{"id":17017,"date":"2026-09-21T05:59:49","date_gmt":"2026-09-21T05:59:49","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17017"},"modified":"2026-09-21T05:59:49","modified_gmt":"2026-09-21T05:59:49","slug":"google-professional-cloud-architect-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/google-professional-cloud-architect-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Google Professional Cloud Architect Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/professional-cloud-architect-exam-dumps\"><b>Google Professional Cloud Architect Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>A company has multiple service projects that need to use centrally managed networking from one host project. Application teams should manage their own resources without creating separate VPC networks. Which architecture is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Network Peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared VPC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Shared VPC allows a host project to provide centrally managed VPC networking to resources in attached service projects. This model separates network administration from application administration while allowing participating projects to use shared subnets and centralized network controls. It is useful for organizations that want consistent networking and governance across multiple teams or projects. VPC Network Peering connects separate VPC networks but does not provide the same host-project and service-project administrative model. Therefore, Shared VPC is appropriate for centralized network management across service projects.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>An organization wants private access from workloads to Google APIs while preventing traffic from using external IP addresses. Which combination should an architect consider?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN and Cloud Armor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT and Cloud DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private Google Access and restricted Google APIs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Interconnect and Filestore<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Private Google Access allows eligible resources without external IP addresses to reach supported Google APIs and services. When stronger service-access restrictions are required, restricted Google APIs can limit access to APIs through the restricted VIP and help reduce exposure to unintended services. This combination can support private and controlled access from workloads in VPC environments. Cloud NAT serves outbound internet connectivity, while Cloud CDN and Cloud Armor address application delivery and protection. Therefore, Private Google Access with restricted Google APIs is the appropriate combination.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>A network team must connect several VPC networks and on-premises environments through a centralized connectivity architecture rather than maintaining many independent point-to-point connections. Which service should it evaluate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Connectivity Center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Memorystore<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Connectivity Center provides a hub-and-spoke approach for connecting supported network resources and can simplify large-scale connectivity architectures. Instead of maintaining numerous independent connections between every environment, organizations can use a centralized connectivity model to reduce network-management complexity. This can be particularly useful when multiple VPC networks, hybrid environments, or supported connectivity resources need to communicate. Cloud Storage, Memorystore, and Cloud Scheduler address storage, caching, and scheduling rather than network topology. Therefore, Network Connectivity Center should be evaluated for centralized connectivity.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>A company needs a DNS solution where users inside a VPC can resolve internal application names, but those names should not be publicly resolvable. What should the architect configure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private Cloud DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private Cloud DNS zone provides DNS records that can be resolved by authorized VPC networks without publishing those names to the public internet. This is useful for internal applications, private service endpoints, and other resources whose names should remain accessible only within controlled network environments. A public DNS zone is intended for publicly resolvable names, while Cloud CDN and Cloud NAT provide content delivery and outbound connectivity. Therefore, a private Cloud DNS zone is the appropriate choice for internal-only DNS resolution.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>A company needs applications in different regions to communicate with minimal administrative overhead. The applications use regional VPC subnets and should retain centralized control of networking. Which VPC characteristic is relevant to this design?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC networks are global while subnets are regional<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC networks are regional while subnets are zonal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC networks are zonal while subnets are global<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC networks and subnets are both zonal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Google Cloud VPC networks are global resources, while their subnets are regional. This design allows a single VPC network to contain subnets in multiple regions while maintaining centralized network configuration. Applications deployed in different regions can therefore use the same VPC architecture while retaining regional subnet placement. Understanding this distinction is important when designing multi-region environments, routing, firewall rules, and shared network services. The other choices incorrectly describe the scope of VPC networks or subnets. Therefore, the first option accurately represents the relevant VPC characteristic.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>An organization wants to connect its on-premises network to Google Cloud using a dedicated private connection with predictable bandwidth. Which option should it evaluate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Interconnect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Run<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Interconnect provides private connectivity between an on-premises environment and Google Cloud and is designed for organizations that require dedicated connectivity and predictable capacity. It can be appropriate for high-volume or latency-sensitive hybrid workloads where relying on encrypted tunnels over the public internet is not preferred. Cloud VPN provides encrypted connectivity over the internet but does not provide the same dedicated physical connectivity model. Cloud CDN and Cloud Run address application delivery and compute. Therefore, Cloud Interconnect should be evaluated for dedicated private hybrid connectivity.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>A development team needs a Kubernetes environment where Google manages much of the underlying infrastructure and node administration, allowing developers to focus primarily on workloads. Which option should it consider?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GKE Standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compute Engine<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GKE Autopilot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Functions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">GKE Autopilot provides a managed Kubernetes experience in which Google handles more infrastructure and node-management responsibilities than in GKE Standard. This can reduce operational overhead for teams that want Kubernetes capabilities without managing as many details of the underlying nodes. GKE Standard provides greater infrastructure-level control and is useful when organizations require customized node configurations or specialized operational requirements. Compute Engine is a VM service, while Cloud Functions is a serverless function platform. Therefore, GKE Autopilot is appropriate when reduced Kubernetes infrastructure management is desired.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>A security team wants to ensure that only container images that have passed defined security requirements can be deployed to production. Which capability should be incorporated into the deployment process?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Binary Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Binary Authorization can help enforce deployment policies for containerized workloads by allowing only images that meet specified authorization requirements to be deployed. It can be integrated into container deployment workflows to strengthen supply-chain controls and reduce the risk of deploying unapproved artifacts. Cloud NAT provides outbound network translation, Cloud Scheduler handles scheduled jobs, and Cloud DNS provides name resolution. Therefore, Binary Authorization should be incorporated when production deployments must be restricted to trusted or approved container images.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>A company wants to route traffic between VPC networks using dynamic routing information exchanged through BGP. Which Google Cloud component provides the routing control plane for this purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Armor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Memorystore<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Router provides dynamic route exchange using Border Gateway Protocol, or BGP, for supported hybrid and network connectivity configurations. It can learn routes from connected environments and advertise Google Cloud routes, allowing routing information to adapt dynamically rather than relying entirely on manually configured static routes. Cloud Storage provides object storage, Cloud Armor protects applications from network threats, and Memorystore provides in-memory caching. Therefore, Cloud Router is the appropriate component when dynamic BGP-based route exchange is required.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>A company has a critical relational application that requires strong consistency across multiple geographic regions and horizontal scaling beyond a traditional single-region database. Which service is designed for this workload?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud SQL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firestore<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Spanner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bigtable<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Spanner is designed for globally distributed relational workloads that require strong consistency and horizontal scalability. It combines relational database capabilities with distributed architecture, making it suitable for applications that need transactional consistency across regions while scaling beyond the limitations of a conventional single-region relational database. Cloud SQL is a managed traditional relational database service, Firestore is document-oriented, and Bigtable uses a wide-column model. Therefore, Cloud Spanner is designed for the stated combination of global distribution, relational transactions, consistency, and scale.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>A company needs to process a continuous stream of events, transform the data in near real time, and write the results into an analytics warehouse. Which service is suitable for the stream-processing stage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dataflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud KMS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Filestore<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dataflow is a managed data-processing service that supports both batch and streaming pipelines. For a continuous event-processing architecture, it can consume streaming data, transform or enrich records, and write processed results to downstream systems such as BigQuery. This removes the need to manage the underlying processing infrastructure while supporting scalable data pipelines. Cloud Storage provides object storage, Cloud KMS manages encryption keys, and Filestore provides managed file storage. Therefore, Dataflow is suitable for the stream-processing stage of this architecture.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>A company stores compliance records that must not be deleted or modified before a specified retention period expires. Which Cloud Storage capability should it investigate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Object Lifecycle Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage Transfer Service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Cloud Storage retention policy can require objects to remain retained for a defined period before they can be deleted or replaced in ways restricted by the policy. This can support compliance requirements where records must be preserved for a minimum retention duration. Object Lifecycle Management serves a different purpose by automating actions such as transitioning or deleting objects according to configured conditions. Cloud CDN provides content delivery, while Storage Transfer Service handles data movement. Therefore, a retention policy should be investigated when records must be preserved for a required period.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>An organization wants to separate development, testing, and production resources so that access permissions, quotas, and billing can be managed independently. What is a suitable architectural approach?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Place everything in one project<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use separate projects for the environments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use only separate Cloud Storage buckets<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use one service account for all teams<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Using separate Google Cloud projects for development, testing, and production can provide clear boundaries for IAM permissions, quotas, billing, APIs, and resource administration. This separation reduces the risk that development activities directly affect production resources and allows organizations to apply different policies to each environment. Merely separating buckets does not provide equivalent project-level isolation, while using one service account across teams can weaken access boundaries. Therefore, separate projects are a suitable approach when environments require independent governance and administration.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>A company wants to expose a privately hosted service to selected consumer VPC networks without requiring the consumers to establish traditional network peering. Which technology should it evaluate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private Service Connect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Trace<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Private Service Connect allows service consumers to access supported services privately from their VPC networks while maintaining a service-oriented connectivity model. It can reduce the need for broad network-level connectivity between the service producer and consumers and can provide more controlled exposure of specific services. This is useful when an organization wants to offer a service privately to selected consumers without establishing traditional VPC Network Peering. Cloud CDN, Cloud Scheduler, and Cloud Trace address content delivery, scheduling, and observability. Therefore, Private Service Connect should be evaluated.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>A production service requires rapid recovery after a regional failure, and the business can tolerate losing up to 30 minutes of recently generated data. Which requirement does the 30-minute figure represent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SLO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SLA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery Point Objective, or RPO, defines the maximum acceptable amount of data loss measured in time. If the business can tolerate losing up to 30 minutes of recently generated data, the recovery design must have an RPO of 30 minutes or better. RTO instead measures the targeted time required to restore service after an outage. SLO describes a service-performance target, while SLA commonly represents a formal service commitment. Therefore, the 30-minute data-loss tolerance represents the RPO requirement.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>A company wants to reduce database load for read-heavy workloads without moving its primary transactional database to another platform. Which architecture can help?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Read replicas<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Read replicas can help distribute read workloads away from a primary database instance. They are useful for applications where many operations are reads and the organization wants to reduce pressure on the primary database while retaining the existing database platform. Applications must account for replication characteristics and potential lag depending on the service and configuration. Cloud NAT provides outbound connectivity, Cloud CDN caches web content, and Cloud Scheduler runs scheduled operations. Therefore, read replicas can help address a read-heavy workload without replacing the primary transactional database.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>A security architect wants to reduce the risk of sensitive data moving from protected Google Cloud resources to unauthorized services or locations. Which control should be evaluated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Service Controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Trace<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Service Controls can create security perimeters around supported Google Cloud services and help reduce the risk of unauthorized data movement across defined trust boundaries. They are particularly relevant for organizations handling sensitive information and seeking additional controls beyond IAM. VPC Service Controls can help address data-exfiltration risks while allowing authorized workloads to interact with protected services according to the configured perimeter design. Cloud CDN, Cloud Scheduler, and Cloud Trace provide content delivery, scheduling, and observability capabilities rather than data-exfiltration protection. Therefore, VPC Service Controls should be evaluated.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>A company wants to improve an existing application by moving it to a managed platform with minimal code changes while reducing responsibility for operating virtual machines. Which migration strategy best describes this approach?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rehost<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retire<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replatform<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Repurchase<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Replatforming involves moving an application to a different or more managed platform while making limited changes to take advantage of improved operational capabilities. For example, an application might move from self-managed infrastructure to a managed service while preserving much of its existing application architecture. Rehosting generally means moving workloads with minimal modification, while retiring removes an unnecessary workload and repurchasing replaces it with a different product or service. Therefore, replatforming best describes modernization through a managed platform with limited application changes.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>A company wants to encrypt sensitive data using keys that it manages through a centralized key-management service. Which Google Cloud service should be used to manage those cryptographic keys?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secret Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud KMS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BigQuery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Key Management Service, or Cloud KMS, provides centralized management of cryptographic keys used by supported Google Cloud services and applications. Organizations can use it to control key creation, rotation, permissions, and lifecycle operations according to their security requirements. Secret Manager is designed for storing sensitive values such as passwords and API credentials rather than managing encryption keys. Cloud Logging collects logs, while BigQuery provides analytics capabilities. Therefore, Cloud KMS should be used when centralized cryptographic key management is required.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>A company is designing a new application and must choose between a globally distributed database, a low-latency cache, and object storage. Which principle should guide the architecture decision?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Select the service with the most features regardless of workload<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use the same database service for every application component<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Match each service to the workload&#8217;s data-access and availability requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Choose the service with the highest possible capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud architecture decisions should be based on workload requirements rather than selecting a service simply because it has the largest feature set or capacity. Different services are optimized for different access patterns, consistency models, latency expectations, scalability requirements, and availability objectives. A globally distributed database, in-memory cache, and object store solve fundamentally different problems and may be used together in one architecture. Therefore, architects should match each service to the application&#8217;s data-access patterns, performance requirements, availability needs, and operational constraints rather than applying one service universally.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Google Professional Cloud Architect Exam Dumps and Practice Test Dumps. &nbsp; Question 381 A company has multiple service projects that need to use centrally managed networking from one host project. Application teams should manage their own resources without creating separate VPC networks. Which architecture is appropriate? VPC Network Peering Shared VPC Cloud VPN [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17017"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17017"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17017\/revisions"}],"predecessor-version":[{"id":17018,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17017\/revisions\/17018"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17017"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17017"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17017"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}