PCD Sample Questions

PCD Sample Questions & Answers

Free Professional Cloud Developer practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full PCD simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Building and testing applications · Using Cloud Build and Artifact Registry to build and store containers from source code

    You are building a CI/CD pipeline using Cloud Build. The build process requires a specific version of a proprietary code analysis tool that is not available in the standard Cloud Build builder images. You want to make this tool available to your build steps while following security best practices and ensuring build reproducibility. What is the recommended approach?

    Show answer & explanation

    Correct answer: C

    Creating a custom builder image is the recommended best practice. This approach encapsulates the dependency within a versioned Docker image, which can be stored securely in Artifact Registry. It ensures that builds are faster (no download/install step) and more reliable and reproducible, as they always use the exact same environment.

  2. Question 2BeginnerSelect 2

    Building and testing applications · Writing unit tests with the help of Gemini Code Assist.

    A new developer on your team is using Gemini Code Assist in their IDE. They want to generate unit tests for a complex function they have written in Python. Which TWO of the following actions are best practices for effectively using Gemini Code Assist for this task? (Select TWO).

    Show answer & explanation

    Correct answers: A, C

  3. Question 3Intermediate

    Deploying applications · Deploying applications from source code

    You are deploying a new version of a critical microservice to Cloud Run. To minimize the risk of a faulty deployment affecting all users, you want to first deploy the new version without sending it any production traffic. After verifying its health through internal tests, you then want to gradually shift 100% of the traffic to it. Which deployment command sequence should you use?

    Show answer & explanation

    Correct answer: B

    This sequence correctly implements the desired strategy. The --no-traffic flag deploys the new revision but does not allocate any production traffic to it, allowing for safe, isolated testing. The second command, update-traffic, then safely migrates traffic to the new, verified revision. The --migrate-gradually flag can be used to perform a gradual rollout.

  4. Question 4Intermediate

    Designing highly scalable, available, and reliable cloud-native applications · Authenticating to Google Cloud services (e.g., Application Default Credentials, JSON Web Token [JWT], OAuth 2.0, Cloud SQL Auth Proxy, AlloyDB Auth Proxy)

    Your application, running on Compute Engine, needs to read sensitive configuration data stored in Secret Manager. To adhere to the principle of least privilege and avoid managing service account keys, what is the most secure method for the application to authenticate to the Secret Manager API?

    Show answer & explanation

    Correct answer: B

    This is the most secure and recommended method. By attaching a service account to the VM instance, the application can use the Google Cloud client libraries, which automatically find and use the credentials provided by the instance's metadata server via Application Default Credentials (ADC). This completely avoids the need to handle, distribute, and rotate static key files.

  5. Question 5Intermediate

    Integrating applications with data and storage services · Managing connections to various Google Cloud datastores (e.g., Cloud SQL, Firestore, Cloud Storage)

    True or False: When using the Cloud SQL Auth Proxy to connect from a GKE pod to a Cloud SQL instance, you must configure a firewall rule to allow TCP traffic on port 3307 from the GKE nodes to the Cloud SQL instance's public IP address.

    Show answer & explanation

    Correct answer: B

    False. The Cloud SQL Auth Proxy works by creating a secure tunnel using SSL/TLS over port 443 to communicate with the Cloud SQL APIs. It does not connect directly to the database port (e.g., 3306 for MySQL, 5432 for PostgreSQL). Therefore, you do not need to open the database port in any firewall rules; you only need outbound internet access on port 443.

  6. Question 6Intermediate

    Designing highly scalable, available, and reliable cloud-native applications · Creating and deploying APIs (e.g., HTTP REST, gRPC [Google Remote Procedure Call])

    An e-commerce application experiences performance degradation during peak traffic. Analysis with Cloud Profiler reveals that a significant amount of CPU time is spent serializing and deserializing JSON payloads for service-to-service communication. The development team wants to replace the existing REST/JSON communication with a more efficient, high-performance alternative suitable for internal microservices. What should they use?

    Show answer & explanation

    Correct answer: B

    gRPC uses Protocol Buffers (protobuf) as its interface definition language and message interchange format. Protobufs are a binary serialization format that is much more compact and efficient to parse than text-based formats like JSON. This directly addresses the identified bottleneck of CPU time spent on JSON serialization/deserialization, making it the ideal choice for high-performance internal microservices communication.

  7. Question 7Intermediate

    Integrating applications with Google Cloud services · Handling errors (e.g., exponential backoff)

    A batch processing job running on a GKE cluster frequently fails with a 429 Too Many Requests error when writing a high volume of small files to a Cloud Storage bucket. The application code currently has no retry logic. To make the uploads more reliable, you need to implement a retry strategy. According to Google Cloud best practices, what is the proper way to handle these errors?

    Show answer & explanation

    Correct answer: C

    A 429 error indicates that the client is sending requests too quickly. The recommended practice for handling this and other transient server-side errors (5xx) is to retry with exponential backoff. This strategy involves waiting progressively longer between retries to avoid overwhelming the service. Adding jitter (randomness) to the backoff delay helps prevent a 'thundering herd' problem where many clients retry simultaneously.

  8. Question 8Beginner

    Deploying applications · Invoking Cloud Run services using triggers (e.g., Eventarc, Pub/Sub)

    You are designing a data pipeline that processes user-uploaded images. The raw images are stored in a Cloud Storage bucket. You need a solution that automatically resizes these images into several different thumbnail sizes as soon as they are uploaded. The solution should be serverless, cost-effective for sporadic workloads, and scale to zero when there are no new uploads. Which service is the best fit for this task?

    Show answer & explanation

    Correct answer: C

    Cloud Functions is the ideal service for this use case. It is a serverless, event-driven compute platform that can be directly triggered by events from other Google Cloud services, such as a new object being created in a Cloud Storage bucket. It automatically scales based on the number of events and scales to zero when inactive, making it highly cost-effective for workloads that are not constant.

  9. Question 9AdvancedSelect 2

    Designing highly scalable, available, and reliable cloud-native applications · Storing, accessing, and rotating application secrets, credentials, and encryption keys (e.g., Secret Manager, Cloud Key Management Service, Workload Identity Federation)

    A developer needs to provide a third-party CI/CD platform (e.g., GitHub Actions) with the ability to deploy an application to Cloud Run. The security team has forbidden the use of long-lived JSON service account keys. Which combination of Google Cloud features should be used to provide secure, keyless authentication for the external platform? (Select TWO).

    Show answer & explanation

    Correct answers: A, C

  10. Question 10Beginner

    Building and testing applications · Emulating Google Cloud services using the Google Cloud CLI for local application development and local unit testing

    You are setting up a local development environment to build a Go application that interacts with Cloud Spanner. You want to test your application's database logic locally without incurring costs or affecting the production Spanner instance. What is the recommended tool for this purpose?

    Show answer & explanation

    Correct answer: A

    The Cloud Spanner Emulator is a tool provided by Google that you can run on your local machine. It provides a local, in-memory emulation of the Cloud Spanner service, allowing you to develop and test your application's database interactions without connecting to the actual Spanner service. This is ideal for local development, unit testing, and integration testing in a CI environment.

Ready for the real thing?

The full PCD simulator has every exam-style question, timed mode, and instant scoring.

Go to the PCD simulator →