Google CloudProfessional

Professional Cloud Developer

PCD

Build scalable, highly available cloud-native applications using Google-recommended tools and best practices.

Duration
120 min
Exam questions
50–60
Passing score
Pass / Fail (undisclosed)
Exam fee
$200
Question formats:Multiple choiceMultiple response
Free plan
3 free papers
Free account
Mocks locked
Pro only
Upgrade to Pro
Every paper and mock exam.
See Pro

Start with free papers Free

You get 3 free practice papers with your plan.

Free
Mixed paper 1
Domain 1 · 25 questions
Free
Mixed paper 2
Domain 1 · 25 questions
Free
Mixed paper 3
Domain 1 · 25 questions

Domain papers 500 questions

Free
Mixed paper 1
25 questions · 60 min
Free
Mixed paper 2
25 questions · 60 min
Free
Mixed paper 3
25 questions · 60 min
Pro
Mixed paper 4
25 questions · 60 min
Pro
Mixed paper 5
25 questions · 60 min
Pro
Mixed paper 6
25 questions · 60 min
Pro
Mixed paper 7
25 questions · 60 min
Pro
Mixed paper 8
14 questions · 34 min

Mock exams Pro

Full-length, exam-like practice tests. Available with Pro.

Mock exam 1
55 questions · 120 min
Mock exam 2
55 questions · 120 min
Mock exam 3
55 questions · 120 min

Try a sample question

All 10 sample questions →
Question 1Designing highly scalable, secure, and reliable cloud-native applications

A gaming studio's CI system runs outside Google Cloud and authenticates with a downloaded service account JSON key. Policy now forbids long-lived keys and an organization policy blocks key creation, but deployments must still push images to Artifact Registry and deploy Cloud Run revisions. Which two actions should you take? (Choose TWO.)

Choose 2.

  1. A.

    Create a workload identity pool and OIDC provider trusting the CI issuer, with an attribute condition on repository and branch.

  2. B.

    Grant the federated principal set roles/iam.workloadIdentityUser on the deployer service account so CI can impersonate it.

  3. C.

    Store the existing JSON key in Secret Manager and fetch it at the start of each pipeline run.

  4. D.

    Grant the CI system's user account roles/owner on the project.

  5. E.

    Create a second service account whose key expires after 90 days and rotate it on a schedule.

Show answer

Answer: A, B

Workload Identity Federation exchanges the CI system's own OIDC token for short-lived Google credentials, so no service account key is ever created.

  • A. A workload identity pool with an OIDC provider and an attribute condition establishes trust in the CI issuer while limiting it to the intended repository and branch.
  • B. roles/iam.workloadIdentityUser on the deployer service account lets the federated identity impersonate it and receive short-lived tokens instead of a key.
  • C. Secret Manager improves where the key is stored but the credential is still long-lived and exfiltratable, so the policy is not satisfied.
  • D. Granting Owner violates least privilege spectacularly and does not remove the need for a credential that CI can present to Google Cloud.
  • E. This still produces a downloadable service account key, which the new policy forbids and the organization policy constraint blocks outright.

What's on the exam

4 domains · 11 task statements, straight from the official exam guide (as of 2026-09-14).

  1. 1.1Designing high-performing applications and APIs
    • Choosing the appropriate platform based on the use case and requirements (e.g., Compute Engine, Google Kubernetes Engine, Cloud Run)
    • Building, refactoring, and deploying application containers to Cloud Run and GKE
    • Understanding how Google Cloud services are geographically distributed (e.g., latency, regional services, zonal services)
    • Understanding the use cases for load balancers
    • Enabling session affinity for performant content delivery
    • Implementing caching solutions (e.g., Memorystore)
    • Creating and deploying APIs (e.g., HTTP REST, gRPC [Remote Procedure Call])
    • Using application rate limiting, authentication, and observability (e.g., Apigee, Cloud API Gateway)
    • Integrating applications using asynchronous or event-driven approaches (e.g., Eventarc, Pub/Sub)
    • Defining resource requirements for workloads
    • Optimizing for cost and resource usage
    • Understanding data replication to support zonal and regional failover models
    • Using traffic splitting strategies (e.g., gradual rollouts, rollbacks, A/B testing) on a new service on Cloud Run or GKE
    • Orchestrating application services with Workflows, Eventarc, Cloud Tasks, and Cloud Scheduler
  2. 1.2Designing secure applications
    • Implementing data retention and organization policies (e.g., Cloud Storage Object Lifecycle Management, Cloud Storage use and lock retention policies)
    • Using security mechanisms that identify vulnerabilities and protect services and resources (e.g., Identity-Aware Proxy [IAP], Web Security Scanner)
    • Responding to and resolving vulnerabilities, including those identified by Artifact Analysis and Security Command Center
    • Storing, accessing, and rotating application secrets, credentials, and encryption keys (e.g., Secret Manager, Cloud Key Management Service, Workload Identity Federation)
    • Authenticating to Google Cloud services (e.g., Application Default Credentials, JSON Web Token [JWT], OAuth 2.0, Cloud SQL Auth Proxy, AlloyDB Auth Proxy, Identity Platform, WIF)
    • Securing cloud resources using Identity and Access Management (IAM) roles for service accounts
    • Incorporating secure service-to-service communications (e.g., Cloud Service Mesh, Kubernetes Network Policies, Direct VPC egress, private service connectivity)
    • Running services with least privileged access
    • Securing application artifacts using Binary Authorization
  3. 1.3Storing and accessing data
    • Selecting the appropriate storage system based on the volume of data and performance requirements
    • Designing appropriate schemas for structured databases (e.g., AlloyDB, Spanner) and unstructured databases (e.g., Bigtable, Firestore)
    • Understanding the implications of eventual and strongly consistent replication of AlloyDB, Bigtable, Cloud SQL, Spanner, and Cloud Storage
    • Creating signed URLs to grant access to Cloud Storage objects
    • Writing data to BigQuery for analytics and AI/ML workloads

Outline reproduced from the vendor's public exam guide for study reference.Official guide

PCD practice — frequently asked questions

Are these real PCD exam questions?

No. Every question on CertifyCloudx is original, written by us against Google Cloud's publicly available PCD exam guide to rehearse the skills it lists. None are actual exam questions, and CertifyCloudx is not affiliated with or endorsed by Google Cloud.

How many PCD practice questions are there?

500 practice questions, including 3 full-length timed mock exams and 47 domain papers of up to 25 questions (mixed and by topic). Every question has a detailed explanation of why the right answer wins and why each distractor loses.

Is the content up to date with the current PCD exam guide?

The questions are written against the PCD exam guide dated 2026-09-14, and we revise them when Google Cloud updates the guide.

What question formats are covered?

The same formats the real PCD uses: Multiple choice, Multiple response. Each is rendered and graded the way the exam does it.

How long is the PCD exam and how many questions does it have?

According to Google Cloud's published exam details: 50–60 questions, 120 minutes, passing score Pass / Fail (undisclosed). Our mock exams use the same time limit, with a question count in the middle of that range. Always confirm current details with Google Cloud before booking.

Can I practise PCD for free?

Yes. 3 papers are free, with up to 10 questions a day on the free plan and no card needed. Pro unlocks every paper and mock exam with no daily limit.

Does CertifyCloudx guarantee that I will pass?

No practice material can guarantee a result. CertifyCloudx helps you find and close your weak areas — accuracy by exam-guide domain and topic shows what to study next.