Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise runs microservice workloads across Google Kubernetes Engine (GKE) on Google Cloud, on-premises VMware environments, and AWS. The organization requires a centralized management strategy to achieve the following goals:
Which combination of GKE Enterprise capabilities should the cloud architect recommend?
Deploy Knative serving across all external virtual machines, establish Cloud Interconnect for configuration syncing, use Binary Authorization to enforce runtime policies, and collect telemetry using Container Threat Detection.
Group the clusters into a GKE fleet, use Config Sync and Policy Controller for configuration and compliance, and deploy Cloud Service Mesh for mTLS and telemetry.
Migrate all workloads to Google Cloud VMware Engine, manage cluster manifests using Config Connector, enforce security with Container-Optimized OS, and expose internal services via the Connect gateway with HTTP load balancing.
Connect all clusters using VPC Network Peering, configure Deployment Manager for cluster synchronization, apply IAM custom roles for policy governance, and implement Cloud NAT for mTLS communications.
Deploy Knative serving across all external virtual machines, establish Cloud Interconnect for configuration syncing, use Binary Authorization to enforce runtime policies, and collect telemetry using Container Threat Detection.
Group the clusters into a GKE fleet, use Config Sync and Policy Controller for configuration and compliance, and deploy Cloud Service Mesh for mTLS and telemetry.
GKE Enterprise (formerly Anthos) provides an integrated hybrid and multicloud application platform. It enables organizations to run, manage, and secure Kubernetes workloads across Google Cloud, on-premises data centers, and third-party clouds such as AWS and Azure through a unified control plane.
This architecture utilizes native GKE Enterprise features specifically built for hybrid and multicloud governance. It avoids custom operational tooling and delivers unified multi-cluster policy enforcement, declarative synchronization, and cross-cluster service mesh security.
Migrate all workloads to Google Cloud VMware Engine, manage cluster manifests using Config Connector, enforce security with Container-Optimized OS, and expose internal services via the Connect gateway with HTTP load balancing.
Connect all clusters using VPC Network Peering, configure Deployment Manager for cluster synchronization, apply IAM custom roles for policy governance, and implement Cloud NAT for mTLS communications.