Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial services enterprise is operating several production and staging workloads on Google Cloud. During an architecture review, the cloud architecture team identifies several operational inefficiencies and security concerns:
Which strategy should the cloud architect implement to optimize infrastructure costs and harden the security posture in accordance with Google Cloud best practices?
Pre-encrypt all persistent storage on-premises prior to ingestion and disable Cloud Audit Logs across projects to eliminate logging ingestion costs and reduce API quotas.
Evaluate machine-learning and AI-driven recommendations from IAM Recommender and Active Assist to downscale underutilized resources and enforce least privilege, while implementing VPC Service Controls and Security Command Center for perimeter defense and continuous threat monitoring.
Configure automated Cloud Build CI/CD jobs that ingest all Active Assist findings and immediately apply destructive VM deletions and IAM revocations without administrative approval.
Migrate all workloads to single-zone Spot Virtual Machines and assign primitive Editor roles to administrative groups to minimize runtime costs and reduce administrative overhead.
Pre-encrypt all persistent storage on-premises prior to ingestion and disable Cloud Audit Logs across projects to eliminate logging ingestion costs and reduce API quotas.
Evaluate machine-learning and AI-driven recommendations from IAM Recommender and Active Assist to downscale underutilized resources and enforce least privilege, while implementing VPC Service Controls and Security Command Center for perimeter defense and continuous threat monitoring.
This strategy leverages Active Assist and IAM Recommender alongside core security services (Security Command Center and VPC Service Controls) to continuously evaluate, rightsize, and protect Google Cloud infrastructure. It combines intelligent machine-learning analytics with strict perimeter security and human governance.
This approach adheres directly to the Google Cloud Well-Architected Framework and Secure AI Framework (SAIF) principles by combining data-driven resource optimization with multi-layered defense and governance.
Configure automated Cloud Build CI/CD jobs that ingest all Active Assist findings and immediately apply destructive VM deletions and IAM revocations without administrative approval.
Migrate all workloads to single-zone Spot Virtual Machines and assign primitive Editor roles to administrative groups to minimize runtime costs and reduce administrative overhead.