Hard1 markMultiple Choice
Domain 2: Managing and Provisioning a Solution InfrastructureCloud InterconnectHybrid ConnectivitySecurity
This question is part of a case study — click to read the full scenario(Case 06)

CASE STUDY: RetailMart

Overview: Global e-commerce, 5,000 employees. Legacy monolith on VMware, 20TB Oracle DB on-prem.
Business: Modernize to microservices, 100% uptime during Black Friday (10x traffic), real-time inventory sync, exit data center in 2 years.
Executives:

  • CEO: "Innovate faster to beat online-only competitors."
  • CFO: "End hardware CAPEX. Move to pure OPEX."
  • CTO: "Break monolith safely. Zero downtime during transition."
    Tech: Migrate off Oracle to open-source, containerize, secure hybrid connectivity during transition, automated scaling.
    Constraints: Zero downtime for storefront, heavy reliance on Oracle stored procedures, all hybrid traffic must be private/encrypted.

Which migration approach should you recommend to safely break down the monolith with zero downtime?

GCP PCA · Question 07 · Domain 2: Managing and Provisioning a Solution Infrastructure

CASE STUDY: RetailMart

Overview: Global e-commerce, 5,000 employees. Legacy monolith on VMware, 20TB Oracle DB on-prem.
Business: Modernize to microservices, 100% uptime during Black Friday (10x traffic), real-time inventory sync, exit data center in 2 years.
Executives:

  • CEO: "Innovate faster to beat online-only competitors."
  • CFO: "End hardware CAPEX. Move to pure OPEX."
  • CTO: "Break monolith safely. Zero downtime during transition."
    Tech: Migrate off Oracle to open-source, containerize, secure hybrid connectivity during transition, automated scaling.
    Constraints: Zero downtime for storefront, heavy reliance on Oracle stored procedures, all hybrid traffic must be private/encrypted.

How should you design the hybrid connectivity to meet the security and bandwidth requirements during the 2-year transition?

Answer options:

A.

Use Cloud VPN over the public internet.

B.

Provision Dedicated Interconnect and configure MACsec or IPsec over the interconnect for encryption.

C.

Use Partner Interconnect without additional encryption.

D.

Set up VPC Peering between the on-premises data center and Google Cloud.

How to approach this question

Combine the need for high bandwidth (Interconnect) with the strict security constraint (encryption).

Full Answer

B.Provision Dedicated Interconnect and configure MACsec or IPsec over the interconnect for encryption.✓ Correct
Provision Dedicated Interconnect and configure MACsec or IPsec over the interconnect for encryption.
During a 2-year hybrid transition of a high-traffic e-commerce site with a 20TB database, high bandwidth and low latency are critical, requiring Dedicated Interconnect. However, Interconnect traffic is not encrypted by default. To meet the security team's strict encryption requirement, you must deploy HA VPN over Cloud Interconnect or use MACsec for Cloud Interconnect.

Common mistakes

Assuming Dedicated Interconnect is encrypted by default (C). It provides a private circuit, but not cryptographic encryption.

Practice the full GCP Professional Cloud Architect Practice Exam 4

50 questions · hints · full answers · grading

More questions from this exam