{"id":16995,"date":"2026-09-21T05:52:32","date_gmt":"2026-09-21T05:52:32","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16995"},"modified":"2026-09-21T05:52:32","modified_gmt":"2026-09-21T05:52:32","slug":"google-professional-cloud-architect-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/google-professional-cloud-architect-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Google Professional Cloud Architect Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/professional-cloud-architect-exam-dumps\"><b>Google Professional Cloud Architect Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141<\/b><\/h3>\n<p><b>A company needs to expose an application running on GKE to users on the internet and distribute traffic across healthy application instances. Which component should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External Application Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud KMS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An external Application Load Balancer can provide an internet-facing entry point for applications and distribute incoming HTTP or HTTPS traffic across appropriate backends. When used with GKE, it can integrate with Kubernetes services and workloads to provide scalable traffic distribution and health-aware routing. Cloud Storage provides object storage, Cloud Scheduler manages scheduled tasks, and Cloud KMS manages cryptographic keys. Therefore, an external Application Load Balancer should be considered when a GKE-hosted application needs a public entry point and traffic distribution across healthy backends.<\/span><\/p>\n<h3><b>Question 142<\/b><\/h3>\n<p><b>Which Google Cloud service is designed to provide managed orchestration for data-processing workflows?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Composer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Armor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Composer provides managed workflow orchestration based on Apache Airflow. It can coordinate complex sequences of data-processing tasks, define dependencies, schedule executions, and monitor workflow progress. This makes it useful when an organization needs to orchestrate pipelines involving services such as BigQuery, Dataflow, Cloud Storage, or other processing systems. Cloud CDN accelerates content delivery, Cloud Armor provides application protection, and Cloud NAT provides outbound connectivity for private resources. Therefore, Cloud Composer is the appropriate service for managed data-workflow orchestration.<\/span><\/p>\n<h3><b>Question 143<\/b><\/h3>\n<p><b>A company wants to store sensitive configuration values separately from application source code and retrieve them securely at runtime. Which service should it use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secret Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secret Manager provides centralized storage and controlled access for sensitive information such as API keys, passwords, tokens, and other application secrets. Applications can retrieve secrets at runtime rather than embedding them directly in source code or configuration files. Secret versions also support controlled updates and rotation workflows. Cloud DNS manages name resolution, Cloud Scheduler runs scheduled tasks, and Cloud CDN provides content delivery. Therefore, Secret Manager is the appropriate service for securely separating sensitive configuration from application source code.<\/span><\/p>\n<h3><b>Question 144<\/b><\/h3>\n<p><b>A company is migrating a legacy application to Google Cloud and wants to make only the infrastructure change necessary to move it, without redesigning the application. Which migration strategy is being used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Refactor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rehost<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retire<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rebuild<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Rehosting involves moving an existing application to a new infrastructure environment with minimal modification to the application itself. This approach is commonly called lift and shift and can reduce the initial migration effort when the primary goal is to move workloads quickly. Refactoring involves changing application architecture to take advantage of cloud-native capabilities, while rebuilding generally involves creating a substantially new implementation. Retiring means removing an application that is no longer required. Therefore, rehost is the migration strategy described in this scenario.<\/span><\/p>\n<h3><b>Question 145<\/b><\/h3>\n<p><b>A production database must remain available even if the VM hosting one database component fails. Which design principle is most important?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminate all backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Introduce redundancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use only local storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deploy everything on one VM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Redundancy is a fundamental reliability principle for critical workloads. By maintaining additional instances or standby components, an application can continue operating when an individual component fails. Depending on the database technology, redundancy may involve synchronous replication, standby instances, regional configurations, or managed high-availability features. Relying on one VM creates a single point of failure, while local storage alone does not provide sufficient redundancy. Backups remain important for recovery but do not necessarily provide immediate failover. Therefore, introducing appropriate redundancy is essential for improving production database availability.<\/span><\/p>\n<h3><b>Question 146<\/b><\/h3>\n<p><b>Which Google Cloud service is intended for asynchronous communication between producers and consumers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud SQL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Run<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pub\/Sub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pub\/Sub is a managed messaging service designed to decouple producers from consumers through asynchronous communication. A publisher sends messages to a topic, while one or more subscribers receive and process those messages independently. This architecture allows components to operate at different speeds and reduces direct dependencies between services. Cloud SQL provides relational databases, Cloud Run executes containerized applications, and Cloud DNS manages name resolution. Therefore, Pub\/Sub is the appropriate service when applications need scalable asynchronous messaging and loose coupling.<\/span><\/p>\n<h3><b>Question 147<\/b><\/h3>\n<p><b>An organization wants to give a development team access to resources in a project but prevent access to unrelated production projects. Which IAM design is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant access at the entire organization level<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use project-level IAM permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Give every developer Owner access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share one administrator account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Project-level IAM permissions allow an organization to scope access to the resources required by a particular team without automatically granting access to unrelated projects. This supports the principle of least privilege and improves administrative separation between development and production environments. Granting organization-wide permissions may provide excessive access, while Owner access is broader than most application-development tasks require. Shared administrator accounts also reduce accountability. Therefore, project-level IAM permissions are appropriate when a development team needs access to one project while remaining isolated from unrelated production environments.<\/span><\/p>\n<h3><b>Question 148<\/b><\/h3>\n<p><b>A company wants to run a Kubernetes workload while retaining detailed control over node pools, machine types, and cluster infrastructure. Which GKE mode is more appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GKE Standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Run<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Functions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">App Engine<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">GKE Standard provides greater control over cluster infrastructure, including node pools, machine configurations, and other Kubernetes infrastructure settings. This flexibility is useful when application requirements or operational policies require detailed control over how Kubernetes resources are deployed. GKE Autopilot provides a more managed experience with less node-level responsibility. Cloud Run, Cloud Functions, and App Engine are managed application platforms but do not provide the same Kubernetes infrastructure control. Therefore, GKE Standard is more appropriate when detailed control over cluster infrastructure is required.<\/span><\/p>\n<h3><b>Question 149<\/b><\/h3>\n<p><b>A data engineering team needs to run Apache Spark and Hadoop workloads without managing a long-lived cluster. Which option should it evaluate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dataproc Serverless<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Armor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Memorystore<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dataproc Serverless allows organizations to run supported Spark and batch processing workloads without maintaining a persistent Dataproc cluster. Google Cloud manages the underlying infrastructure, allowing data teams to focus on submitting jobs and processing data. This can reduce operational overhead and avoid maintaining clusters when processing requirements are intermittent. Cloud DNS manages DNS, Cloud Armor protects applications, and Memorystore provides caching. Therefore, Dataproc Serverless should be evaluated when Spark or related data-processing workloads are needed without long-lived cluster management.<\/span><\/p>\n<h3><b>Question 150<\/b><\/h3>\n<p><b>Which approach is most appropriate for an application that must continue serving users even when one entire region becomes unavailable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deploy all resources in a single region<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use only zonal local storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deploy application capacity across multiple regions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable automated health checks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Regional redundancy requires distributing application capacity across more than one region so that a failure affecting an entire region does not eliminate all application instances. A global load-balancing architecture can direct traffic toward healthy regional backends when properly configured. Keeping all resources in one region does not protect against a regional outage. Local SSD provides temporary local storage and does not create regional redundancy, while disabling health checks reduces the ability to detect failed backends. Therefore, deploying application capacity across multiple regions is appropriate for regional disaster resilience.<\/span><\/p>\n<h3><b>Question 151<\/b><\/h3>\n<p><b>A company wants to prevent unauthorized changes to sensitive resources while still allowing teams to manage the resources they own. Which principle should guide IAM design?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege means granting users and workloads only the permissions required to perform their responsibilities. Applying this principle reduces the potential impact of compromised accounts and accidental administrative actions. Organizations can implement it through appropriate predefined or custom IAM roles, carefully scoped resource permissions, and separate administrative responsibilities. Shared credentials and anonymous access reduce accountability and can expose resources unnecessarily, while maximum privilege directly conflicts with secure access design. Therefore, least privilege should guide IAM design when sensitive resources need stronger access control.<\/span><\/p>\n<h3><b>Question 152<\/b><\/h3>\n<p><b>A company needs to query a large analytical dataset using SQL and does not want to manage database servers. Which service should it use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BigQuery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Filestore<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local SSD<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BigQuery is a fully managed, serverless analytical data warehouse designed for large-scale SQL queries and data analysis. It removes the need for organizations to provision and maintain traditional database servers for analytical workloads. BigQuery can process large datasets and integrate with various Google Cloud data sources. Filestore provides shared file storage, Cloud DNS manages name resolution, and Local SSD provides temporary high-performance block storage. Therefore, BigQuery is the appropriate service when teams need serverless SQL analytics over large datasets.<\/span><\/p>\n<h3><b>Question 153<\/b><\/h3>\n<p><b>An application receives unpredictable traffic spikes and should automatically add compute capacity when demand increases. Which capability should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static resource allocation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed instance group autoscaling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual VM creation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fixed-size database storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Managed instance group autoscaling automatically adjusts the number of VM instances in a managed instance group according to configured signals such as CPU utilization or other supported metrics. This allows applications to respond to changing demand without requiring administrators to manually create or remove instances. Static resource allocation and manual VM creation cannot respond as efficiently to unpredictable traffic changes. Database storage sizing addresses a different resource requirement. Therefore, managed instance group autoscaling is appropriate when VM-based application capacity must automatically increase and decrease with demand.<\/span><\/p>\n<h3><b>Question 154<\/b><\/h3>\n<p><b>A company needs to encrypt sensitive data using keys that it controls and manages through Google Cloud. Which service should be used to manage those cryptographic keys?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud KMS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Key Management Service (Cloud KMS) allows organizations to create, manage, rotate, and control access to cryptographic keys used for encryption and other security operations. It can support customer-managed encryption key architectures when organizations need greater control over key management than Google-managed encryption alone provides. Cloud Monitoring handles observability, Cloud Scheduler manages scheduled tasks, and Cloud DNS handles DNS services. Therefore, Cloud KMS is the appropriate service for centralized management of customer-controlled cryptographic keys.<\/span><\/p>\n<h3><b>Question 155<\/b><\/h3>\n<p><b>A company wants to identify which users or service accounts performed administrative actions on Google Cloud resources. Which capability should it examine?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Audit Logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage lifecycle rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Run jobs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Audit Logs provides records of activities performed on Google Cloud resources, including administrative actions and applicable access events depending on the audit-log category. These records can help security and operations teams determine which identity performed an action and when it occurred. Audit logs are useful for investigations, compliance monitoring, and operational accountability. Cloud CDN provides content delivery, Cloud Storage lifecycle rules manage objects, and Cloud Run jobs execute containerized tasks. Therefore, Cloud Audit Logs should be examined when tracking administrative activity.<\/span><\/p>\n<h3><b>Question 156<\/b><\/h3>\n<p><b>A company wants to deploy a small event-driven function without managing servers or container infrastructure. Which service is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compute Engine<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Functions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Filestore<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bigtable<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Functions provides a managed execution environment for event-driven functions without requiring the team to manage servers or container infrastructure directly. Functions can respond to supported triggers and execute application logic when events occur. This makes the service useful for lightweight event-driven processing, automation, and integration tasks. Compute Engine requires VM management, Filestore provides shared file storage, and Bigtable is a database service. Therefore, Cloud Functions is appropriate when a small event-driven workload needs serverless execution with minimal infrastructure management.<\/span><\/p>\n<h3><b>Question 157<\/b><\/h3>\n<p><b>A company needs a highly available private connection between its on-premises network and Google Cloud over the public internet. Which solution should it consider?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standard public DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HA VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HA VPN provides highly available IPsec VPN connectivity between networks using Google Cloud&#8217;s VPN infrastructure. It is designed for scenarios where encrypted connectivity over the public internet is required while improving availability compared with a single basic VPN tunnel. Depending on the architecture, HA VPN can be combined with Cloud Router and BGP for dynamic route exchange. Public DNS handles name resolution, Cloud CDN accelerates content delivery, and Cloud Storage provides object storage. Therefore, HA VPN should be considered for highly available encrypted hybrid connectivity over the internet.<\/span><\/p>\n<h3><b>Question 158<\/b><\/h3>\n<p><b>A company wants to reduce application latency by keeping frequently accessed data in memory rather than repeatedly querying a database. Which service should it evaluate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Memorystore<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BigQuery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Memorystore provides managed in-memory data stores that can be used for caching frequently accessed application data. Keeping suitable data in memory can reduce the number of repeated database queries and improve application response times. This is particularly useful for workloads with frequently requested, relatively short-lived data. Cloud Storage is object storage, Cloud Router manages dynamic network routing, and BigQuery is designed for analytical workloads. Therefore, Memorystore should be evaluated when an application needs a managed in-memory caching layer to reduce latency and database load.<\/span><\/p>\n<h3><b>Question 159<\/b><\/h3>\n<p><b>A company has a workload with strict recovery requirements and wants to define how much data it can afford to lose after a disaster. Which metric should it establish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SLI<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SLA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time. For example, an RPO of 15 minutes means the organization aims to recover data to a point no more than approximately 15 minutes before the disruption. RTO instead defines how quickly the service should be restored. SLI is a service-performance measurement, while SLA represents a formal service commitment. Therefore, RPO is the appropriate metric when an organization needs to determine how much data it can afford to lose during disaster recovery.<\/span><\/p>\n<h3><b>Question 160<\/b><\/h3>\n<p><b>A team wants to monitor CPU utilization and receive an alert when a production VM exceeds a defined threshold. Which Google Cloud service should it use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Build<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Monitoring collects metrics from Google Cloud resources and applications and provides dashboards, alerting policies, and other observability capabilities. A team can create an alerting policy that evaluates VM CPU utilization against a defined threshold and notifies the appropriate recipients when the condition is met. Cloud Storage provides object storage, Cloud DNS manages DNS, and Cloud Build supports software build automation. Therefore, Cloud Monitoring is the appropriate service for tracking CPU utilization and generating alerts when a production VM exceeds a specified threshold.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Google Professional Cloud Architect Exam Dumps and Practice Test Dumps. &nbsp; Question 141 A company needs to expose an application running on GKE to users on the internet and distribute traffic across healthy application instances. Which component should be considered? Cloud Storage External Application Load Balancer Cloud Scheduler Cloud KMS Correct Answer: 2 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16995"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16995"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16995\/revisions"}],"predecessor-version":[{"id":16996,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16995\/revisions\/16996"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16995"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16995"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16995"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}