that scale with requests, but they do not match this stem as directly as Memory-optimized machine family.

C. Incorrect: Storage bucket class is incorrect because it does not answer this stem as directly as Memory-optimized machine family.

D. Incorrect: Cloud Run function class is incorrect because it does not answer this stem as directly as Memory-optimized machine family.

Why this matters: This matters because Managing and Provisioning a Cloud Solution Infrastructure questions test whether Memory-optimized machine family fits the scenario's constraints, not just whether the term sounds familiar.
Question 8 of 30
Objective 3.4 Designing for Security and Compliance

How can you ensure that sensitive data stored in Secret Manager is not accidentally exposed?

Concept tested: Designing for Security and Compliance

A. Incorrect: Encrypting the secrets with a third-party tool is incorrect because it does not answer this stem as directly as By setting up alerts on Cloud Monitoring.

B. Incorrect: Using version control systems like Git is incorrect because it does not answer this stem as directly as By setting up alerts on Cloud Monitoring.

C. Incorrect: Disabling all access to the secrets is incorrect because it does not answer this stem as directly as By setting up alerts on Cloud Monitoring.

D. Correct: By setting up alerts on Cloud Monitoring is the correct answer because setting up alerts in Cloud Monitoring helps detect and respond to unauthorized access. The wrong answers are useful review cues: Encrypting the secrets with a third-party tool is a related option that does not directly answer this stem; Using version control systems like Git is a related option that does not directly answer this stem, while Disabling all access to the secrets is a related option that does not directly answer this stem, and they do not match this stem as directly as By setting up alerts on Cloud Monitoring.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 9 of 30
Objective 1.3 Designing and Planning a Cloud Solution Architecture

In the context of operational excellence, which practice is essential for quickly identifying and responding to incidents in a cloud environment?

Concept tested: Designing and Planning a Cloud Solution Architecture

A. Correct: Establishing comprehensive monitoring and alerting mechanisms is the correct answer because comprehensive monitoring and alerting mechanisms are crucial for operational excellence as they enable quick identification and response to incidents. The wrong answers are useful review cues: Ensuring high availability through redundant systems is a related option that does not directly answer this stem; access control restricts who or what can use a resource, while Optimizing resource usage with auto-scaling policies is a related option that does not directly answer this stem, and they do not match this stem as directly as Establishing comprehensive monitoring and alerting mechanisms.

B. Incorrect: Ensuring high availability through redundant systems is incorrect because it does not answer this stem as directly as Establishing comprehensive monitoring and alerting mechanisms.

C. Incorrect: Implementing strict access controls on all resources is incorrect because it does not answer this stem as directly as Establishing comprehensive monitoring and alerting mechanisms.

D. Incorrect: Optimizing resource usage with auto-scaling policies is incorrect because it does not answer this stem as directly as Establishing comprehensive monitoring and alerting mechanisms.

Why this matters: This matters because Designing and Planning a Cloud Solution Architecture questions test whether Establishing comprehensive monitoring and alerting mechanisms fits the scenario's constraints, not just whether the term sounds familiar.
Question 10 of 30
Objective 5.6 Managing Implementation

When implementing a Google Cloud project that uses multiple APIs, what is the recommended approach to manage authentication across these services?

Concept tested: Managing Implementation

A. Incorrect: Use a single service account for all API interactions is incorrect because it does not answer this stem as directly as Implement IAM roles with least privilege access per API..

B. Correct: Implement IAM roles with least privilege access per API is the correct answer because implement IAM roles with least privilege access per API. Using IAM roles allows you to define specific permissions needed by an application, ensuring that the principle of least privilege is followed. The wrong answers are useful review cues: service accounts are identities used by workloads or automation; Create separate OAuth 2.0 credentials for each API. is a related option that does not directly answer this stem, while Utilize shared JWT tokens between different APIs. is a related option that does not directly answer this stem, but they do not match this stem as directly as Implement IAM roles with least privilege access per API..

C. Incorrect: Create separate OAuth 2.0 credentials for each API is incorrect because it does not answer this stem as directly as Implement IAM roles with least privilege access per API..

D. Incorrect: Utilize shared JWT tokens between different APIs is incorrect because it does not answer this stem as directly as Implement IAM roles with least privilege access per API..

Why this matters: This matters because Zero Trust questions test whether identity, device, and access risk are verified before Microsoft 365 resources are allowed.
Question 11 of 30
Objective 4.2 Analyzing and Optimizing Technical and Business Processes

When conducting a root cause analysis for an operational incident, which of the following is most important to identify first?

Concept tested: Analyzing and Optimizing Technical and Business Processes

A. Correct: The initial trigger event is the correct answer because identifying the initial trigger event helps in understanding how the incident started, which is crucial for further analysis. The wrong answers are useful review cues: All potential contributing factors is a related option that does not directly answer this stem; The underlying technical issue is a related option that does not directly answer this stem, while The immediate impact on users is a related option that does not directly answer this stem, and they do not match this stem as directly as The initial trigger event.

B. Incorrect: All potential contributing factors is incorrect because it does not answer this stem as directly as The initial trigger event.

C. Incorrect: The underlying technical issue is incorrect because it does not answer this stem as directly as The initial trigger event.

D. Incorrect: The immediate impact on users is incorrect because it does not answer this stem as directly as The initial trigger event.

Why this matters: This matters because resilient design depends on choosing decoupling services when workloads need buffering, retries, or asynchronous processing.
Question 12 of 30
Objective 6.5 Ensuring Solution and Operations Excellence

When implementing a rollback strategy for your application, which feature of Cloud Deploy ensures that you can revert to the previous version if issues arise?

Concept tested: Ensuring Solution and Operations Excellence

A. Incorrect: Release approvals is incorrect because it does not answer this stem as directly as Rollback triggers.

B. Incorrect: Deployment policies is incorrect because it does not answer this stem as directly as Rollback triggers.

C. Correct: Rollback triggers is the correct answer because rollback triggers in Cloud Deploy automatically initiate a rollback process when certain conditions are met, ensuring application stability. The wrong answers are useful review cues: release approvals add a human gate before rollout; deployment policies constrain how releases move through stages, while rollback behavior restores a previous release when problems appear, but they do not match this stem as directly as Rollback triggers.

D. Incorrect: Manual rollbacks is incorrect because it does not answer this stem as directly as Rollback triggers.

Why this matters: This matters because Ensuring Solution and Operations Excellence questions test whether Rollback triggers fits the scenario's constraints, not just whether the term sounds familiar.
Question 13 of 30
Objective 2.1 Managing and Provisioning a Cloud Solution Infrastructure

When designing a VPC network for high availability, which configuration is essential to ensure traffic can flow between two subnets in different regions?

Concept tested: Managing and Provisioning a Cloud Solution Infrastructure

A. Incorrect: Enable Cloud DNS forwarding is incorrect because it does not answer this stem as directly as Configure a global load balancer.

B. Incorrect: Create a shared VPC service project is incorrect because it does not answer this stem as directly as Configure a global load balancer.

C. Incorrect: Set up peering connections between the subnets is incorrect because it does not answer this stem as directly as Configure a global load balancer.

D. Correct: Configure a global load balancer is the correct answer because a global load balancer is essential for directing traffic across different regions, ensuring high availability and redundancy. The wrong answers are useful review cues: Cloud DNS manages DNS zones and records; Create a shared VPC service project is a related option that does not directly answer this stem, while Set up peering connections between the subnets is a related option that does not directly answer this stem, and they do not match this stem as directly as Configure a global load balancer.

Why this matters: This matters because architecture questions ask you to match availability, latency, and recovery requirements to the feature designed for that job.
Question 14 of 30
Objective 3.7 Designing for Security and Compliance

Which approach is recommended to securely delegate access from external identities to Google Cloud services without storing long-term credentials?

Concept tested: Designing for Security and Compliance

A. Incorrect: Use a single service account with broad permissions is incorrect because it does not answer this stem as directly as Implement Workload Identity Federation for secure delegation..

B. Incorrect: Store API keys in environment variables for all users is incorrect because it does not answer this stem as directly as Implement Workload Identity Federation for secure delegation..

C. Correct: Implement Workload Identity Federation for secure delegation is the correct answer because implement Workload Identity Federation for secure delegation. Workload Identity Federation enables secure and temporary access from external identities, ensuring that no long-term credentials are stored on the client side. The wrong answers are useful review cues: service accounts are identities used by workloads or automation; Store API keys in environment variables for all users. is a related option that does not directly answer this stem, while Grant IAM roles directly to individual user accounts. is a related option that does not directly answer this stem, but they do not match this stem as directly as Implement Workload Identity Federation for secure delegation..

D. Incorrect: Grant IAM roles directly to individual user accounts is incorrect because it does not answer this stem as directly as Implement Workload Identity Federation for secure delegation..

Why this matters: This matters because Zero Trust questions test whether identity, device, and access risk are verified before Microsoft 365 resources are allowed.
Question 15 of 30
Objective 1.2 Designing and Planning a Cloud Solution Architecture

In disaster recovery planning, which metric defines the maximum acceptable length of time a workload can be unavailable?

Concept tested: Designing and Planning a Cloud Solution Architecture

A. Correct: Recovery time objective is the correct answer because google Cloud disaster recovery guidance uses recovery time objective to describe how long a workload can be unavailable after a failure. The wrong answers are useful review cues: service accounts are identities used by workloads or automation; Subnet CIDR size is a related option that does not directly answer this stem, while Container image digest is a related option that does not directly answer this stem, and they do not match this stem as directly as Recovery time objective.

B. Incorrect: Service account key age is incorrect because it does not answer this stem as directly as Recovery time objective.

C. Incorrect: Subnet CIDR size is incorrect because it does not answer this stem as directly as Recovery time objective.

D. Incorrect: Container image digest is incorrect because it does not answer this stem as directly as Recovery time objective.

Why this matters: This matters because architecture questions ask you to match availability, latency, and recovery requirements to the feature designed for that job.
Question 16 of 30
Objective 5.3 Managing Implementation

Which Google Cloud SDK command is used to list all the buckets in a project?

Concept tested: Managing Implementation

A. Incorrect: gcloud storage bucket-list is incorrect because it does not answer this stem as directly as gsutil ls gs://.

B. Incorrect: bq ls --buckets is incorrect because it does not answer this stem as directly as gsutil ls gs://.

C. Correct: gsutil ls gs:// is the correct answer because the correct command 'gsutil ls gs://' is used to list all the buckets in a project. The wrong answers are useful review cues: Cloud Storage is object storage for durable files and objects, while bq is the BigQuery command-line tool, but they do not match this stem as directly as gsutil ls gs://.

D. Incorrect: gcloud storage ls is incorrect because it does not answer this stem as directly as gsutil ls gs://.

Why this matters: This matters because Managing Implementation questions test whether gsutil ls gs:// fits the scenario's constraints, not just whether the term sounds familiar.
Question 17 of 30
Objective 4.4 Analyzing and Optimizing Technical and Business Processes

When evaluating resource utilization for cost optimization, which approach is most effective in reducing unnecessary expenses?

Concept tested: Analyzing and Optimizing Technical and Business Processes

A. Incorrect: Disabling all unused services immediately is incorrect because it does not answer this stem as directly as Implementing auto-scaling policies.

B. Correct: Implementing auto-scaling policies is the correct answer because auto-scaling policies help adjust resource allocation based on demand, reducing costs by avoiding over-provisioning. The wrong answers are useful review cues: Disabling all unused services immediately is a related option that does not directly answer this stem; Creating more detailed billing reports is a related option that does not directly answer this stem, while Increasing the number of reserved instances is a related option that does not directly answer this stem, and they do not match this stem as directly as Implementing auto-scaling policies.

C. Incorrect: Creating more detailed billing reports is incorrect because it does not answer this stem as directly as Implementing auto-scaling policies.

D. Incorrect: Increasing the number of reserved instances is incorrect because it does not answer this stem as directly as Implementing auto-scaling policies.

Why this matters: This matters because cost questions reward matching pricing behavior to workload patterns, not choosing the most familiar service.
Question 18 of 30
Objective 6.2 Ensuring Solution and Operations Excellence

What is the primary purpose of creating custom dashboards in Cloud Monitoring?

Concept tested: Ensuring Solution and Operations Excellence

A. Correct: To visualize metrics data is the correct answer because custom dashboards allow users to visualize and monitor key performance indicators and other relevant metrics for their services. The wrong answers are useful review cues: To manage IAM roles is a related option that does not directly answer this stem; To configure network settings is a related option that does not directly answer this stem, while Cloud Run functions are event-driven serverless functions, but they do not match this stem as directly as To visualize metrics data.

B. Incorrect: To manage IAM roles is incorrect because it does not answer this stem as directly as To visualize metrics data.

C. Incorrect: To configure network settings is incorrect because it does not answer this stem as directly as To visualize metrics data.

D. Incorrect: To deploy cloud functions is incorrect because it does not answer this stem as directly as To visualize metrics data.

Why this matters: This matters because Ensuring Solution and Operations Excellence questions test whether To visualize metrics data fits the scenario's constraints, not just whether the term sounds familiar.
Question 19 of 30
Objective 2.4 Managing and Provisioning a Cloud Solution Infrastructure

When configuring lifecycle management for Google Cloud Storage, which action is recommended to reduce costs for rarely accessed data?

Concept tested: Managing and Provisioning a Cloud Solution Infrastructure

A. Incorrect: Encrypt all objects with customer-managed keys is incorrect because it does not answer this stem as directly as Move objects to Nearline.

B. Incorrect: Delete objects after 30 days is incorrect because it does not answer this stem as directly as Move objects to Nearline.

C. Correct: Move objects to Nearline is the correct answer because moving objects to the Nearline storage class reduces costs for data that is rarely accessed but still needs to be retained. The wrong answers are useful review cues: Encrypt all objects with customer-managed keys is a related option that does not directly answer this stem; Delete objects after 30 days is a related option that does not directly answer this stem, while Archive objects in a separate bucket is a related option that does not directly answer this stem, and they do not match this stem as directly as Move objects to Nearline.

D. Incorrect: Archive objects in a separate bucket is incorrect because it does not answer this stem as directly as Move objects to Nearline.

Why this matters: This matters because Managing and Provisioning a Cloud Solution Infrastructure questions test whether Move objects to Nearline fits the scenario's constraints, not just whether the term sounds familiar.
Question 20 of 30
Objective 3.9 Designing for Security and Compliance

Which Google Cloud service helps screen prompts and responses for generative AI safety and security risks?

Concept tested: Designing for Security and Compliance

A. Incorrect: Service Catalog is incorrect because it does not answer this stem as directly as Model Armor.

B. Incorrect: Cloud NAT is incorrect because it does not answer this stem as directly as Model Armor.

C. Correct: Model Armor is the correct answer because google Cloud documentation describes Model Armor as a service for screening model prompts and responses for safety and security risks. The wrong answers are useful review cues: Service Catalog is a related option that does not directly answer this stem; Cloud NAT gives private resources outbound internet access, while Cloud DNS manages DNS zones and records, but they do not match this stem as directly as Model Armor.

D. Incorrect: Cloud DNS peering is incorrect because it does not answer this stem as directly as Model Armor.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 21 of 30
Objective 1.6 Designing and Planning a Cloud Solution Architecture

Which approach should be used to ensure that resources are sized appropriately for peak usage while minimizing costs during off-peak times?

Concept tested: Designing and Planning a Cloud Solution Architecture

A. Incorrect: Using reserved instances exclusively is incorrect because it does not answer this stem as directly as Implementing auto-scaling with spot instances.

B. Incorrect: Purchasing committed use discounts is incorrect because it does not answer this stem as directly as Implementing auto-scaling with spot instances.

C. Incorrect: Deploying static resource sizes year-round is incorrect because it does not answer this stem as directly as Implementing auto-scaling with spot instances.

D. Correct: Implementing auto-scaling with spot instances is the correct answer because auto-scaling with spot instances allows for dynamic adjustment of resources based on demand, reducing costs during off-peak times. The wrong answers are useful review cues: Using reserved instances exclusively is a related option that does not directly answer this stem; Purchasing committed use discounts is a related option that does not directly answer this stem, while Deploying static resource sizes year-round is a related option that does not directly answer this stem, and they do not match this stem as directly as Implementing auto-scaling with spot instances.

Why this matters: This matters because Copilot administration questions separate license assignment, billing policy, analytics, and security controls.
Question 22 of 30
Objective 5.2 Managing Implementation

Which Apigee feature enables you to define and enforce rate limits on API requests?

Concept tested: Managing Implementation

A. Incorrect: Rate Quotas is incorrect because it does not answer this stem as directly as Usage Plans.

B. Incorrect: Access Control is incorrect because it does not answer this stem as directly as Usage Plans.

C. Incorrect: Throttling Policies is incorrect because it does not answer this stem as directly as Usage Plans.

D. Correct: Usage Plans is the correct answer because usage Plans allow you to define and enforce rate limits on API requests. The wrong answers are useful review cues: quotas limit request volume over a defined window; access control restricts who or what can use a resource, while Throttling Policies is a related option that does not directly answer this stem, and they do not match this stem as directly as Usage Plans.

Why this matters: This matters because Copilot administration questions separate license assignment, billing policy, analytics, and security controls.
Question 23 of 30
Objective 4.6 Analyzing and Optimizing Technical and Business Processes

In Service Catalog, what object groups approved solutions so users can find and launch them?

Concept tested: Analyzing and Optimizing Technical and Business Processes

A. Incorrect: Log sink is incorrect because it does not answer this stem as directly as Catalog.

B. Incorrect: Firewall policy is incorrect because it does not answer this stem as directly as Catalog.

C. Incorrect: VPC subnet is incorrect because it does not answer this stem as directly as Catalog.

D. Correct: Catalog is the correct answer because service Catalog documentation describes catalogs as collections used to organize solutions that can be shared with users. The wrong answers are useful review cues: Log sink is a related option that does not directly answer this stem; Firewall policy is a related option that does not directly answer this stem, while VPC subnet is a related option that does not directly answer this stem, and they do not match this stem as directly as Catalog.

Why this matters: This matters because Analyzing and Optimizing Technical and Business Processes questions test whether Catalog fits the scenario's constraints, not just whether the term sounds familiar.
Question 24 of 30
Objective 6.1 Ensuring Solution and Operations Excellence

When designing a runbook for incident response, which of the following is most important to include?

Concept tested: Ensuring Solution and Operations Excellence

A. Correct: Step-by-step procedures for restoring service availability is the correct answer because the primary goal of an incident response runbook is to provide clear, actionable steps to restore service availability. The wrong answers are useful review cues: A detailed list of all stakeholders' contact information is a related option that does not directly answer this stem; An exhaustive inventory of all cloud resources used by the company is a related option that does not directly answer this stem, while Instructions on how to update the company's website is a related option that does not directly answer this stem, and they do not match this stem as directly as Step-by-step procedures for restoring service availability.

B. Incorrect: A detailed list of all stakeholders' contact information is incorrect because it does not answer this stem as directly as Step-by-step procedures for restoring service availability.

C. Incorrect: An exhaustive inventory of all cloud resources used by the company is incorrect because it does not answer this stem as directly as Step-by-step procedures for restoring service availability.

D. Incorrect: Instructions on how to update the company's website is incorrect because it does not answer this stem as directly as Step-by-step procedures for restoring service availability.

Why this matters: This matters because architecture questions ask you to match availability, latency, and recovery requirements to the feature designed for that job.
Question 25 of 30
Objective 2.3 Managing and Provisioning a Cloud Solution Infrastructure

Which configuration is necessary to establish private connectivity between an on-premises network and Google services using Private Service Connect?

Concept tested: Managing and Provisioning a Cloud Solution Infrastructure

A. Incorrect: Configure VPC service controls is incorrect because it does not answer this stem as directly as Establish a service attachment.

B. Correct: Establish a service attachment is the correct answer because service attachments are used to establish private connectivity between an on-premises network and Google services. The wrong answers are useful review cues: VPC Service Controls create service perimeters around supported resources; Create a peering connection in the VPC is a related option that does not directly answer this stem, while Set up interconnects with shared VPC is a related option that does not directly answer this stem, and they do not match this stem as directly as Establish a service attachment.

C. Incorrect: Create a peering connection in the VPC is incorrect because it does not answer this stem as directly as Establish a service attachment.

D. Incorrect: Set up interconnects with shared VPC is incorrect because it does not answer this stem as directly as Establish a service attachment.

Why this matters: This matters because Managing and Provisioning a Cloud Solution Infrastructure questions test whether Establish a service attachment fits the scenario's constraints, not just whether the term sounds familiar.
Question 26 of 30
Objective 3.2 Designing for Security and Compliance

When designing a resource hierarchy in Google Cloud, what is the recommended approach to organize access control policies across multiple projects?

Concept tested: Designing for Security and Compliance

A. Incorrect: Create individual IAM policies for each project is incorrect because it does not answer this stem as directly as Use folders to group related projects and apply centralized IAM policies..

B. Correct: Use folders to group related projects and apply centralized IAM policies is the correct answer because use folders to group related projects and apply centralized IAM policies. Using folders allows you to group related projects together and apply consistent IAM policies across them, simplifying management and compliance. The wrong answers are useful review cues: IAM controls identity and permission relationships, while Assign all users global roles that cover all projects. is a related option that does not directly answer this stem, but they do not match this stem as directly as Use folders to group related projects and apply centralized IAM policies..

C. Incorrect: Assign all users global roles that cover all projects is incorrect because it does not answer this stem as directly as Use folders to group related projects and apply centralized IAM policies..

D. Incorrect: Disable IAM policies and use custom scripts for access control is incorrect because it does not answer this stem as directly as Use folders to group related projects and apply centralized IAM policies..

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 27 of 30
Objective 1.4 Designing and Planning a Cloud Solution Architecture

For planned maintenance, which reliability practice gives users the best chance of continued service?

Concept tested: Designing and Planning a Cloud Solution Architecture

A. Correct: Failover to healthy capacity is the correct answer because reliability guidance emphasizes resilient design and recovery behavior so systems can continue operating when components fail or need maintenance. The wrong answers are useful review cues: Deleting monitoring data is a related option that does not directly answer this stem; Using one zonal resource only is a related option that does not directly answer this stem, while Disabling health checks is a related option that does not directly answer this stem, and they do not match this stem as directly as Failover to healthy capacity.

B. Incorrect: Deleting monitoring data is incorrect because it does not answer this stem as directly as Failover to healthy capacity.

C. Incorrect: Using one zonal resource only is incorrect because it does not answer this stem as directly as Failover to healthy capacity.

D. Incorrect: Disabling health checks is incorrect because it does not answer this stem as directly as Failover to healthy capacity.

Why this matters: This matters because architecture questions ask you to match availability, latency, and recovery requirements to the feature designed for that job.
Question 28 of 30
Objective 5.5 Managing Implementation

When implementing Infrastructure as Code with Terraform in a multi-region environment, which strategy ensures consistent resource configuration across regions?

Concept tested: Managing Implementation

A. Incorrect: Using separate state files for each region to maintain isolation is incorrect because it does not answer this stem as directly as Employing modules that define common resources and variables..

B. Correct: Employing modules that define common resources and variables is the correct answer because employing modules that define common resources and variables. Using modules with defined inputs allows for consistent resource configuration across different regions without duplicating code. The wrong answers are useful review cues: Using separate state files for each region to maintain isolation. is a related option that does not directly answer this stem; Creating individual workspaces for every project within the same region. is a related option that does not directly answer this stem, while Hardcoding regional settings directly into Terraform scripts. is a related option that does not directly answer this stem, but they do not match this stem as directly as Employing modules that define common resources and variables..

C. Incorrect: Creating individual workspaces for every project within the same region is incorrect because it does not answer this stem as directly as Employing modules that define common resources and variables..

D. Incorrect: Hardcoding regional settings directly into Terraform scripts is incorrect because it does not answer this stem as directly as Employing modules that define common resources and variables..

Why this matters: This matters because architecture questions ask you to match availability, latency, and recovery requirements to the feature designed for that job.
Question 29 of 30
Objective 4.5 Analyzing and Optimizing Technical and Business Processes

Before implementing a new cloud service, what should an architect assess about the team?

Concept tested: Analyzing and Optimizing Technical and Business Processes

A. Incorrect: Logo dimensions is incorrect because it does not answer this stem as directly as Skills and readiness.

B. Incorrect: Browser theme preference is incorrect because it does not answer this stem as directly as Skills and readiness.

C. Correct: Skills and readiness is the correct answer because the Professional Cloud Architect exam guide includes analyzing stakeholder readiness, technical skills, and business processes as part of architecture work. The wrong answers are useful review cues: Logo dimensions is a related option that does not directly answer this stem; Browser theme preference is a related option that does not directly answer this stem, while Ad campaign names is a related option that does not directly answer this stem, and they do not match this stem as directly as Skills and readiness.

D. Incorrect: Ad campaign names is incorrect because it does not answer this stem as directly as Skills and readiness.

Why this matters: This matters because Analyzing and Optimizing Technical and Business Processes questions test whether Skills and readiness fits the scenario's constraints, not just whether the term sounds familiar.
Question 30 of 30
Objective 6.4 Ensuring Solution and Operations Excellence

Which of the following is a best practice for setting up alerting strategies to monitor service level objectives (SLOs)?

Concept tested: Ensuring Solution and Operations Excellence

A. Incorrect: Setting alerts based on SLO violations only after they occur is incorrect because it does not answer this stem as directly as Configuring alerts to notify teams before an SLO is breached, allowing proactive resolution..

B. Correct: Configuring alerts to notify teams before an SLO is breached, allowing proactive resolution is the correct answer because configuring alerts to notify teams before an SLO is breached, allowing proactive resolution. Proactive notification allows for timely intervention and reduces the likelihood of service degradation. The wrong answers are useful review cues: Setting alerts based on SLO violations only after they occur. is a related option that does not directly answer this stem; Creating alerts that trigger when any metric exceeds its threshold, regardless of impact on user experience. is a related option that does not directly answer this stem, while Disabling all alert notifications during off-hours to avoid unnecessary interruptions. is a related option that does not directly answer this stem, but they do not match this stem as directly as Configuring alerts to notify teams before an SLO is breached, allowing proactive resolution..

C. Incorrect: Creating alerts that trigger when any metric exceeds its threshold, regardless of impact on user experience is incorrect because it does not answer this stem as directly as Configuring alerts to notify teams before an SLO is breached, allowing proactive resolution..

D. Incorrect: Disabling all alert notifications during off-hours to avoid unnecessary interruptions is incorrect because it does not answer this stem as directly as Configuring alerts to notify teams before an SLO is breached, allowing proactive resolution..

Why this matters: This matters because Ensuring Solution and Operations Excellence questions test whether Configuring alerts to notify teams before an SLO is breached,... fits the scenario's constraints, not just whether the term sounds familiar.
Where to go after the daily web set

How are Google Cloud Architect questions generated?

dotCreds builds Google Cloud Architect practice questions from public exam objectives and Google exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 30-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start Google Cloud Architect practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.

Why use the app when available?

The web page is the quick free sampler. If a dotCreds app is available for Google Cloud Architect, the app is better for larger banks, focused weak-domain drills, longer review sessions, and mobile study routines.