Skip to content

Google Cloud Professional Cloud Architect - Fact Sheet

Quick Reference

Exam Code: Professional Cloud Architect Duration: 120 minutes (2 hours) Questions: 50-60 questions Passing Score: ~70% (not officially published) Cost: $200 USD Validity: 2 years Difficulty: ⭐⭐⭐⭐⭐ (Most challenging GCP certification) Prerequisites: Recommended 3+ years of industry experience, including 1+ year designing GCP solutions

Exam Domains

Domain Weight Key Focus
Designing and planning a cloud solution architecture 24% Business requirements, application design, infrastructure design
Managing and provisioning solution infrastructure 15% Network topology, storage, compute resources
Designing for security and compliance 18% Identity and access, data protection, separation of duties
Analyzing and optimizing technical and business processes 17% Technical analysis, business analysis, procedures
Managing implementation 10% Advising development teams, managing changes
Ensuring solution and operations reliability 16% Monitoring, logging, incident response, supporting product launches

Core Architecture Principles

Well-Architected Framework

πŸ“– Google Cloud Architecture Framework - Complete architecture framework

Five Pillars: 1. Operational Excellence - Efficient operations and monitoring 2. Security, Privacy, and Compliance - Protection and governance 3. Reliability - Availability and fault tolerance 4. Cost Optimization - Resource efficiency and financial governance 5. Performance Optimization - Efficient resource use and scaling

Key Resources: - πŸ“– Architecture Center - Reference architectures and diagrams - πŸ“– Best Practices - Enterprise design patterns - πŸ“– Cloud Architecture Patterns - System design patterns - πŸ“– Decision Trees - Architecture decision guides

Compute Services - Architecture Deep Dive

Compute Engine

Strategic Use Cases: - Legacy application migrations (lift-and-shift) - Custom operating systems or kernels - GPU/TPU workloads requiring specific configurations - Per-second billing with sustained use discounts - πŸ“– Compute Engine Overview - Architecture guide - πŸ“– Machine Families - Choosing the right machine type - πŸ“– Instance Templates - Configuration management - πŸ“– Managed Instance Groups - Auto-scaling and load balancing - πŸ“– Sole-Tenant Nodes - Dedicated hardware for compliance

Advanced Features: - Custom Machine Types - Precise resource allocation - Preemptible VMs - Up to 80% cost savings for fault-tolerant workloads - Spot VMs - More flexible than preemptible with longer runtime - Committed Use Discounts - 1 or 3 year commitments for 57% savings - Shielded VMs - Secure boot, vTPM, integrity monitoring - πŸ“– Live Migration - Zero-downtime maintenance - πŸ“– Persistent Disk Performance - Storage optimization

Google Kubernetes Engine (GKE)

Enterprise Architecture: - Autopilot - Fully managed, pay-per-pod, optimal configurations - Standard - Node-level control, custom configurations - GKE Enterprise - Multi-cluster management with Anthos - πŸ“– GKE Architecture - Complete overview - πŸ“– Cluster Architecture - Control plane and nodes - πŸ“– Multi-Cluster Ingress - Global load balancing - πŸ“– Binary Authorization - Deploy-time security controls - πŸ“– GKE Networking - VPC-native clusters

Advanced Patterns: - Workload Identity - Pod-to-GCP service authentication without keys - Config Connector - Manage GCP resources via Kubernetes - Node Auto-Provisioning - Automatic node pool creation - Vertical Pod Autoscaling - Right-size container resources - Multi-cluster Services - Service discovery across clusters - πŸ“– GKE Best Practices - Production guidelines - πŸ“– Security Hardening - Security best practices

Cloud Run

Serverless Container Architecture: - Fully managed compute platform for containers - Scales to zero, pay only for actual usage - Auto-scales based on concurrent requests - πŸ“– Cloud Run Documentation - Complete guide - πŸ“– Service Identity - IAM integration - πŸ“– VPC Connectivity - Direct VPC egress - πŸ“– Cloud Run Jobs - Batch workloads

Architecture Decisions: - vs App Engine - More flexibility, custom containers - vs GKE - Simpler operations, less control - vs Cloud Functions - Longer execution time, more memory

App Engine

Platform as a Service: - Standard Environment - Rapid scaling, sandbox runtime, free tier - Flexible Environment - Docker containers, SSH access, custom runtimes - πŸ“– App Engine Architecture - Environment comparison - πŸ“– Scaling Types - Automatic, basic, manual scaling - πŸ“– Traffic Splitting - A/B testing and canary - πŸ“– Migration to Standard 2nd Gen - Modern runtimes

Cloud Functions

Event-Driven Serverless: - 2nd Generation - Built on Cloud Run, better performance, longer execution - Event sources: Cloud Storage, Pub/Sub, HTTP, Firestore, Firebase - πŸ“– Cloud Functions Architecture - Concepts and patterns - πŸ“– Eventarc Integration - Unified eventing - πŸ“– Security Best Practices - Function security

Storage Architecture

Cloud Storage

Global Object Storage: - Storage Classes Decision Matrix: - Standard - Hot data, frequent access - Nearline - < 1/month access, 30-day minimum - Coldline - < 1/quarter access, 90-day minimum - Archive - < 1/year access, 365-day minimum - πŸ“– Storage Classes - Detailed comparison - πŸ“– Object Lifecycle Management - Automated tiering - πŸ“– Bucket Locations - Regional, dual-region, multi-region - πŸ“– Object Versioning - Version control - πŸ“– Retention Policies - Compliance and data governance - πŸ“– Customer-Managed Encryption Keys - CMEK integration

Advanced Features: - Requester Pays - Transfer costs to downloader - Object Holds - Legal and temporary holds - Dual-region - 99.95% SLA with geo-redundancy - Turbo Replication - < 15 minute RPO between regions - πŸ“– Performance Optimization - Request rate best practices

Persistent Disks and Filestore

Block and File Storage: - Persistent Disk Types: - Standard (pd-standard) - HDD, sequential workloads - Balanced (pd-balanced) - SSD, balanced price/performance - SSD (pd-ssd) - High-performance SSD - Extreme (pd-extreme) - Highest performance, configurable IOPS - πŸ“– Disk Types Comparison - Performance and pricing - πŸ“– Regional Persistent Disks - Synchronous replication - πŸ“– Disk Snapshots - Incremental backups - πŸ“– Filestore - Managed NFS file server - πŸ“– Filestore Instances - Basic, High Scale, Enterprise tiers

Database Architecture

Cloud SQL

Managed Relational Databases: - Supports MySQL, PostgreSQL, SQL Server - High Availability Configuration: - Regional HA with synchronous replication - Automatic failover (typically 60-120 seconds) - Read replicas for read scaling - πŸ“– Cloud SQL Overview - Architecture guide - πŸ“– High Availability - HA architecture - πŸ“– Replication - Read replicas and cross-region - πŸ“– Backup and Recovery - Backup strategies - πŸ“– Connection Options - Cloud SQL Proxy, Private IP

Cloud Spanner

Globally Distributed Relational Database: - Horizontally scalable, strongly consistent - Global transactions with 99.999% availability SLA - Multi-region configurations for HA and low latency - πŸ“– Cloud Spanner Overview - Architecture concepts - πŸ“– Replication - Multi-region replication - πŸ“– Schema Design Best Practices - Performance optimization - πŸ“– Instance Configurations - Regional and multi-regional - πŸ“– Choosing Between Cloud SQL and Spanner - Decision guide

Firestore and Datastore

NoSQL Document Databases: - Firestore - Next-generation, real-time synchronization - Datastore Mode - Server-side applications - Automatic multi-region replication - Strong consistency for entity group queries - πŸ“– Firestore Overview - Complete guide - πŸ“– Choosing Between Firestore Modes - Native vs Datastore mode - πŸ“– Data Modeling - Document structure - πŸ“– Best Practices - Performance and cost optimization

Bigtable

Wide-Column NoSQL: - Petabyte-scale, sub-10ms latency - Ideal for time-series, IoT, financial services - HBase API compatible - πŸ“– Bigtable Overview - Architecture and use cases - πŸ“– Schema Design - Row key design critical - πŸ“– Replication - Multi-cluster replication - πŸ“– Performance Tuning - Optimization guide - πŸ“– Choosing Between Bigtable and Other Databases - Decision tree

BigQuery

Serverless Data Warehouse: - Petabyte-scale analytics with standard SQL - Separation of compute and storage - Automatic optimization and indexing - πŸ“– BigQuery Architecture - Complete guide - πŸ“– Partitioning and Clustering - Query optimization - πŸ“– BigQuery BI Engine - In-memory analytics - πŸ“– BigQuery ML - Machine learning in SQL - πŸ“– Cost Optimization - Query cost management - πŸ“– Data Transfer Service - Scheduled data imports

Memorystore

Managed In-Memory Data Store: - Memorystore for Redis - Advanced features, persistence - Memorystore for Memcached - Simple caching - πŸ“– Memorystore for Redis - Redis architecture - πŸ“– High Availability - Standard vs basic tier

Networking Architecture

Virtual Private Cloud (VPC)

Network Foundation: - Global resource spanning all regions - Subnets are regional (not zonal) - No inter-region bandwidth charges within VPC - πŸ“– VPC Overview - Fundamental concepts - πŸ“– VPC Network Design - Best practices - πŸ“– Subnet Configuration - IP addressing - πŸ“– Firewall Rules - Traffic control - πŸ“– Routes - Routing configuration - πŸ“– Alias IP Ranges - Container and service IPs

Advanced VPC Patterns: - Shared VPC - Cross-project networking - VPC Peering - Private connectivity between VPCs - VPC Service Controls - Security perimeters - Private Google Access - Access Google APIs privately - Private Service Connect - Private access to managed services - πŸ“– Shared VPC - Multi-project architecture - πŸ“– VPC Peering - VPC interconnection - πŸ“– VPC Service Controls - Security perimeter - πŸ“– Private Google Access - API access without internet - πŸ“– Private Service Connect - Private service access

Cloud Load Balancing

Global Load Balancing: - Single anycast IP serving globally - Automatic multi-region failover - Layer 4 (TCP/UDP) and Layer 7 (HTTP/S) options - πŸ“– Load Balancing Overview - Architecture guide - πŸ“– Choosing a Load Balancer - Decision tree - πŸ“– External HTTP(S) Load Balancer - Global Layer 7 - πŸ“– Internal HTTP(S) Load Balancer - Regional Layer 7 - πŸ“– Network Load Balancer - Regional Layer 4 - πŸ“– SSL Policies - TLS configuration - πŸ“– Cloud Armor - DDoS protection and WAF

Cloud CDN

Content Delivery Network: - Global edge network with Google's infrastructure - Cache-to-cache filling reduces origin load - Integration with Cloud Load Balancing - πŸ“– Cloud CDN Overview - Architecture - πŸ“– Caching Best Practices - Performance optimization - πŸ“– Cache Keys and Modes - Cache control - πŸ“– Signed URLs and Cookies - Content access control

Hybrid Connectivity

Connecting to Google Cloud: - Cloud VPN - IPsec, up to 3 Gbps per tunnel with HA VPN - Cloud Interconnect - Dedicated physical connections - Dedicated - 10 or 100 Gbps direct connection - Partner - 50 Mbps to 50 Gbps via partner - πŸ“– Hybrid Connectivity Overview - Options comparison - πŸ“– Cloud VPN - VPN architecture - πŸ“– HA VPN - High availability VPN - πŸ“– Cloud Interconnect - Dedicated connectivity - πŸ“– Partner Interconnect - Service provider connectivity - πŸ“– Cloud Router - Dynamic BGP routing

Network Intelligence Center: - πŸ“– Network Topology - Visualization - πŸ“– Connectivity Tests - Troubleshooting - πŸ“– Performance Dashboard - Monitoring

Security and Identity

Identity and Access Management (IAM)

Principle of Least Privilege: - Who - Google Account, Service Account, Google Group, Cloud Identity domain - What - Resources (projects, folders, organization) - How - Roles (primitive, predefined, custom) - πŸ“– IAM Overview - Core concepts - πŸ“– IAM Roles - Role types and hierarchy - πŸ“– Custom Roles - Role creation - πŸ“– IAM Conditions - Conditional access - πŸ“– IAM Best Practices - Security guidelines - πŸ“– Policy Intelligence - Policy analysis tools

Service Accounts

Application Identity: - Default compute service account (not recommended for production) - User-managed service accounts (recommended) - Short-lived credentials via Workload Identity Federation - πŸ“– Service Accounts - Complete guide - πŸ“– Best Practices - Security patterns - πŸ“– Workload Identity - External identity federation - πŸ“– Service Account Impersonation - Delegation patterns

Encryption

Data Protection: - Encryption at rest - Default with Google-managed keys - Customer-Managed Encryption Keys (CMEK) - Cloud KMS integration - Customer-Supplied Encryption Keys (CSEK) - Customer-provided keys - πŸ“– Encryption at Rest - Default encryption - πŸ“– Cloud KMS - Key management service - πŸ“– CMEK - Customer-managed keys - πŸ“– Cloud HSM - Hardware security modules - πŸ“– Secret Manager - Secrets storage

Security Command Center

Centralized Security Management: - Asset discovery and inventory - Vulnerability scanning - Threat detection - Compliance monitoring - πŸ“– Security Command Center - Overview - πŸ“– Asset Discovery - Inventory management - πŸ“– Finding Types - Security findings

Identity-Aware Proxy (IAP)

Application-Level Access Control: - Zero-trust access to applications - No VPN required - Context-aware access controls - πŸ“– Identity-Aware Proxy - Architecture guide - πŸ“– IAP TCP Forwarding - SSH/RDP access

Operations and Observability

Cloud Monitoring (Operations Suite)

Monitoring and Alerting: - Infrastructure and application metrics - Custom metrics from applications - Uptime checks and alerting - πŸ“– Cloud Monitoring - Complete guide - πŸ“– Metrics - Available metrics - πŸ“– Alerting - Alert policies - πŸ“– Dashboards - Visualization - πŸ“– Uptime Checks - Availability monitoring

Cloud Logging (Operations Suite)

Centralized Log Management: - All GCP service logs automatically collected - Log sinks to BigQuery, Cloud Storage, Pub/Sub - Log-based metrics for custom monitoring - πŸ“– Cloud Logging - Architecture overview - πŸ“– Logs Router - Log routing - πŸ“– Log Sinks - Export destinations - πŸ“– Logs Explorer - Query interface - πŸ“– Audit Logs - Compliance logging

Cloud Trace and Profiler

Application Performance: - Cloud Trace - Distributed tracing for latency analysis - Cloud Profiler - Continuous CPU and memory profiling - Cloud Debugger - Production debugging without stopping - πŸ“– Cloud Trace - Latency tracking - πŸ“– Cloud Profiler - Performance profiling - πŸ“– Error Reporting - Error aggregation

Migration Strategies

Migration Framework (5 Rs)

Migration Patterns: 1. Rehost - Lift-and-shift to Compute Engine 2. Replatform - Minor optimizations (e.g., Cloud SQL instead of self-managed) 3. Refactor - Re-architect for cloud-native (serverless, microservices) 4. Retire - Decommission unnecessary systems 5. Retain - Keep on-premises temporarily

Migration Tools: - Migrate for Compute Engine - VM migration from on-prem or other clouds - Database Migration Service - Continuous replication for minimal downtime - Transfer Appliance - Physical data transfer for large datasets - Storage Transfer Service - Online data transfer - πŸ“– Migration to Google Cloud - Migration framework - πŸ“– Migrate for Compute Engine - VM migration - πŸ“– Database Migration Service - Database migration - πŸ“– Transfer Appliance - Offline data transfer - πŸ“– Storage Transfer Service - Online data transfer

Cost Optimization

Compute Cost Optimization

Cost-Effective Compute: - Committed Use Discounts - 1 or 3 year, up to 57% savings - Sustained Use Discounts - Automatic discounts for running instances - Preemptible VMs - Up to 80% savings, 24-hour max - Spot VMs - More flexible preemptible alternative - Custom Machine Types - Right-size CPU and memory - πŸ“– Pricing Overview - GCP pricing model - πŸ“– Committed Use Discounts - Long-term commitments - πŸ“– Resource-Based Pricing - Per-second billing - πŸ“– Pricing Calculator - Cost estimation

Storage Cost Optimization

Storage Classes and Lifecycle: - Autoclass for Cloud Storage buckets - Object lifecycle management - Nearline/Coldline/Archive for infrequent access - Regional vs multi-region trade-offs - πŸ“– Storage Cost Optimization - Best practices

Cost Management Tools

Visibility and Control: - Cost Management - Budgets, alerts, reports - Recommender - AI-powered cost and performance recommendations - Active Assist - Proactive optimization recommendations - πŸ“– Cost Management - Cost visibility - πŸ“– Billing Reports - Cost analysis - πŸ“– Budgets and Alerts - Cost controls - πŸ“– Recommender - Optimization recommendations

High Availability and Disaster Recovery

Availability Patterns

Multi-Zonal and Multi-Regional: - Zonal Resources - Compute Engine instances, persistent disks - Regional Resources - Cloud SQL, regional MIGs, subnets - Multi-Regional Resources - Cloud Storage, Spanner - Global Resources - VPC networks, load balancers, Cloud CDN

Disaster Recovery Strategies

RTO and RPO Trade-offs:

Strategy RTO RPO Cost Use Case
Backup & Restore Hours Hours $ Dev/test, non-critical
Pilot Light 10s of minutes Minutes $$ Lower-tier production
Warm Standby Minutes Seconds $$$ Business-critical
Active-Active Multi-Region Seconds Near-zero $$$$ Mission-critical

DR Best Practices: - Regular backup testing and validation - Automated failover procedures - Multi-region replication for critical data - Documentation and runbooks - Periodic DR drills

Compliance and Governance

Resource Hierarchy

Organization Structure:

Organization
β”œβ”€β”€ Folder (Business Unit)
β”‚   β”œβ”€β”€ Folder (Environment)
β”‚   β”‚   β”œβ”€β”€ Project (Application)
β”‚   β”‚   └── Project (Application)

Compliance and Certifications

Regulatory Compliance: - ISO 27001, SOC ⅔, PCI-DSS, HIPAA, GDPR - Regional data residency controls - Compliance reports and certifications - πŸ“– Compliance Offerings - Certifications and reports - πŸ“– Data Residency - Location controls

Common Architecture Patterns

Pattern 1: Three-Tier Web Application

Architecture: - Presentation Tier - Cloud Load Balancer + Cloud CDN - Application Tier - Managed Instance Group (auto-scaling) - Data Tier - Cloud SQL with read replicas

Key Services: - Global HTTP(S) Load Balancer - Cloud CDN for static assets - Cloud Armor for DDoS protection - VPC with private subnets - Cloud SQL with HA configuration

Pattern 2: Microservices on GKE

Architecture: - GKE Autopilot or Standard cluster - Workload Identity for service authentication - Cloud SQL Proxy for database access - Anthos Service Mesh for observability

Key Services: - GKE with VPC-native networking - Cloud Build for CI/CD - Artifact Registry for container images - Cloud Monitoring for observability

Pattern 3: Real-Time Data Pipeline

Architecture: - Ingestion - Pub/Sub for event streaming - Processing - Dataflow for stream processing - Storage - BigQuery for analytics - Visualization - Looker or Data Studio

Key Services: - Pub/Sub for decoupling - Dataflow for ETL - BigQuery for warehousing - Dataproc for Hadoop/Spark workloads

Pattern 4: Serverless Application

Architecture: - Cloud Run or Cloud Functions for compute - Firestore for NoSQL database - Cloud Storage for object storage - API Gateway for API management

Key Services: - Cloud Run with automatic scaling - Eventarc for event routing - Secret Manager for credentials - Cloud CDN for caching

Pattern 5: Hybrid Cloud with Anthos

Architecture: - GKE clusters on GCP and on-premises - Anthos Config Management for policy - Anthos Service Mesh for networking - Cloud Interconnect for connectivity

Key Services: - Anthos GKE on-prem - Cloud VPN or Interconnect - Binary Authorization - Cloud Operations suite

Data Engineering Architecture

Batch Processing

MapReduce and Spark: - Dataproc - Managed Hadoop and Spark - Dataflow - Serverless Apache Beam pipelines - πŸ“– Dataproc - Managed big data - πŸ“– Dataflow - Stream and batch processing

Stream Processing

Real-Time Analytics: - Pub/Sub - Global message queue - Dataflow - Stream processing - Bigtable - High-throughput writes - πŸ“– Pub/Sub - Messaging architecture - πŸ“– Streaming Analytics - Reference architecture

Data Warehousing

BigQuery Architecture: - Columnar storage for analytics - Automatic query optimization - Federated queries across sources - πŸ“– BigQuery Best Practices - Performance guide

Machine Learning and AI

AI Platform and Vertex AI

ML Workflow: - Vertex AI - Unified ML platform - Training with custom or pre-built containers - Model deployment and serving - πŸ“– Vertex AI - ML platform - πŸ“– AutoML - No-code ML

Pre-Trained APIs

AI Services: - Vision API, Natural Language API, Translation API - Speech-to-Text, Text-to-Speech - πŸ“– Cloud AI Products - AI/ML services

DevOps and CI/CD

Cloud Build

Continuous Integration: - Serverless build service - Container and non-container builds - Integration with GitHub, Bitbucket, Cloud Source Repositories - πŸ“– Cloud Build - CI/CD platform

Infrastructure as Code

Deployment Automation: - Deployment Manager - Native GCP IaC - Terraform - Multi-cloud IaC (popular choice) - Config Connector - Kubernetes-native GCP resource management - πŸ“– Deployment Manager - GCP native IaC - πŸ“– Terraform on GCP - Terraform integration

Exam Scenarios and Solutions

Scenario 1: High-Traffic Web Application

Requirements: Handle millions of requests, global users, cost-effective

Solution: - Global HTTP(S) Load Balancer with Cloud CDN - Regional Managed Instance Groups with autoscaling - Cloud SQL with read replicas or Cloud Spanner - Cloud Storage for static assets - Cloud Armor for security

Key Decision: Cloud Spanner if multi-region writes needed, else Cloud SQL with cross-region read replicas

Scenario 2: Lift-and-Shift Migration

Requirements: Migrate 100+ VMs from on-premises quickly

Solution: - Migrate for Compute Engine - Phased migration approach - Cloud VPN or Interconnect for connectivity - Use Committed Use Discounts for cost savings

Key Decision: Start with non-critical workloads, validate, then migrate production

Scenario 3: Real-Time Analytics

Requirements: Ingest millions of events per second, real-time dashboards

Solution: - Pub/Sub for ingestion - Dataflow for stream processing - BigQuery for data warehouse - Bigtable for operational queries - Looker or Data Studio for visualization

Key Decision: BigQuery for ad-hoc analytics, Bigtable for operational low-latency queries

Scenario 4: Hybrid Cloud

Requirements: Keep sensitive data on-premises, use GCP for compute

Solution: - Cloud Interconnect (dedicated) for consistent performance - Shared VPC for network segregation - Private Google Access for API calls - Cloud SQL with private IP - Anthos if running Kubernetes workloads

Key Decision: Dedicated Interconnect vs Partner Interconnect based on bandwidth needs

Scenario 5: Disaster Recovery

Requirements: RPO < 1 hour, RTO < 4 hours

Solution: - Pilot Light strategy - Cloud SQL automated backups - Persistent disk snapshots to Cloud Storage - Infrastructure as Code for rapid deployment - Runbooks in Cloud Storage

Key Decision: Warm Standby if stricter RTO/RPO needed

Scenario 6: Multi-Tenant SaaS

Requirements: Isolate customer data, cost attribution

Solution: - Separate projects per customer (strong isolation) - OR Shared infrastructure with tagging (cost-effective) - Folder hierarchy for organization - Labels for cost allocation - VPC Service Controls for data exfiltration protection

Key Decision: Isolation level vs cost trade-off

Exam Tips and Strategy

Keywords to Watch

Question Patterns: - "Cost-effective" β†’ Committed use, preemptible, autoscaling, Cloud Functions/Run - "Minimize operational overhead" β†’ Managed services, serverless, GKE Autopilot - "High availability" β†’ Multi-zone, multi-region, load balancing - "Low latency" β†’ Memorystore, CDN, proximity to users, Bigtable - "Compliance/regulatory" β†’ VPC Service Controls, organization policies, audit logs - "Real-time" β†’ Pub/Sub, Dataflow, Bigtable - "Big data analytics" β†’ BigQuery, Dataproc, Dataflow - "Secure" β†’ VPC, IAM, CMEK, Private Google Access

Service Selection Decision Trees

Compute Decision:

Stateless application?
β”œβ”€ YES β†’ Container?
β”‚  β”œβ”€ YES β†’ Need Kubernetes?
β”‚  β”‚  β”œβ”€ YES β†’ GKE
β”‚  β”‚  └─ NO β†’ Cloud Run
β”‚  └─ NO β†’ Need custom runtime?
β”‚     β”œβ”€ YES β†’ App Engine Flexible
β”‚     └─ NO β†’ App Engine Standard
└─ NO β†’ Compute Engine

Database Decision:

Relational needed?
β”œβ”€ YES β†’ Global transactions?
β”‚  β”œβ”€ YES β†’ Cloud Spanner
β”‚  └─ NO β†’ Cloud SQL
└─ NO β†’ Data model?
   β”œβ”€ Key-Value/Document β†’ Firestore
   β”œβ”€ Wide-Column β†’ Bigtable
   └─ Analytics β†’ BigQuery

Time Management

  • 120 minutes Γ· 50 questions = 2.4 minutes per question
  • First pass: Answer confident questions (60 minutes)
  • Second pass: Tackle difficult questions (45 minutes)
  • Final pass: Review flagged questions (15 minutes)

Common Traps

  • ❌ Choosing complex solutions when simple ones suffice
  • ❌ Ignoring cost constraints
  • ❌ Over-emphasizing technical perfection vs business needs
  • ❌ Not considering operational overhead
  • ❌ Forgetting about managed service alternatives
  • ❌ Mixing up service capabilities and limits

Study Checklist

Knowledge Areas: - [ ] Can design multi-tier applications on GCP - [ ] Understand VPC networking, shared VPC, and VPC peering - [ ] Know when to use each compute option (GCE, GKE, App Engine, Cloud Run, Functions) - [ ] Can select appropriate database for use case - [ ] Understand migration strategies and tools - [ ] Know cost optimization techniques - [ ] Can design for high availability and disaster recovery - [ ] Understand IAM, service accounts, and security best practices - [ ] Know monitoring and logging setup - [ ] Familiar with hybrid connectivity options

Preparation: - [ ] Hands-on experience with GCP (build actual projects) - [ ] Review all case studies on exam guide - [ ] Complete practice exams (80%+ score) - [ ] Read official GCP Architecture Framework - [ ] Review common reference architectures - [ ] Practice with GCP Console and gcloud CLI


Pro Tip: The Professional Cloud Architect exam tests your ability to make architecture trade-offs based on business requirements. Always consider: cost, operational overhead, performance, security, compliance, and scalability. The "best" answer balances all these factors based on scenario constraints!

Documentation Count: This fact sheet contains 100+ embedded documentation links to official Google Cloud documentation.

Good luck! This certification demonstrates expert-level cloud architecture skills on Google Cloud Platform.