Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization wants to streamline infrastructure provisioning on Google Cloud while eliminating manual interventions. Currently, engineers execute terraform apply directly from their local workstations, leading to configuration drift and inconsistent environments between staging and production.
The cloud architecture team establishes the following governance and operational requirements:
dev environment prior to promotion to prod.How should you design this automated provisioning workflow?
Migrate all Terraform configurations to Cloud Deployment Manager templates, and configure developers to run gcloud deployment-manager deployments create manually using deployment previews.
Store Terraform state files locally on individual developer workstations, and configure Cloud Build triggers to pull state files over SSH during pipeline execution before deploying to production.
Configure a single Cloud Build trigger on the main branch that executes terraform plan and terraform apply -auto-approve simultaneously against both development and production projects whenever a commit is pushed.
Configure remote Terraform state in a Cloud Storage bucket, create Cloud Build pull request triggers to run terraform plan for automated validation, and configure branch triggers so merging into dev applies changes to the development environment, followed by merging dev into prod to apply changes to production.
Migrate all Terraform configurations to Cloud Deployment Manager templates, and configure developers to run gcloud deployment-manager deployments create manually using deployment previews.
Store Terraform state files locally on individual developer workstations, and configure Cloud Build triggers to pull state files over SSH during pipeline execution before deploying to production.
Configure a single Cloud Build trigger on the main branch that executes terraform plan and terraform apply -auto-approve simultaneously against both development and production projects whenever a commit is pushed.
Configure remote Terraform state in a Cloud Storage bucket, create Cloud Build pull request triggers to run terraform plan for automated validation, and configure branch triggers so merging into dev applies changes to the development environment, followed by merging dev into prod to apply changes to production.
A GitOps infrastructure workflow uses a version-controlled Git repository as the single source of truth for infrastructure configuration, paired with automated CI/CD tools such as Cloud Build to execute Terraform commands predictably and reliably across environments.
terraform plan. Collaborators can inspect the generated execution plan directly on the pull request before any code is merged, preventing unintended changes from entering the codebase.dev to prod): Merging approved pull requests into the dev branch triggers a Cloud Build job that executes terraform apply against the development environment. Once verified in dev, a subsequent pull request merges the dev branch into prod, triggering an automated terraform apply in the production environment.terraform plan) and validated against policies before actuation.This architecture adheres to Google Cloud's recommended GitOps blueprint for Infrastructure as Code. It establishes strict environment isolation, prevents configuration drift, and ensures changes are validated before impacting production workloads.