When the scenario says… which service, in which cloud
In plain English: interviewers and exams rarely ask “what is Spanner”. They describe a constraint and wait to see which name you reach for. Each line below is a constraint, then the answer in all three clouds, then the reason the other options lose.
“We need one relational database with strong consistency that scales writes across regions.” → Spanner on Google Cloud is the reference answer, and Aurora DSQL is AWS’s first true equivalent since 2025. Aurora Global Database is read replicas plus a promotion, not multi-region writes, and Azure has no relational equivalent: Cosmos DB offers multi-region writes but it is not a relational database.
“A serverless warehouse where we pay only for what each query scans.” → BigQuery. On AWS the closest are Redshift Serverless and Athena, and on Azure the Fabric warehouse or Synapse serverless SQL. Redshift provisioned clusters and dedicated SQL pools are the opposite model: you size and pay for capacity whether or not you query.
“Our Kafka producers must keep working with no code change.” → Azure Event Hubs speaks the Kafka protocol natively, so clients repoint with a connection string. On AWS use Amazon MSK, on Google Cloud Managed Service for Apache Kafka; Kinesis and Pub/Sub are their own protocols and need client changes.
“Managed Kubernetes with the least node management we can get away with.” → GKE Autopilot has done it longest; EKS Auto Mode and AKS Automatic are the 2024 and 2025 answers on the other two. Standard EKS and AKS still leave node pools, upgrades and capacity to you.
“We already pay for Windows Server and SQL Server licences.” → Azure Hybrid Benefit lets those licences carry into Azure VMs and Azure SQL, and it frequently decides the whole business case. AWS and Google Cloud offer bring-your-own-licence paths for some products, but nothing as broad or as cheap.
“Reach a partner’s service privately, and our address ranges overlap with theirs.” → A private endpoint: AWS PrivateLink, Google Cloud Private Service Connect, Azure Private Link. The overlap is irrelevant because the two networks never join; peering or a VPN would fail on exactly that overlap.
“Guardrails that can also fix a non-compliant resource, not only deny the request.” → Azure Policy, whose effects include audit, deny and deploy-if-not-exists remediation. AWS service control policies only deny, and Google Cloud Organization Policy constrains what may be created; both need a separate remediation service to change anything.
“Stop data leaving our project even when the identity is authorised.” → VPC Service Controls on Google Cloud: a perimeter around services that blocks calls from outside it regardless of IAM. Azure’s Network Security Perimeter is the closest packaged equivalent; AWS assembles the effect from VPC endpoint policies and service control policies rather than selling it as one product.
“Run an agent in production with managed sessions, memory and a gateway to its tools.” → Amazon Bedrock AgentCore, Google Cloud’s Agent Runtime with Agent Gateway inside the Gemini Enterprise Agent Platform, and Azure AI Foundry Agent Service. Bedrock, Vertex AI and Foundry Models alone give you model access, not the operating layer around the agent.
“Screen prompts for injection and responses for leaks before they reach the model or the user.” → Amazon Bedrock Guardrails, Google Cloud Model Armor, Azure AI Content Safety. A web application firewall is the wrong layer: it inspects HTTP traffic, not the meaning of a prompt.
“Where did Azure Active Directory go?” → It became Microsoft Entra ID in 2023 and the Entra family now covers workforce identity, external identity and permissions. Same service, same tenants; only the name and the product grouping changed.
“Which provider should host our source code?” → Usually GitHub or GitLab, with the cloud’s own build service behind it. AWS closed CodeCommit to new customers in 2024 and quietly reopened it in late 2025, Google Cloud is retiring Cloud Source Repositories in favour of Secure Source Manager, and Azure points you at Azure Repos or GitHub, which Microsoft owns. None of the three treats hosting your code as a flagship.
“Archive petabytes cheaply, but a restore must return a file in milliseconds.” → Google Cloud Storage Archive class keeps millisecond access at archive prices, and S3 Glacier Instant Retrieval does the same on AWS. Azure’s Blob Archive tier and S3 Glacier Deep Archive need rehydration measured in hours, which changes a disaster-recovery design.
“Redis changed its licence. What do the clouds sell now?” → ElastiCache and Memorystore both added Valkey, the open-source fork, and steer new work to it; Azure Managed Redis is built on Redis Enterprise under a partnership. The old “managed Redis” row is now three different answers.
“A container orchestrator that is not Kubernetes.” → Amazon ECS, in practice. Azure Service Fabric exists but is legacy-leaning, with Microsoft steering new work to AKS and Container Apps, and Google Cloud has none: container work there goes to GKE or Cloud Run.