GCP-PCDE Sample Questions

GCP-PCDE Sample Questions & Answers

Capacity planning and designing for high availability and disaster recovery takes the biggest slice, alongside connectivity and keeping watch across database technologies, planning data migration and replication, and deploying scalable Google Cloud databases.

Launch the full GCP-PCDE simulator →

Showing 8 of 17 free samples.

  1. Question 1Intermediate

    Design Innovative, Scalable, and Highly Available Cloud Database Solutions · High availability and disaster recovery

    A database engineer is designing a disaster recovery strategy for a mission-critical Cloud SQL for MySQL database. The business requires the ability to perform a planned failover (switchover) to a different region with absolutely zero data loss and minimal downtime during regular maintenance drills. Which feature should be implemented?

    Show answer & explanation

    Correct answer: C

    Cloud SQL Enterprise Plus offers Advanced Disaster Recovery. This allows you to designate a DR Replica and perform a 'switchover'. During a switchover, the system automatically ensures zero data loss, demotes the primary, promotes the DR replica, and automatically re-establishes the replication topology in reverse.

  2. Question 2Beginner

    Design Innovative, Scalable, and Highly Available Cloud Database Solutions · High availability and disaster recovery

    True or False: AlloyDB for PostgreSQL secondary clusters located in different regions use synchronous replication to ensure strict global consistency.

    Show answer & explanation

    Correct answer: B

    False. AlloyDB secondary clusters use asynchronous replication based on PostgreSQL's streaming replication. Because it is asynchronous, there is a replication lag, meaning it provides eventual consistency across regions, not strict global consistency.

  3. Question 3Beginner

    Design Innovative, Scalable, and Highly Available Cloud Database Solutions · High availability and disaster recovery

    An organization is using a multi-cluster Cloud Bigtable instance to serve a globally distributed application. They want to ensure that reads are always strongly consistent (Read-Your-Writes) for individual users, even if a cluster fails. Which App Profile configuration is required?

    Show answer & explanation

    Correct answer: A

    To achieve strong consistency (Read-Your-Writes) in Bigtable, you must use an App Profile configured for single-cluster routing. This ensures that a specific client's reads and writes all go to the exact same cluster, avoiding replication lag.

  4. Question 4Intermediate

    Design Innovative, Scalable, and Highly Available Cloud Database Solutions · Application database connectivity

    A cloud architect is designing the network connectivity for a fleet of 50 Cloud SQL instances across multiple VPCs. The security team mandates that all traffic remain on internal IP addresses. The architect must choose between Private Service Access (PSA) and Private Service Connect (PSC). Which of the following is a critical limitation of PSA that PSC resolves in this scenario?

    Show answer & explanation

    Correct answer: B

    Private Service Access (PSA) relies on VPC peering and requires allocating a contiguous range of IP addresses (often a /16 or /24) to the Google managed services VPC. In large environments, this quickly leads to IP exhaustion. Private Service Connect (PSC) solves this by mapping the database to a single IP address (endpoint) in your VPC.

  5. Question 5Advanced

    Design Innovative, Scalable, and Highly Available Cloud Database Solutions · Application database connectivity

    An enterprise organization uses a Shared VPC architecture. The Host Project contains the network infrastructure, and multiple Service Projects contain application workloads. A Database Engineer needs to deploy an AlloyDB cluster in 'Service Project A' and make it securely accessible to applications in 'Service Project B'. The IP ranges of the two service projects overlap. Which connectivity architecture should be used?

    Show answer & explanation

    Correct answer: B

    Private Service Connect (PSC) is the ideal solution for this scenario. PSC allows you to consume services across different VPC networks (even with overlapping IP ranges) by creating a localized endpoint in the consumer network that privately maps to the producer service.

  6. Question 6Beginner

    Design Innovative, Scalable, and Highly Available Cloud Database Solutions · Application database connectivity

    To securely connect a serverless Cloud Run application to a Cloud SQL instance using IAM database authentication, the developer must configure the Cloud SQL Auth Proxy sidecar. The command to start the proxy must include the ________ flag to instruct the proxy to request ephemeral IAM tokens.

    Show answer & explanation

    Correct answer: B

    The --enable-iam-auth flag (or -i in older versions) must be passed to the Cloud SQL Auth Proxy. This instructs the proxy to automatically request an ephemeral, short-lived OAuth 2.0 token from the Google Cloud IAM service and use it as the database password.

  7. Question 7Intermediate

    Design Innovative, Scalable, and Highly Available Cloud Database Solutions · Application database connectivity

    A healthcare organization stores highly sensitive Patient Health Information (PHI) in Cloud Spanner. To comply with strict regulatory requirements, the security team mandates that even if a user has valid IAM credentials (e.g., roles/spanner.databaseAdmin), they must be physically located within the corporate network to access the data. Which Google Cloud security control should be implemented to enforce this?

    Show answer & explanation

    Correct answer: D

    VPC Service Controls (VPC-SC) creates a secure perimeter around Google Cloud managed services like Spanner. It evaluates context (like source IP, device identity) before allowing access to the API, preventing data exfiltration even if the user possesses valid IAM credentials but is outside the allowed perimeter.

  8. Question 8AdvancedSelect 2

    Design Innovative, Scalable, and Highly Available Cloud Database Solutions · Application database connectivity

    A government agency requires absolute cryptographic control over their Cloud SQL databases. They have mandated the use of Customer-Managed Encryption Keys (CMEK). Which TWO of the following statements are correct regarding the implementation and limitations of CMEK with Cloud SQL? (Select TWO)

    Show answer & explanation

    Correct answers: C, D

    This is a strict requirement. For performance and regulatory reasons, the Cloud KMS key used for CMEK must reside in the exact same geographic region as the Cloud SQL instance it encrypts.

    This is the primary security benefit of CMEK (crypto-shredding). If the key is revoked, destroyed, or disabled in Cloud KMS, Cloud SQL loses access to the data, and the instance enters a suspended state, making data inaccessible.

Ready for the real thing?

The full GCP-PCDE simulator has every exam-style question, timed mode, and instant scoring.