PRACTICE TRACK / 105 QUESTIONS

GCP
Think it through.

Google Cloud architecture, networking, IAM, and SRE operations.

Choose a question, explain your approach, then reveal the supplied answer. Difficulty labels come from the existing question library.

105 questions

Answers stay closed until you choose to reveal them.

QUESTION 01GCPEasy

What is the difference between a GCP project, folder, and organization?

#
Reveal answer guidance

The organization is the top-level resource tied to a company identity domain. Folders group projects by team, environment, or business unit. Projects are the main isolation and billing boundary where APIs, IAM bindings, quotas, and resources live. Mature GCP design uses folders and projects to separate ownership, environments, and blast radius.

QUESTION 02GCPMedium

How does a service account differ from a user account in GCP?

#
Reveal answer guidance

A user account represents a human identity. A service account represents a workload identity used by VMs, GKE, Cloud Run, Cloud Build, or automation. Service accounts should be granted least-privilege IAM roles and used through workload identity or impersonation rather than downloaded long-lived keys.

QUESTION 03GCPMedium

What is Private Google Access and when do you use it?

#
Reveal answer guidance

Private Google Access lets VMs without external IP addresses reach Google APIs over internal Google network paths when subnet and DNS/routing are configured correctly. Use it for private workloads that need services like Cloud Storage, Artifact Registry, or BigQuery without public internet egress.

QUESTION 04GCPHard

How do you design a production GKE cluster for least privilege?

#
Reveal answer guidance

Use private clusters where appropriate, Workload Identity for pod-to-service-account mapping, namespace isolation, RBAC, network policies, limited node service account roles, Binary Authorization or admission policies for image control, and separate node pools for workloads with different trust or resource profiles.

QUESTION 05GCPHard

A Cloud SQL database must support production failover. What controls matter beyond enabling HA?

#
Reveal answer guidance

You need tested failover behavior, connection pooling, backup/PITR verification, maintenance windows, alerting, application retry handling, schema migration controls, and restore drills. HA reduces zonal failure impact, but it does not replace backup validation or application-level resilience.

QUESTION 06GCPHard

GCP incident: Users in one region see 502s while backends in another region are healthy. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Cloud Load Balancing backend health, URL maps, firewall rules, NEG status, and Cloud Logging. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Validate backend health per region, firewall source ranges, URL map routing, CDN/cache behavior, and failover policy. Keep direct backend access closed.

QUESTION 07GCPHard

GCP architecture scenario: Design global HTTPS load balancing for multi-region services. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Validate backend health per region, firewall source ranges, URL map routing, CDN/cache behavior, and failover policy. Keep direct backend access closed.

QUESTION 08GCPMedium

GCP security scenario: Backend services expose instances directly. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Validate backend health per region, firewall source ranges, URL map routing, CDN/cache behavior, and failover policy. Keep direct backend access closed.

QUESTION 09GCPHard

GCP release scenario: Move from regional ingress to global load balancing. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Validate backend health per region, firewall source ranges, URL map routing, CDN/cache behavior, and failover policy. Keep direct backend access closed.

QUESTION 10GCPMedium

GCP reliability/cost scenario: Cross-region egress costs are higher than expected. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Validate backend health per region, firewall source ranges, URL map routing, CDN/cache behavior, and failover policy. Keep direct backend access closed.

QUESTION 11GCPHard

GCP incident: A Cloud Run service works locally but fails to access Pub/Sub in production. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Cloud Audit Logs, Policy Troubleshooter, IAM bindings, service account impersonation checks, and denied permission messages. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Use one service account per workload, grant resource-level roles where possible, avoid project Editor, and use impersonation for CI/CD instead of downloaded keys.

QUESTION 12GCPHard

GCP architecture scenario: Design least-privilege service account access. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Use one service account per workload, grant resource-level roles where possible, avoid project Editor, and use impersonation for CI/CD instead of downloaded keys.

QUESTION 13GCPMedium

GCP security scenario: Broad project-level roles grant excessive access. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Use one service account per workload, grant resource-level roles where possible, avoid project Editor, and use impersonation for CI/CD instead of downloaded keys.

QUESTION 14GCPHard

GCP release scenario: Replace Editor roles with scoped predefined or custom roles. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Use one service account per workload, grant resource-level roles where possible, avoid project Editor, and use impersonation for CI/CD instead of downloaded keys.

QUESTION 15GCPMedium

GCP reliability/cost scenario: IAM sprawl makes audits slow. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Use one service account per workload, grant resource-level roles where possible, avoid project Editor, and use impersonation for CI/CD instead of downloaded keys.

QUESTION 16GCPHard

GCP incident: A VM in a private subnet cannot reach Google APIs. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: routes, firewall rules, Private Google Access setting, Cloud NAT logs, DNS policy, and VPC Flow Logs. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Check subnet settings, DNS resolution, routes, firewall, and service-specific private access. Use Private Google Access/PSC before defaulting to internet egress.

QUESTION 17GCPHard

GCP architecture scenario: Design private access to Google managed services. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Check subnet settings, DNS resolution, routes, firewall, and service-specific private access. Use Private Google Access/PSC before defaulting to internet egress.

QUESTION 18GCPMedium

GCP security scenario: Public IPs are added to private workloads. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Check subnet settings, DNS resolution, routes, firewall, and service-specific private access. Use Private Google Access/PSC before defaulting to internet egress.

QUESTION 19GCPHard

GCP release scenario: Enable Private Google Access and private service connectivity. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Check subnet settings, DNS resolution, routes, firewall, and service-specific private access. Use Private Google Access/PSC before defaulting to internet egress.

QUESTION 20GCPMedium

GCP reliability/cost scenario: NAT egress costs are growing. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Check subnet settings, DNS resolution, routes, firewall, and service-specific private access. Use Private Google Access/PSC before defaulting to internet egress.

QUESTION 21GCPHard

GCP incident: A GKE node pool upgrade disrupts critical pods. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: GKE events, PDBs, node pool surge settings, scheduler events, and cluster autoscaler logs. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Use PDBs, surge upgrades, workload identity, namespace isolation, cluster autoscaling, and staging validation before production upgrades.

QUESTION 22GCPHard

GCP architecture scenario: Design a multi-tenant GKE platform. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Use PDBs, surge upgrades, workload identity, namespace isolation, cluster autoscaling, and staging validation before production upgrades.

QUESTION 23GCPMedium

GCP security scenario: Workload Identity is not used and node service accounts are overpowered. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Use PDBs, surge upgrades, workload identity, namespace isolation, cluster autoscaling, and staging validation before production upgrades.

QUESTION 24GCPHard

GCP release scenario: Upgrade cluster and node pools safely. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Use PDBs, surge upgrades, workload identity, namespace isolation, cluster autoscaling, and staging validation before production upgrades.

QUESTION 25GCPMedium

GCP reliability/cost scenario: Overprovisioned nodes increase monthly cost. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Use PDBs, surge upgrades, workload identity, namespace isolation, cluster autoscaling, and staging validation before production upgrades.

QUESTION 26GCPHard

GCP incident: Cloud SQL failover causes longer downtime than expected. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Cloud SQL operations, database logs, connection count, failover events, and query insights. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Use HA for zonal failure, test failover behavior, tune connection pooling, back up and restore regularly, and separate app roles by privilege.

QUESTION 27GCPHard

GCP architecture scenario: Design a resilient database tier on GCP. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Use HA for zonal failure, test failover behavior, tune connection pooling, back up and restore regularly, and separate app roles by privilege.

QUESTION 28GCPMedium

GCP security scenario: Application credentials have excessive database privileges. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Use HA for zonal failure, test failover behavior, tune connection pooling, back up and restore regularly, and separate app roles by privilege.

QUESTION 29GCPHard

GCP release scenario: Enable HA and read replicas for an existing database. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Use HA for zonal failure, test failover behavior, tune connection pooling, back up and restore regularly, and separate app roles by privilege.

QUESTION 30GCPMedium

GCP reliability/cost scenario: Cloud SQL CPU and storage costs keep increasing. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Use HA for zonal failure, test failover behavior, tune connection pooling, back up and restore regularly, and separate app roles by privilege.

QUESTION 31GCPHard

GCP incident: Messages are delivered multiple times and downstream creates duplicates. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: subscription backlog, ack deadline, delivery attempts, dead-letter metrics, and consumer logs. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Make consumers idempotent, tune ack deadlines, use dead-letter topics, avoid large sensitive payloads, and monitor oldest unacked message age.

QUESTION 32GCPHard

GCP architecture scenario: Design event processing with at-least-once delivery. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Make consumers idempotent, tune ack deadlines, use dead-letter topics, avoid large sensitive payloads, and monitor oldest unacked message age.

QUESTION 33GCPMedium

GCP security scenario: Messages contain sensitive data without retention controls. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Make consumers idempotent, tune ack deadlines, use dead-letter topics, avoid large sensitive payloads, and monitor oldest unacked message age.

QUESTION 34GCPHard

GCP release scenario: Add dead-letter topics and retry policies. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Make consumers idempotent, tune ack deadlines, use dead-letter topics, avoid large sensitive payloads, and monitor oldest unacked message age.

QUESTION 35GCPMedium

GCP reliability/cost scenario: Backlog growth increases processing cost. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Make consumers idempotent, tune ack deadlines, use dead-letter topics, avoid large sensitive payloads, and monitor oldest unacked message age.

QUESTION 36GCPHard

GCP incident: P99 latency spikes after idle periods. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Cloud Run revision metrics, cold start timing, concurrency, CPU allocation, and request logs. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Tune concurrency, min instances, CPU allocation, startup work, and auth. Separate latency-sensitive APIs from background jobs.

QUESTION 37GCPHard

GCP architecture scenario: Design serverless containers for APIs and background workers. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Tune concurrency, min instances, CPU allocation, startup work, and auth. Separate latency-sensitive APIs from background jobs.

QUESTION 38GCPMedium

GCP security scenario: Unauthenticated invocations expose internal services. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Tune concurrency, min instances, CPU allocation, startup work, and auth. Separate latency-sensitive APIs from background jobs.

QUESTION 39GCPHard

GCP release scenario: Move a container service from GKE to Cloud Run. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Tune concurrency, min instances, CPU allocation, startup work, and auth. Separate latency-sensitive APIs from background jobs.

QUESTION 40GCPMedium

GCP reliability/cost scenario: Min instances improve latency but raise cost. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Tune concurrency, min instances, CPU allocation, startup work, and auth. Separate latency-sensitive APIs from background jobs.

QUESTION 41GCPHard

GCP incident: Objects are accidentally made public through IAM or ACLs. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: bucket IAM, public access prevention, ACL status, access logs, lifecycle rules, and CDN logs. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Use uniform bucket-level access, public access prevention, signed URLs where needed, lifecycle policies, and CDN caching for public content.

QUESTION 42GCPHard

GCP architecture scenario: Design secure object storage and CDN delivery. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Use uniform bucket-level access, public access prevention, signed URLs where needed, lifecycle policies, and CDN caching for public content.

QUESTION 43GCPMedium

GCP security scenario: Legacy ACLs bypass intended IAM controls. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Use uniform bucket-level access, public access prevention, signed URLs where needed, lifecycle policies, and CDN caching for public content.

QUESTION 44GCPHard

GCP release scenario: Migrate buckets to uniform bucket-level access. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Use uniform bucket-level access, public access prevention, signed URLs where needed, lifecycle policies, and CDN caching for public content.

QUESTION 45GCPMedium

GCP reliability/cost scenario: Storage class and egress costs are high. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Use uniform bucket-level access, public access prevention, signed URLs where needed, lifecycle policies, and CDN caching for public content.

QUESTION 46GCPHard

GCP incident: A dashboard query suddenly costs much more and runs slowly. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: query plan, bytes processed, partition filters, slot usage, audit logs, and table metadata. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Partition and cluster by access pattern, require partition filters, use authorized views or column policies, and label jobs for cost ownership.

QUESTION 47GCPHard

GCP architecture scenario: Design governed analytics datasets. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Partition and cluster by access pattern, require partition filters, use authorized views or column policies, and label jobs for cost ownership.

QUESTION 48GCPMedium

GCP security scenario: Users can query sensitive columns directly. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Partition and cluster by access pattern, require partition filters, use authorized views or column policies, and label jobs for cost ownership.

QUESTION 49GCPHard

GCP release scenario: Introduce partitioning, clustering, and authorized views. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Partition and cluster by access pattern, require partition filters, use authorized views or column policies, and label jobs for cost ownership.

QUESTION 50GCPMedium

GCP reliability/cost scenario: BigQuery spend is hard to attribute. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Partition and cluster by access pattern, require partition filters, use authorized views or column policies, and label jobs for cost ownership.

QUESTION 51GCPHard

GCP incident: A bot spike overloads the backend despite autoscaling. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Cloud Armor logs, sampled requests, load balancer metrics, backend saturation, and rule match data. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Start rules in preview, tune false positives, rate limit targeted paths, combine geo/IP/user-agent signals carefully, and keep rollback procedures.

QUESTION 52GCPHard

GCP architecture scenario: Design edge protection for public HTTP services. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Start rules in preview, tune false positives, rate limit targeted paths, combine geo/IP/user-agent signals carefully, and keep rollback procedures.

QUESTION 53GCPMedium

GCP security scenario: WAF rules block legitimate users. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Start rules in preview, tune false positives, rate limit targeted paths, combine geo/IP/user-agent signals carefully, and keep rollback procedures.

QUESTION 54GCPHard

GCP release scenario: Move Cloud Armor rules from preview to enforce. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Start rules in preview, tune false positives, rate limit targeted paths, combine geo/IP/user-agent signals carefully, and keep rollback procedures.

QUESTION 55GCPMedium

GCP reliability/cost scenario: Abusive traffic increases backend and logging costs. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Start rules in preview, tune false positives, rate limit targeted paths, combine geo/IP/user-agent signals carefully, and keep rollback procedures.

QUESTION 56GCPHard

GCP incident: Private workloads intermittently fail outbound connections. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Cloud NAT metrics, port allocation errors, VPC Flow Logs, route tables, and connection reuse metrics. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Tune NAT port allocation, reduce connection churn, use private access for Google APIs, and alert on dropped packets and port exhaustion.

QUESTION 57GCPHard

GCP architecture scenario: Design reliable private outbound egress. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Tune NAT port allocation, reduce connection churn, use private access for Google APIs, and alert on dropped packets and port exhaustion.

QUESTION 58GCPMedium

GCP security scenario: NAT logs reveal sensitive destination patterns. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Tune NAT port allocation, reduce connection churn, use private access for Google APIs, and alert on dropped packets and port exhaustion.

QUESTION 59GCPHard

GCP release scenario: Move private subnets behind Cloud NAT. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Tune NAT port allocation, reduce connection churn, use private access for Google APIs, and alert on dropped packets and port exhaustion.

QUESTION 60GCPMedium

GCP reliability/cost scenario: NAT port allocation and egress costs grow. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Tune NAT port allocation, reduce connection churn, use private access for Google APIs, and alert on dropped packets and port exhaustion.

QUESTION 61GCPHard

GCP incident: A rotated secret breaks a deployed service. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Secret version state, IAM bindings, access logs, workload identity, and application errors. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Grant access per secret, use workload identity, cache secrets with short TTL, rotate with overlapping versions, and never bake secrets into images.

QUESTION 62GCPHard

GCP architecture scenario: Design secret rotation across GCP workloads. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Grant access per secret, use workload identity, cache secrets with short TTL, rotate with overlapping versions, and never bake secrets into images.

QUESTION 63GCPMedium

GCP security scenario: Secrets are stored in container images or Terraform state. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Grant access per secret, use workload identity, cache secrets with short TTL, rotate with overlapping versions, and never bake secrets into images.

QUESTION 64GCPHard

GCP release scenario: Move environment secrets into Secret Manager. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Grant access per secret, use workload identity, cache secrets with short TTL, rotate with overlapping versions, and never bake secrets into images.

QUESTION 65GCPMedium

GCP reliability/cost scenario: Secret access calls are noisy and hard to audit. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Grant access per secret, use workload identity, cache secrets with short TTL, rotate with overlapping versions, and never bake secrets into images.

QUESTION 66GCPHard

GCP incident: An incident occurs but alerting only catches infrastructure symptoms. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Cloud Monitoring metrics, log-based metrics, Error Reporting, Trace, alert history, and log sinks. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Alert on user impact and saturation, sample verbose logs, redact sensitive fields, export long-retention logs to cheaper storage, and use SLO burn rates.

QUESTION 67GCPHard

GCP architecture scenario: Design service-level monitoring on GCP. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Alert on user impact and saturation, sample verbose logs, redact sensitive fields, export long-retention logs to cheaper storage, and use SLO burn rates.

QUESTION 68GCPMedium

GCP security scenario: Logs contain sensitive request payloads. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Alert on user impact and saturation, sample verbose logs, redact sensitive fields, export long-retention logs to cheaper storage, and use SLO burn rates.

QUESTION 69GCPHard

GCP release scenario: Introduce SLO burn-rate alerts. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Alert on user impact and saturation, sample verbose logs, redact sensitive fields, export long-retention logs to cheaper storage, and use SLO burn rates.

QUESTION 70GCPMedium

GCP reliability/cost scenario: Cloud Logging ingestion costs are high. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Alert on user impact and saturation, sample verbose logs, redact sensitive fields, export long-retention logs to cheaper storage, and use SLO burn rates.

QUESTION 71GCPHard

GCP incident: Teams create resources in the wrong project and lose cost visibility. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Resource hierarchy, IAM policy, org policies, billing export, labels, and audit logs. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Use folders/projects by environment and ownership, enforce org policies, require labels, centralize billing export, and avoid dumping unrelated workloads into one project.

QUESTION 72GCPHard

GCP architecture scenario: Design project/folder structure for environments and teams. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Use folders/projects by environment and ownership, enforce org policies, require labels, centralize billing export, and avoid dumping unrelated workloads into one project.

QUESTION 73GCPMedium

GCP security scenario: Organization policies are missing or inconsistent. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Use folders/projects by environment and ownership, enforce org policies, require labels, centralize billing export, and avoid dumping unrelated workloads into one project.

QUESTION 74GCPHard

GCP release scenario: Move workloads into standardized projects. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Use folders/projects by environment and ownership, enforce org policies, require labels, centralize billing export, and avoid dumping unrelated workloads into one project.

QUESTION 75GCPMedium

GCP reliability/cost scenario: Shared projects make chargeback difficult. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Use folders/projects by environment and ownership, enforce org policies, require labels, centralize billing export, and avoid dumping unrelated workloads into one project.

QUESTION 76GCPHard

GCP incident: A build can deploy to production from an untrusted branch. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Cloud Build triggers, service account roles, approval gates, Artifact Registry usage, and audit logs. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Use protected triggers, minimal deploy roles, approvals for production, artifact provenance, and retention policies for old images.

QUESTION 77GCPHard

GCP architecture scenario: Design secure CI/CD on GCP. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Use protected triggers, minimal deploy roles, approvals for production, artifact provenance, and retention policies for old images.

QUESTION 78GCPMedium

GCP security scenario: Build service accounts have broad project permissions. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Use protected triggers, minimal deploy roles, approvals for production, artifact provenance, and retention policies for old images.

QUESTION 79GCPHard

GCP release scenario: Move deployments to service account impersonation. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Use protected triggers, minimal deploy roles, approvals for production, artifact provenance, and retention policies for old images.

QUESTION 80GCPMedium

GCP reliability/cost scenario: Build minutes and artifact storage costs are increasing. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Use protected triggers, minimal deploy roles, approvals for production, artifact provenance, and retention policies for old images.

QUESTION 81GCPHard

GCP incident: Deployments pull mutable image tags and rollbacks are unreliable. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: image digests, repository IAM, vulnerability scans, cleanup policies, and deploy manifests. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Promote immutable digests, scope repository IAM, enable scanning, sign artifacts where required, and apply cleanup policies by environment.

QUESTION 82GCPHard

GCP architecture scenario: Design container artifact promotion. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Promote immutable digests, scope repository IAM, enable scanning, sign artifacts where required, and apply cleanup policies by environment.

QUESTION 83GCPMedium

GCP security scenario: Repositories allow unauthenticated or broad pull access. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Promote immutable digests, scope repository IAM, enable scanning, sign artifacts where required, and apply cleanup policies by environment.

QUESTION 84GCPHard

GCP release scenario: Move from Container Registry to Artifact Registry. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Promote immutable digests, scope repository IAM, enable scanning, sign artifacts where required, and apply cleanup policies by environment.

QUESTION 85GCPMedium

GCP reliability/cost scenario: Old images consume storage. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Promote immutable digests, scope repository IAM, enable scanning, sign artifacts where required, and apply cleanup policies by environment.

QUESTION 86GCPHard

GCP incident: A streaming pipeline falls behind after traffic increases. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: Dataflow backlog, system lag, worker CPU, autoscaling events, Pub/Sub metrics, and error logs. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Inspect source backlog, worker saturation, hot keys, windowing, and sink throughput. Tune autoscaling and fix data skew before simply adding workers.

QUESTION 87GCPHard

GCP architecture scenario: Design scalable data processing on GCP. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Inspect source backlog, worker saturation, hot keys, windowing, and sink throughput. Tune autoscaling and fix data skew before simply adding workers.

QUESTION 88GCPMedium

GCP security scenario: Pipeline workers can access broader data than required. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Inspect source backlog, worker saturation, hot keys, windowing, and sink throughput. Tune autoscaling and fix data skew before simply adding workers.

QUESTION 89GCPHard

GCP release scenario: Change worker sizing and autoscaling settings. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Inspect source backlog, worker saturation, hot keys, windowing, and sink throughput. Tune autoscaling and fix data skew before simply adding workers.

QUESTION 90GCPMedium

GCP reliability/cost scenario: Streaming costs rise faster than event volume. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Inspect source backlog, worker saturation, hot keys, windowing, and sink throughput. Tune autoscaling and fix data skew before simply adding workers.

QUESTION 91GCPHard

GCP incident: Global users see inconsistent latency and transaction contention. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: query latency, transaction aborts, key distribution, schema design, and capacity metrics. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Choose based on consistency, access pattern, transaction needs, and scale. Avoid hot keys, test migrations, and model cost under real traffic.

QUESTION 92GCPHard

GCP architecture scenario: Choose between Cloud SQL, Spanner, Firestore, and Bigtable. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Choose based on consistency, access pattern, transaction needs, and scale. Avoid hot keys, test migrations, and model cost under real traffic.

QUESTION 93GCPMedium

GCP security scenario: Database IAM and application roles are not separated. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Choose based on consistency, access pattern, transaction needs, and scale. Avoid hot keys, test migrations, and model cost under real traffic.

QUESTION 94GCPHard

GCP release scenario: Migrate a workload to a globally scalable database. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Choose based on consistency, access pattern, transaction needs, and scale. Avoid hot keys, test migrations, and model cost under real traffic.

QUESTION 95GCPMedium

GCP reliability/cost scenario: Provisioned capacity is expensive for uneven traffic. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Choose based on consistency, access pattern, transaction needs, and scale. Avoid hot keys, test migrations, and model cost under real traffic.

QUESTION 96GCPHard

GCP incident: A certificate renewal fails and HTTPS breaks. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: certificate status, DNS records, load balancer config, Certificate Manager events, and browser errors. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Use managed certificates where possible, validate DNS ownership, monitor expiry/status, and keep DNS changes reviewed with rollback.

QUESTION 97GCPHard

GCP architecture scenario: Design managed TLS and DNS for public services. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Use managed certificates where possible, validate DNS ownership, monitor expiry/status, and keep DNS changes reviewed with rollback.

QUESTION 98GCPMedium

GCP security scenario: DNS ownership is split across teams with no change control. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Use managed certificates where possible, validate DNS ownership, monitor expiry/status, and keep DNS changes reviewed with rollback.

QUESTION 99GCPHard

GCP release scenario: Move custom certs to managed certificates. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Use managed certificates where possible, validate DNS ownership, monitor expiry/status, and keep DNS changes reviewed with rollback.

QUESTION 100GCPMedium

GCP reliability/cost scenario: Manual certificate operations consume on-call time. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Use managed certificates where possible, validate DNS ownership, monitor expiry/status, and keep DNS changes reviewed with rollback.

QUESTION 101GCPHard

GCP incident: A regional quota blocks autoscaling during a traffic spike. How do you investigate, recover service, and prevent the same failure?

#
Reveal answer guidance

Start by proving scope and recent change: quota metrics, autoscaler events, capacity forecasts, regional usage, and launch plan assumptions. Check logs, metrics, health checks, dependency errors, and config drift before changing anything. Recover with the smallest reversible action, then document the root cause. Prevention: Monitor critical quotas, request increases ahead of launches, distribute capacity across regions/zones, and treat quota as part of reliability design.

QUESTION 102GCPHard

GCP architecture scenario: Design quota-aware production capacity. What design would you choose, and what tradeoffs would you call out in an interview?

#
Reveal answer guidance

Design for failure domains, rollback, observability, and least privilege first. Validate capacity, limits, network paths, and operational ownership. The practical answer is not one service or command; it is the architecture plus the runbook. For this scenario: Monitor critical quotas, request increases ahead of launches, distribute capacity across regions/zones, and treat quota as part of reliability design.

QUESTION 103GCPMedium

GCP security scenario: Emergency quota increases bypass approval. How do you harden it without breaking production?

#
Reveal answer guidance

Baseline current behavior, add guardrails in report-only or staged mode where possible, and test the highest-risk paths first. Roll out with logs, alerts, and a rollback plan. Use least privilege, explicit ownership, and automated checks. For this scenario: Monitor critical quotas, request increases ahead of launches, distribute capacity across regions/zones, and treat quota as part of reliability design.

QUESTION 104GCPHard

GCP release scenario: Add quota monitoring before a launch. How do you ship the change safely?

#
Reveal answer guidance

Separate build, deploy, validation, and cutover. Use canary or blue/green where possible, keep the old path available until health checks pass, and define rollback before starting. Watch saturation, errors, latency, and user-facing checks. For this scenario: Monitor critical quotas, request increases ahead of launches, distribute capacity across regions/zones, and treat quota as part of reliability design.

QUESTION 105GCPMedium

GCP reliability/cost scenario: Reserved capacity increases idle cost. What signals do you inspect and what changes do you make?

#
Reveal answer guidance

Look at utilization, error rate, latency, queue depth, throttling, quota, retry volume, and recent deployment history. Optimize the bottleneck rather than guessing. Prefer rightsizing, caching, batching, and lifecycle policies before broad rewrites. For this scenario: Monitor critical quotas, request increases ahead of launches, distribute capacity across regions/zones, and treat quota as part of reliability design.

CONTINUE PRACTICING

Try another perspective.