PCDOE Sample Questions & Answers
Designing, implementing, and managing CI/CD pipelines carries the biggest share, next to bootstrapping a resource hierarchy, balancing velocity with reliability under SRE practices, keeping logs, metrics, and dashboards in order, and cost-aware troubleshooting.
Launch the full PCDOE simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Building and implementing CI/CD pipelines for applications and infrastructure · Applying CI/CD practices to infrastructure
Your organization manages dozens of GCP projects using Terraform. Multiple teams are making infrastructure changes concurrently, leading to conflicts and accidental overwrites of the Terraform state file. You need to implement a solution that provides state locking and a consistent, shared backend for all team members. Which Google Cloud service should you configure as the Terraform backend to achieve this?
Show answer & explanation
Correct answer: B
Cloud Storage is the recommended and standard backend for Terraform on GCP. When configured as a backend, it stores the state file centrally. Crucially, the GCS backend for Terraform natively supports state locking by creating a lock object in the bucket while an operation is in progress. This prevents other users from running
terraform applyconcurrently, thus avoiding state file corruption and conflicts. - Question 2Beginner
Applying site reliability engineering practices to applications · Balancing change, velocity, and reliability of the service
True or False: An error budget represents the maximum amount of time a service can be unavailable or perform below its SLO before violating its contractual SLA with a customer.
Show answer & explanation
Correct answer: B
This statement is false. An error budget is derived from the Service Level Objective (SLO), which is an internal reliability target. It is not directly tied to the Service Level Agreement (SLA), which is an external, often legally binding, contract with customers. The SLO is typically stricter than the SLA to provide a buffer. The error budget is the amount of acceptable 'unreliability' (100% - SLO) that can be 'spent' on new releases, maintenance, or unavoidable failures without alerting engineers, whereas violating an SLA has financial or contractual consequences.
- Question 3Intermediate
Implementing observability practices · Logging optimization
Your company's application generates a large volume of debug-level logs that are useful for real-time troubleshooting but are expensive to retain in Cloud Logging for the mandatory 90-day period. You also need to perform complex analytical queries on all retained logs. What is the most cost-effective approach to meet these requirements?
Show answer & explanation
Correct answer: C
This approach is the most cost-effective. A log sink forwards logs to a destination like BigQuery before they are processed for exclusion. This means all logs, including debug logs, are sent to BigQuery for cheap, long-term storage and powerful analytical querying. The exclusion filter then prevents the expensive debug logs from being ingested and stored in the standard Cloud Logging buckets, which are optimized for real-time access and have higher storage costs. This meets both requirements efficiently.
- Question 4IntermediateSelect 3
Bootstrapping and maintaining a Google Cloud organization · Creating and managing service accounts
You are creating a dedicated service account for a Cloud Build pipeline. The pipeline needs to perform the following actions: build a Docker image, push the image to Artifact Registry, and deploy the new image as a service revision to Cloud Run. Following the principle of least privilege, which THREE IAM roles should you grant to this service account? (Select THREE)
Show answer & explanation
Correct answers: B, C, D
This role grants the necessary permissions (
artifactregistry.repositories.uploadArtifacts) to push the newly built container image to the specified Artifact Registry repository.This role provides permissions to create and manage Cloud Run revisions, services, and configurations, which is exactly what is needed to deploy the new image.
To deploy a new revision to Cloud Run, the deploying identity (the Cloud Build service account) needs permission to act as the runtime service account of the Cloud Run service (
iam.serviceAccounts.actAs). This role grants that permission. - Question 5Advanced
Optimizing performance and troubleshooting · Google Cloud recommenders
The Google Cloud Recommender API suggests changing the machine type for a fleet of critical production VMs from
n2-standard-4toe2-mediumto save costs. A direct application of this change previously caused an outage due to unexpected performance degradation. As an SRE, what is the best practice for safely validating and implementing this type of recommendation in the future?Show answer & explanation
Correct answer: C
This SRE practice balances cost optimization with reliability. Instead of a 'big bang' change, a canary release allows you to test the recommendation on a small percentage of live traffic. By creating a new instance template and performing a rolling update to a subset of the managed instance group, you can compare the performance SLIs (latency, error rate, CPU utilization) of the new machine type against the existing baseline. If performance degrades, you can easily roll back with minimal user impact.
- Question 6Advanced
Building and implementing CI/CD pipelines for applications and infrastructure · Designing and managing CI/CD pipelines
Case Study
A large retail company,
ShopNow, is modernizing their deployment process for their monolithic e-commerce backend. Currently, deployments are manual, error-prone, and require significant downtime.Current Situation
- The application is packaged as a Docker container.
- Continuous Integration (CI) is handled by a self-hosted Jenkins server which builds the Docker image and pushes it to Artifact Registry.
- There are three environments:
dev,staging, andprod, each running on a separate GKE cluster. - The infrastructure team manages the GKE clusters using Terraform.
Requirements
- Automated Deployments: Implement a continuous delivery (CD) system to automate deployments to all three environments.
- Progressive Delivery: For
proddeployments, the new version must first be rolled out to 10% of traffic. After a 1-hour bake time, it must be manually approved before proceeding to 100%. - Integration: The new CD system must be triggered by the existing Jenkins CI job upon a successful build.
- Auditability: All deployment actions, including manual approvals, must be logged for audit purposes.
Goal
Select the most effective Google Cloud-native solution that meets all requirements with the least amount of custom scripting and operational overhead.
graph TD subgraph On-Prem Jenkins[Jenkins CI Server] end subgraph GCP AR[Artifact Registry] subgraph Dev Env GKE_Dev[GKE Cluster] end subgraph Staging Env GKE_Staging[GKE Cluster] end subgraph Prod Env GKE_Prod[GKE Cluster] end CD[Cloud Deploy] end Jenkins -- Pushes Image --> AR Jenkins -- Triggers --> CD CD -- Deploys to --> GKE_Dev CD -- Promotes to --> GKE_Staging CD -- Promotes to --> GKE_ProdShow answer & explanation
Correct answer: C
This solution directly maps all requirements to the native features of Cloud Deploy. Cloud Deploy is designed for managing multi-environment promotions. It has built-in support for canary deployment strategies, including phases, bake times, and manual approvals. It integrates with Jenkins via API calls, fulfilling the integration requirement. All actions, including promotions and approvals, are automatically captured in Cloud Audit Logs, satisfying the auditability requirement. This approach minimizes custom scripting and operational overhead.
- Question 7Beginner
Building and implementing CI/CD pipelines for applications and infrastructure · CI/CD pipeline triggers
True or False: Cloud Build requires source code to be stored in Cloud Source Repositories to trigger a build.
Show answer & explanation
Correct answer: B
This statement is false. Cloud Build can connect to various source code repositories, including Cloud Source Repositories, GitHub (Cloud and Enterprise), and Bitbucket (Cloud and Data Center). You can configure triggers to automatically start builds based on commits or pull requests from these external repositories.
- Question 8Intermediate
Implementing observability practices · Creating custom metrics from logs
You want to monitor the number of successful user checkouts per minute on your e-commerce site. This information is present in your application's structured JSON logs written to Cloud Logging, which contain a
jsonPayload.eventfield with the valuecheckout_success. How can you visualize this business metric on a Cloud Monitoring dashboard and set an alert if the rate drops unexpectedly?Show answer & explanation
Correct answer: D
Log-based metrics are the native Cloud feature designed for this exact purpose. You can create a metric that counts log entries matching a specific filter. This new metric then appears in Cloud Monitoring just like any standard system metric, allowing you to graph it on dashboards, analyze it in Metrics Explorer, and create alerting policies based on its value or rate of change. This approach does not require any code changes or complex external integrations.
- Question 9Intermediate
Bootstrapping and maintaining a Google Cloud organization · Designing the overall resource hierarchy for an organization
You are designing the Google Cloud resource hierarchy for a large enterprise. The enterprise has a central platform security team that needs to enforce security policies across the entire organization. You also need to provide isolated environments for the data science and web application development teams. Which folder and project structure best meets these requirements?
Show answer & explanation
Correct answer: C
This structure leverages the IAM policy inheritance of the resource hierarchy. By creating folders for each major business unit or function, you can grant permissions to the teams at the folder level, and those permissions will be inherited by all projects within that folder. The central security team can be granted organization-wide roles (like
Security Reviewer) at the top-level Organization node, giving them the necessary visibility and control across all folders and projects while maintaining a clean separation of duties and environments for the development teams. - Question 10Beginner
Optimizing performance and troubleshooting · Implementing debugging tools in Google Cloud
What is the primary purpose of Cloud Profiler when diagnosing application performance issues?
Show answer & explanation
Correct answer: C
Cloud Profiler is a statistical, low-overhead profiler that collects CPU consumption and memory allocation data from your production applications. Its primary purpose is to help you understand the resource consumption of your code, so you can identify and eliminate performance bottlenecks. It visualizes this data as flame graphs, making it easy to see which functions are the most resource-intensive.
Ready for the real thing?
The full PCDOE simulator has every exam-style question, timed mode, and instant scoring.