PCDOE sample questions with answers

10 free practice questions for the Professional Cloud DevOps Engineer exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Bootstrapping and maintaining a Google Cloud organization

Harlow Robotics' custom Cloud Workstations image copies shared IDE settings and a Git configuration into /home/user in its Dockerfile. The image builds correctly, and packages installed in the same Dockerfile are present, but on every workstation those home directory files are missing. What should you do?

  1. A.

    Move the home directory setup into a script in /etc/workstation-startup.d/, since /home is mounted from the disk at runtime.

  2. B.

    Rebuild the image with the files copied to /home/user a second time, because the first copy step was cached incorrectly.

  3. C.

    Increase the persistent disk size in the workstation configuration, because full disks cause the container to drop files from /home.

  4. D.

    Grant the workstation configuration's service account Storage Admin so that it can write files into /home at startup.

Show answer

Answer: A

Because /home is mounted from the persistent disk at runtime, home directory customization belongs in /etc/workstation-startup.d/ scripts.

  • A. The persistent disk is mounted over /home when the container starts, hiding build-time files; startup scripts run after the mount.
  • B. Any build-time content under /home is hidden by the runtime mount, so copying it again changes nothing.
  • C. Disk size isn't related; the files were never on the mounted disk.
  • D. No Google Cloud permission is involved in writing files into the container's home directory.
Question 2Bootstrapping and maintaining a Google Cloud organization

Rendal Freight must stop workloads in its twelve GKE clusters from running privileged containers or pulling images from unapproved registries. The rules must reject objects at admission, be expressed once for all clusters, and first report which existing workloads would violate them. What should you do?

  1. A.

    Write an organization policy constraint that lists approved registries and attach it to the folder containing the cluster projects.

  2. B.

    Add a Cloud Build step that searches every manifest in the repository for privileged: true and registry names before deployment.

  3. C.

    Install Policy Controller across the fleet, distribute the constraints with Config Sync, and run them in dryrun mode before enforcing.

  4. D.

    Schedule a daily job that lists running Pods with the Kubernetes API and deletes any Pod that is privileged or uses an unapproved image.

Show answer

Answer: C

Policy Controller enforces constraints at admission across a fleet, with dryrun to audit existing violations first.

  • A. Organization policies govern Google Cloud API resources, not the Pods and containers admitted inside a cluster.
  • B. A pipeline check misses anything deployed another way and can't report on workloads already running.
  • C. Policy Controller rejects violating objects at admission, and dryrun audits existing workloads without blocking them.
  • D. Deleting Pods afterwards is reactive, and controllers would simply recreate them.
Question 3Bootstrapping and maintaining a Google Cloud organization

Stanwick Insurance has dev, staging and production fleets of GKE clusters, all on the Regular release channel. Last quarter an automatic minor upgrade reached production before staging, and a regression went unnoticed. New versions must reach dev first, then staging, then production, with several days of soak between each. What should you do?

  1. A.

    Configure rollout sequencing that orders the dev, staging and production fleets with a soak time between each stage.

  2. B.

    Put dev on the Rapid channel, staging on Regular and production on Stable, and assume the channel delays will order the upgrades.

  3. C.

    Disable auto-upgrades everywhere and upgrade the three environments manually in order during quarterly change windows.

  4. D.

    Add maintenance exclusions to production until the staging team manually confirms each new version in a ticket.

Show answer

Answer: A

GKE rollout sequencing orders automatic upgrades across fleets with soak time between environments.

  • A. Rollout sequencing upgrades fleets in a defined order with soak time, so versions are qualified before production.
  • B. Channel differences don't guarantee ordering or soak time for the specific version that reaches each environment.
  • C. Manual quarterly upgrades lose automatic patching and let clusters fall behind.
  • D. Manual exclusions and tickets are error-prone, and long exclusions delay security patches.
Question 4Bootstrapping and maintaining a Google Cloud organization

Brisca Foods acquired a company whose projects must stay in a separate Google Cloud organization for at least a year. Applications in both organizations must talk over internal IP addresses, the subnet ranges don't overlap, and each side keeps its own network administrators. What should you do?

  1. A.

    Create Private Service Connect endpoints for Google APIs in both networks so that the applications can reach each other.

  2. B.

    Move all of the acquired company's projects into Brisca's organization now and rebuild their networks inside the host project.

  3. C.

    Connect the two organizations' VPC networks with VPC Network Peering, with each side's administrators configuring its half of the peering.

  4. D.

    Attach the acquired company's projects to Brisca's Shared VPC host project as service projects of that host.

Show answer

Answer: C

VPC Network Peering connects non-overlapping networks across organizations while each side keeps administrative control.

  • A. Endpoints for Google APIs reach Google services such as Cloud Storage, not applications in another customer's network.
  • B. The projects must remain in their own organization for a year, so this breaks a stated constraint.
  • C. Peering works between networks in different organizations, needs a configuration on each side, and leaves each network under its own administration.
  • D. Shared VPC requires the host and service projects to belong to the same organization.
Question 5Bootstrapping and maintaining a Google Cloud organization

Selham Water runs 600 Compute Engine VMs across three zones and patches them by hand, often weeks late. It wants automated monthly OS patching that never patches more than a few VMs of a service at once and runs checks before and after each VM is patched. What should you do? (Choose two.)

Choose 2.

  1. A.

    Enable automatic updates inside each guest OS and let every VM reboot whenever its package manager decides.

  2. B.

    Create a VM Manager patch deployment on a monthly schedule, rolling out one zone at a time with a disruption budget.

  3. C.

    Add pre-patch and post-patch scripts to the patch job to drain each VM first and verify its health afterwards.

  4. D.

    Rely on live migration, which Compute Engine uses to apply guest OS patches without restarting the VMs.

  5. E.

    Recreate all 600 VMs from the latest public image on the first day of each month in a single operation.

Show answer

Answer: B, C

VM Manager patch deployments with zonal rollout and a disruption budget, plus pre- and post-patch scripts, automate safe OS patching.

  • A. Uncoordinated reboots ignore the disruption limit and give no central checks or compliance reporting.
  • B. Patch deployments schedule patch jobs, and zonal rollout with a disruption budget limits how many VMs are patched together.
  • C. Patch jobs run pre-patch and post-patch scripts on each VM, providing the before and after checks.
  • D. Live migration moves VMs during host maintenance; it doesn't patch the guest operating system.
  • E. Recreating everything at once violates the limit on how many VMs of a service are disrupted together.
Question 6Bootstrapping and maintaining a Google Cloud organization

Node pool upgrades in Harrowby Labs' GKE Standard cluster keep failing with quota errors because the project has no spare regional CPU quota, and the quota can't be raised this month. The workloads tolerate losing one node at a time. What should you do?

  1. A.

    Set the node pool's surge settings to maxSurge=0 and maxUnavailable=1 so that no extra nodes are created during upgrades.

  2. B.

    Increase maxSurge to the number of nodes in the pool so that all replacement nodes are created in one quota request.

  3. C.

    Switch the node pool to the blue-green upgrade strategy so that the new nodes are created alongside the existing nodes before draining.

  4. D.

    Disable node auto-upgrade permanently so that the node pool never needs extra quota for upgrades again.

Show answer

Answer: A

Surge upgrades with maxSurge=0 and maxUnavailable=1 need no extra quota, at the cost of reduced capacity during the upgrade.

  • A. With no surge nodes, the upgrade needs no additional quota and replaces one node at a time within the workload's tolerance.
  • B. A larger surge requests more extra capacity at once, making the quota error certain.
  • C. Blue-green needs capacity for a second set of nodes, which demands even more quota.
  • D. Stopping upgrades leaves nodes unpatched and only postpones forced upgrades at end of support.
Question 7Bootstrapping and maintaining a Google Cloud organization

Every new project at Tamsin Retail gets a Compute Engine default service account holding the Editor role, and teams attach it to all their VMs. The organization predates 2024. Security wants new projects to stop receiving that grant and wants each application to run as its own least-privileged identity. What should you do?

  1. A.

    Restrict each VM's access scopes to read-only, which limits what the default service account's Editor role can do.

  2. B.

    Delete the default service account in every project so that no VM can run with the Editor role again.

  3. C.

    Enforce the constraint that stops automatic IAM grants to default service accounts, and give each application a dedicated service account.

  4. D.

    Remove the Editor role from each default service account by hand after every project is created, and keep attaching that account to all VMs.

Show answer

Answer: C

Enforce iam.automaticIamGrantsForDefaultServiceAccounts and run each application under its own dedicated service account.

  • A. Access scopes are coarse, and Google advises against relying on them instead of fine-grained roles.
  • B. This neither stops the grant in future projects nor gives applications their own identities, and deleted defaults can't be recreated.
  • C. The constraint stops the Editor grant in new projects, and per-application service accounts give each workload only the roles it needs.
  • D. Manual clean-up is error-prone, and a shared default account still mixes every application's permissions.
Question 8Bootstrapping and maintaining a Google Cloud organization

Kestner Defence's delivery pipeline pushes container images to an Artifact Registry repository that was created in the us multi-region years ago. A new contract requires every stored artifact for the workload to stay in the EU, and the resource locations constraint is now enforced on the workload's folder. What should you do?

  1. A.

    Create a repository in an EU location, copy the images with gcrane, repoint the pipeline, and delete the old repository.

  2. B.

    Rely on the enforced constraint, which moves the existing repository's images into an allowed EU location within a day.

  3. C.

    Edit the existing repository's location to the europe multi-region, since Artifact Registry moves the stored images automatically.

  4. D.

    Protect the repository with a customer-managed encryption key held in an EU key ring, which keeps the stored images in the EU.

Show answer

Answer: A

An Artifact Registry repository's location is fixed at creation, so meeting a new residency rule means creating a repository in an allowed location and migrating the artifacts.

  • A. A new EU repository plus a digest-preserving copy and cleanup puts every stored image in an allowed location.
  • B. The constraint only restricts where new resources are created; existing repositories stay where they are.
  • C. Repository location cannot be changed after creation, so there is no in-place move.
  • D. CMEK location governs the key, not where the repository stores its encrypted images.
Question 9Bootstrapping and maintaining a Google Cloud organization

Two engineers at Merrow Robotics ran terraform apply at the same time, and the second run destroyed a subnet that the first had just created. State lives in a Cloud Storage bucket used as the gcs backend. Concurrent applies must fail fast, and a damaged state file must be recoverable. What should you do?

  1. A.

    Keep the gcs backend, which locks state during operations, and turn on object versioning on the state bucket for recovery.

  2. B.

    Add a Cloud Scheduler job that serializes changes by running terraform apply once an hour from one shared service account.

  3. C.

    Switch to the local backend on a shared Compute Engine instance that only one engineer can sign in to at a time.

  4. D.

    Move the state file into the Git repository and rely on merge conflicts to stop two engineers from applying at once.

Show answer

Answer: A

The Cloud Storage backend supports state locking, and object versioning on the bucket allows recovery of earlier state.

  • A. The Cloud Storage backend supports state locking, and object versioning keeps earlier state generations to restore from.
  • B. Hourly batch applies remove review of individual plans and do not stop engineers from applying directly.
  • C. A shared VM is a single point of failure and relies on sign-in discipline instead of state locking.
  • D. State in Git has no locking, and state can contain sensitive values that shouldn't be committed.
Question 10Bootstrapping and maintaining a Google Cloud organization

Hexham Data's Cloud Build private pool, peered with its VPC network, must now call a partner's artifact API that accepts requests only from one allowlisted IP address. Builds are rejected because their source address changes from build to build. The partner won't allowlist a range. What should you do?

  1. A.

    Move the builds to the default pool, whose workers use a documented fixed IP address that partners can allowlist.

  2. B.

    Route requests for the partner's range from the peered network to a proxy VM with a static external IP, exporting the custom route to the pool.

  3. C.

    Set the private pool's egress option to NOPUBLICEGRESS so that all builds use one fixed internal address instead.

  4. D.

    Reserve a static external IP address and assign it to the private pool in the pool's worker configuration.

Show answer

Answer: B

Private pool external IPs can't be controlled, so traffic that needs a fixed source address must be routed through a proxy VM with a static external IP.

  • A. Default-pool workers don't have a single fixed address to give the partner.
  • B. Private pool external IPs aren't static or configurable; Google documents routing such traffic through a proxy VM with a reserved address.
  • C. Removing public egress blocks internet access altogether, so the partner's API can't be reached at all.
  • D. Private pools don't let you assign or control their external IP addresses.

Keep going with 490 more PCDOE questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

PCDOE sample questions with answers (10 free) · CertifyCloudx