Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise operates a hybrid production workload where web frontend services run on Google Cloud and backend database services reside in an on-premises data center. During peak hours, users experience intermittent timeouts and transaction failures, requiring the operations team to analyze system logs and metrics to identify performance bottlenecks and determine root causes.
Strict compliance policies mandate that sensitive customer transaction payloads contained in application logs must remain stored exclusively on-premises. However, infrastructure health metrics and operational system logs must be centralized in Google Cloud Logging and Cloud Monitoring to facilitate unified alerting and diagnostic dashboards.
Which telemetry architecture should the cloud architect implement to meet these requirements?
Configure Fluentd on all on-premises servers to export all logs directly to Cloud Logging via Cloud Pub/Sub, then configure Cloud IAM policies to restrict access to payload fields
Deploy OpenTelemetry Collector or BindPlane agents to filter and store sensitive application logs on-premises, while streaming operational system logs and performance metrics to Cloud Logging and Cloud Monitoring
Enable VPC Flow Logs and Google Cloud Armor on cloud networks to inspect Layer 7 application payloads and filter out sensitive transaction fields before logs enter Cloud Monitoring
Deploy Prometheus and Grafana on-premises to collect and store all hybrid telemetry locally, and grant Google Cloud Support access to on-premises instances for root-cause diagnosis
Configure Fluentd on all on-premises servers to export all logs directly to Cloud Logging via Cloud Pub/Sub, then configure Cloud IAM policies to restrict access to payload fields
Deploy OpenTelemetry Collector or BindPlane agents to filter and store sensitive application logs on-premises, while streaming operational system logs and performance metrics to Cloud Logging and Cloud Monitoring
OpenTelemetry Collector and observIQ BindPlane are telemetry pipeline solutions designed to collect, process, transform, and route observability data—including logs, metrics, and traces—from diverse hybrid and multi-cloud environments to designated storage and analysis backends.
Separating application and system data at the collection layer ensures absolute compliance with strict data residency rules while giving SRE and operations teams the necessary operational telemetry in Cloud Monitoring and Cloud Logging to pinpoint and resolve hybrid system bottlenecks.
Enable VPC Flow Logs and Google Cloud Armor on cloud networks to inspect Layer 7 application payloads and filter out sensitive transaction fields before logs enter Cloud Monitoring
Deploy Prometheus and Grafana on-premises to collect and store all hybrid telemetry locally, and grant Google Cloud Support access to on-premises instances for root-cause diagnosis