PCD sample questions with answers

10 free practice questions for the Professional Cloud Developer exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Designing highly scalable, secure, and reliable cloud-native applications

A gaming studio's CI system runs outside Google Cloud and authenticates with a downloaded service account JSON key. Policy now forbids long-lived keys and an organization policy blocks key creation, but deployments must still push images to Artifact Registry and deploy Cloud Run revisions. Which two actions should you take? (Choose TWO.)

Choose 2.

  1. A.

    Create a workload identity pool and OIDC provider trusting the CI issuer, with an attribute condition on repository and branch.

  2. B.

    Grant the federated principal set roles/iam.workloadIdentityUser on the deployer service account so CI can impersonate it.

  3. C.

    Store the existing JSON key in Secret Manager and fetch it at the start of each pipeline run.

  4. D.

    Grant the CI system's user account roles/owner on the project.

  5. E.

    Create a second service account whose key expires after 90 days and rotate it on a schedule.

Show answer

Answer: A, B

Workload Identity Federation exchanges the CI system's own OIDC token for short-lived Google credentials, so no service account key is ever created.

  • A. A workload identity pool with an OIDC provider and an attribute condition establishes trust in the CI issuer while limiting it to the intended repository and branch.
  • B. roles/iam.workloadIdentityUser on the deployer service account lets the federated identity impersonate it and receive short-lived tokens instead of a key.
  • C. Secret Manager improves where the key is stored but the credential is still long-lived and exfiltratable, so the policy is not satisfied.
  • D. Granting Owner violates least privilege spectacularly and does not remove the need for a credential that CI can present to Google Cloud.
  • E. This still produces a downloadable service account key, which the new policy forbids and the organization policy constraint blocks outright.
Question 2Designing highly scalable, secure, and reliable cloud-native applications

A healthcare platform runs on GKE. An engineer recently deployed an image built on a laptop and pushed straight to Artifact Registry. Leadership now requires that only images built by the Cloud Build pipeline and scanned with no critical vulnerabilities can run in production, blocked at deploy time rather than detected afterwards, while the sandbox cluster still runs arbitrary images. What should you do?

  1. A.

    Enable Binary Authorization on the production cluster requiring Cloud Build and vulnerability-scanning attestations, with an allow-all rule for the sandbox cluster.

  2. B.

    Turn on Artifact Analysis scanning and alert the platform team from Security Command Center on critical findings.

  3. C.

    Remove artifactregistry.writer from all users so only the Cloud Build service account can push images.

  4. D.

    Add a Cloud Build step that fails the build when a critical vulnerability is found, and deploy only from that pipeline.

Show answer

Answer: A

Binary Authorization is the admission-time control that rejects images lacking the required build and vulnerability attestations, and its rules can differ per cluster.

  • A. Binary Authorization enforces attestation requirements at admission, and cluster-specific rules let production be strict while the sandbox stays permissive.
  • B. Scanning plus alerting detects problems after the workload is already running, which fails the requirement to block at deploy time.
  • C. Locking down push access does not prevent the cluster from pulling images from other registries and enforces nothing about vulnerability scan results.
  • D. A failing build step only protects images that go through the pipeline; it cannot stop a manifest that points at an image built elsewhere.
Question 3Designing highly scalable, secure, and reliable cloud-native applications

A public Cloud Run service, quote-api, calls a private Cloud Run service, risk-engine. Only quote-api may call risk-engine, and Google Cloud rather than a shared secret must authenticate the call. Each service already has its own service account, and the team wants no certificates or sidecars. What should you do?

  1. A.

    Put both services in Cloud Service Mesh with strict mTLS and an authorization policy.

  2. B.

    Set risk-engine ingress to internal, grant quote-api's service account roles/run.invoker, and send a metadata-server ID token as a bearer token.

  3. C.

    Grant quote-api's service account roles/run.admin on the project.

  4. D.

    Keep risk-engine public and validate a static API key that quote-api sends in a header.

Show answer

Answer: B

Restrict ingress, grant run.invoker to the caller's service account, and authenticate the call with a Google-signed ID token from the metadata server.

  • A. Cloud Service Mesh adds a data plane and configuration burden the team ruled out, and it is aimed at mesh workloads rather than two managed Cloud Run services.
  • B. Internal ingress, run.invoker on the caller's service account, and a metadata-server ID token scoped to the target URL is the documented Cloud Run pattern.
  • C. roles/run.admin grants administrative control over every Cloud Run service in the project, violating least privilege, and still does not authenticate the request.
  • D. A static API key is a copyable shared secret, leaves the service open to the internet, and the platform cannot attribute the call to an identity.
Question 4Designing highly scalable, secure, and reliable cloud-native applications

A subscription billing platform is migrating to Spanner. Every read of an invoice also reads its line items, and both tables use auto-incrementing integer primary keys and join on account_id. Load tests show write throughput plateauing and join latency growing with data volume. You must improve write distribution and read locality. What should you do?

  1. A.

    Keep the auto-incrementing keys and add Spanner nodes until the write plateau disappears.

  2. B.

    Denormalize line items into a JSON column on Invoices and parse it in the application.

  3. C.

    Keep the auto-incrementing keys and add a secondary index on accountid and invoiceid.

  4. D.

    Use a UUID or hashed primary key and interleave LineItems in Invoices so parent and child rows are stored together.

Show answer

Answer: D

Non-sequential primary keys spread writes across splits and interleaving physically colocates child rows with their parent for locality.

  • A. Adding nodes does not help when all inserts target the final split; the hotspot simply persists on one leader while the extra nodes idle.
  • B. A JSON blob prevents indexed queries on line items, forces whole-row rewrites for any change, and gives up Spanner's relational guarantees.
  • C. An index speeds lookups but leaves the monotonic key hotspot in place and still requires a distributed join for parent and child rows.
  • D. A non-sequential key removes the last-split write hotspot, and interleaving colocates line items with their invoice so the common read is local.
Question 5Designing highly scalable, secure, and reliable cloud-native applications

A global loyalty program stores point balances in a multi-region Spanner instance. A reporting endpoint renders recent transactions millions of times per hour and tolerates data a few seconds old, while redemptions must never let a member spend points twice. Reporting reads are adding latency and CPU pressure, which you must reduce without weakening redemption correctness. What should you do?

  1. A.

    Put a Memorystore cache with a ten-second TTL in front of both endpoints.

  2. B.

    Change the redemption endpoint to partitioned DML so the balance update runs across splits in parallel.

  3. C.

    Serve both endpoints from a nearby read replica using strong read-only sessions.

  4. D.

    Serve reporting with read-only transactions at bounded or exact staleness, and keep redemptions in read-write transactions.

Show answer

Answer: D

Stale read-only transactions let reporting be served cheaply from any replica while redemptions keep strong read-write transaction semantics.

  • A. Caching the redemption path would let concurrent redemptions read the same stale balance and double-spend, breaking the stated correctness requirement.
  • B. Partitioned DML targets large bulk updates and provides no cross-statement transactional guarantee, so it cannot protect a read-modify-write balance change.
  • C. A strong read still requires the replica to confirm it has applied all committed transactions, so leader coordination and the associated latency remain.
  • D. Stale read-only transactions are served locally without leader coordination or locks, while read-write transactions preserve strong consistency for redemption.
Question 6Designing highly scalable, secure, and reliable cloud-native applications

A ticketing platform serves a seat-availability endpoint from GKE backed by Cloud SQL. During on-sale events the same 300 records are read tens of thousands of times per minute, database CPU saturates, and p99 latency passes two seconds. The data may be up to 15 seconds stale, and the team will not change the relational schema. What should you do?

  1. A.

    Move Cloud SQL to a larger machine type and raise each Pod's connection pool size.

  2. B.

    Export the event rows to Cloud Storage every minute and read the JSON objects instead.

  3. C.

    Add a cache-aside layer in Memorystore for Redis with a 15-second TTL for seat-availability reads.

  4. D.

    Add two Cloud SQL read replicas and round-robin every seat-availability query to them.

Show answer

Answer: C

A Memorystore for Redis cache-aside layer with a short TTL absorbs the repeated reads and cuts both database load and tail latency.

  • A. Vertical scaling buys headroom at permanent cost and does not remove the redundant queries; raising pool size increases PostgreSQL connection contention.
  • B. Object reads from Cloud Storage are tens of milliseconds and the export job adds an operational pipeline, so this is slower and more complex than caching.
  • C. Cache-aside on Memorystore serves the hot 300 records from memory, and the 15-second TTL matches the stated staleness tolerance exactly.
  • D. Read replicas spread query load but every read still executes on a database engine, so p99 latency stays high and the cost per request is far greater than a cache hit.
Question 7Designing highly scalable, secure, and reliable cloud-native applications

Technicians using a new mobile app see only their own job documents, which must stay available offline and sync when signal returns. Job fields vary by type, and dispatchers need live status updates. Which storage service should you choose?

  1. A.

    Bigtable with a row per job, polled by the dashboard every five seconds.

  2. B.

    Spanner with a table per job type and a change stream feeding the dashboard.

  3. C.

    Cloud SQL for PostgreSQL with a JSONB column and a polling endpoint for the dashboard.

  4. D.

    Firestore in Native mode, using offline persistence in the mobile SDK and real-time listeners.

Show answer

Answer: D

Firestore in Native mode is the document database whose SDKs provide offline persistence and real-time listeners for exactly this mobile pattern.

  • A. Bigtable targets massive wide-column workloads, offers no offline SDK or real-time listeners, and cannot serve the varied document queries needed.
  • B. Spanner is oversized and costly for 50 documents per technician, has no offline mobile SDK, and a table per job type is poor schema design.
  • C. Cloud SQL provides no offline client cache or change push, so the dashboard must poll and technicians lose functionality without connectivity.
  • D. Firestore offers a flexible document model, mobile SDK offline persistence with automatic sync, real-time listeners, and serverless scaling.
Question 8Designing highly scalable, secure, and reliable cloud-native applications

An internal expense-approval app on Compute Engine sits behind a global external Application Load Balancer and has no authentication. Only members of a Google Group may use it, contractors on unmanaged laptops must reach it without a VPN, the identity check must happen before the request reaches the instances, and the app needs the signed-in user's email. What should you do?

  1. A.

    Add a sign-in page with Identity Platform and validate the ID token in application middleware.

  2. B.

    Move the instances to a private subnet and require Cloud VPN before opening the app URL.

  3. C.

    Enable Identity-Aware Proxy on the backend service, grant the group roles/iap.httpsResourceAccessor, and read the signed IAP JWT header.

  4. D.

    Add Cloud Armor rules that allow only the corporate office IP ranges and block every other source address.

Show answer

Answer: C

Identity-Aware Proxy authenticates and authorizes at the load balancer before traffic reaches the VMs, and passes a signed JWT with the user's identity.

  • A. Identity Platform targets customer identity and requires building sign-in into the application, which the scenario rules out, and traffic still reaches the VMs unauthenticated.
  • B. Requiring Cloud VPN directly violates the constraint that contractors on unmanaged laptops must connect without a VPN client.
  • C. IAP enforces Google sign-in and IAM group membership at the load balancer and hands the application a signed JWT carrying the verified email.
  • D. IP allowlisting authenticates a network location rather than a person, so it blocks remote contractors and would admit anyone on an allowed network.
Question 9Designing highly scalable, secure, and reliable cloud-native applications

A logistics startup hosts a gRPC telemetry API on Cloud Run. Vehicle gateways open a long-lived server-streaming call over the public internet, but the stream closes immediately after connecting, while a unary REST endpoint on the same service works. What should you do?

  1. A.

    Redeploy the service with end-to-end HTTP/2 enabled and raise the request timeout to cover the stream.

  2. B.

    Enable gRPC transcoding on API Gateway so calls are translated to JSON over HTTP/1.1.

  3. C.

    Convert the method to unary and have gateways poll every five seconds over HTTP/1.1.

  4. D.

    Put the service behind an internal passthrough Network Load Balancer so that gRPC frames are forwarded without inspection.

Show answer

Answer: A

Cloud Run must be configured for end-to-end HTTP/2 and a long request timeout before it can serve gRPC streaming.

  • A. End-to-end HTTP/2 lets the container terminate the gRPC connection itself, and a longer request timeout keeps the server-streaming call open.
  • B. Transcoding converts REST/JSON calls into gRPC for the backend; it does not support client streaming and does not fix the missing HTTP/2 path.
  • C. Polling replaces the required push model, increases request volume and cost, and adds up to five seconds of latency to every route update.
  • D. Cloud Run services are exposed through serverless network endpoint groups, not passthrough Network Load Balancers, and an internal load balancer would not serve public clients.
Question 10Designing highly scalable, secure, and reliable cloud-native applications

An online learning company serves interactive labs from Compute Engine instance groups behind a global external Application Load Balancer. Each session builds a large in-memory workspace that takes 20 seconds to rebuild, and learners' labs reset when later requests land on a different backend. The workspace cannot move to shared storage this term. What should you do?

  1. A.

    Enable generated cookie session affinity on the backend service with a TTL covering a lab session.

  2. B.

    Reserve a static external IP address for each instance and have each learner connect to it directly.

  3. C.

    Change the backend service locality policy to RING_HASH so requests are distributed deterministically.

  4. D.

    Enable Cloud CDN on the backend service with cache mode USEORIGINHEADERS.

Show answer

Answer: A

Generated cookie affinity on the backend service pins a client's requests to one backend instance for the configured cookie lifetime.

  • A. Generated cookie affinity makes the load balancer issue a cookie and route every request carrying it to the same backend for the cookie TTL.
  • B. Direct per-instance public IPs bypass the load balancer, so health checking, autohealing, and managed TLS are lost and instance replacement breaks every session.
  • C. RING_HASH is a load balancing locality policy; without a session affinity setting it does not guarantee that a given user always reaches the same instance.
  • D. Cloud CDN caches shared responses at the edge and does nothing for per-user in-memory state; it can even return one learner's cached page to another.

Keep going with 490 more PCD questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

PCD sample questions with answers (10 free) · CertifyCloudx