Instiq

Google Cloud Professional Cloud ArchitectStudy guide

The professional certification for designing and managing scalable, available, and secure solutions on Google Cloud (Professional Cloud Architect).

About Google Cloud Professional Cloud Architect (GCP-PCA)

Google Cloud Professional Cloud Architect (GCP-PCA) is a Professional / Expert-level certification from Google Cloud. This page organizes the exam scope into a 6-chapter, 12-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."

Exam domains (approximate weighting)

  • Designing and planning a cloud solution architecture~35%
  • Managing and provisioning a solution infrastructure~30%
  • Designing for security and compliance~20%
  • Analyzing and optimizing technical and business processes~15%

Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.

Official exam information: https://cloud.google.com/learn/certification/cloud-architect

1Designing a cloud solution

  • 1.1From requirements to architecture

    Understand eliciting business and technical requirements and translating them into a Google Cloud architecture, designing the resource hierarchy (Organization → Folder → Project), reflecting stakeholder expectations and compliance constraints, and making design decisions based on success metrics (KPIs/SLOs).

  • 1.2Choosing compute, storage, and data services

    Understand choosing Google Cloud compute (Compute Engine, GKE, Cloud Run, Cloud Functions) by use case, storage (Cloud Storage classes, Persistent Disk, Filestore), and databases (Cloud SQL, Spanner, Firestore, Bigtable, BigQuery).

2Designing availability, scalability, and migration

  • 2.1Designing for high availability, scalability, and disaster recovery

    Understand availability levels (zonal/regional/multi-regional), elasticity via managed instance groups (MIGs) and autoscaling, traffic distribution via load balancers, and disaster recovery strategies (backup-and-restore, warm/hot standby) based on RTO/RPO.

  • 2.2Planning migration and hybrid/multi-cloud

    Understand choosing migration strategies (lift-and-shift, improve-and-move, refactor), migration tools (Migrate to Virtual Machines, Database Migration Service, Storage Transfer Service, Transfer Appliance), hybrid/multi-cloud connectivity (Cloud VPN, Cloud Interconnect), and phased migration planning.

3Managing and provisioning infrastructure

  • 3.1Provisioning with Infrastructure as Code

    Understand reproducible provisioning with Infrastructure as Code (Terraform, Infrastructure Manager), state management and modularization, integration into CI/CD, and avoiding manual clickops to gain consistency and reviewability.

  • 3.2Configuring networking (VPC, load balancers, connectivity)

    Understand designing VPCs/subnets/firewall rules, centralized management via Shared VPC, Cloud Load Balancing types (global/regional, L7/L4), outbound via Cloud NAT, and secure connectivity via Private Google Access and VPC Service Controls.

4Configuring and operating compute and data

  • 4.1Configuring compute and containers

    Understand Compute Engine machine types/MIGs/instance templates, GKE Autopilot/Standard with node pools/workloads, Cloud Run revisions and traffic splitting, and cost-efficient configuration with Spot VMs and committed-use discounts.

  • 4.2Configuring data and operating/monitoring

    Understand configuring managed databases (Cloud SQL HA and read replicas, Spanner scaling), Cloud Storage lifecycle and access control, and operations via Cloud Monitoring, Cloud Logging, and alerts with SLO-based reliability management.

5Designing for security and compliance

  • 5.1IAM, least privilege, and organizational governance

    Understand designing least privilege with IAM (avoid basic roles; predefined/custom roles), service accounts and Workload Identity Federation, enforcing constraints with organization policies, and designing permission inheritance and guardrails along the resource hierarchy.

  • 5.2Data protection and compliance

    Understand encryption at rest/in transit and key management (GMEK/CMEK/CSEK/Cloud KMS), discovering and protecting sensitive data (Sensitive Data Protection / Cloud DLP), data residency and sovereignty, and regulatory compliance via Assured Workloads and audit logs.

6Analyzing and optimizing processes

  • 6.1Cost optimization and aligning business processes

    Understand cost visibility (billing reports, budgets and alerts), optimization levers (committed-use discounts, Spot VMs, Active Assist recommendations, lifecycle), cost allocation via labels, and aligning with business goals/KPIs and continually revisiting stakeholder requirements.

  • 6.2Optimizing technical processes (SRE, CI/CD, change management)

    Understand site reliability engineering operations (SLIs/SLOs/error budgets), safe delivery via CI/CD with deployment strategies (canary, blue/green, rollback), incident response and postmortems, and optimizing cross-team collaboration and decision-making.