PCD Practice Questions
Prepare for PCD with more than an answer.
Unlock the full exam and previous versions
- v1Google Cloud Professional Cloud Developer 156 questions Locked
- PCDLegacy Professional Cloud Developer 289 questions Current
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- Bootstrapping and maintaining a Google Cloud organization17%
- Building and implementing CI/CD pipelines for applications and infrastructure27%
- Applying site reliability engineering practices to applications23%
- Implementing observability practices20%
- Optimizing performance and troubleshooting13%
- 1
A logistics company has a monolithic Java application responsible for tracking shipments. They want to break it down into microservices running on GKE. The first step is to externalize session state, which is currently stored in-memory, to a managed service to allow the new shipment status service to be stateless and horizontally scalable. The session data is small but needs to be accessed with very low latency (sub-millisecond). Which service should they use for session management?
Show answer details
Correct answer: C
Memorystore for Redis is a fully managed in-memory data store service. It is designed for use cases that require extremely low latency, such as caching and session management. Its sub-millisecond latency makes it the perfect choice for externalizing session state for a high-performance microservice, allowing the service to become stateless and easily scalable.
- 2
You are managing a GKE cluster and need to configure autoscaling for a stateless web application. The application's load is directly proportional to the number of incoming HTTP requests per second. You want the number of pods to scale up when the request rate exceeds 100 requests per second per pod. Which type of metric should you configure in your HorizontalPodAutoscaler (HPA) definition?
Show answer details
Correct answer: C
To scale based on requests per second (RPS), you should use an Object metric. The HPA can be configured to query a metric from another object in the same namespace, such as the Ingress object, which often exposes RPS metrics. This allows the HPA to scale the backend pods directly based on the traffic metric that matters most, rather than an indirect proxy like CPU utilization.
- 3
A developer is writing an application that needs to grant users temporary, read-only access to specific, private objects in a Cloud Storage bucket. The users do not have Google accounts. The access needs to be time-limited and secure. What is the most appropriate mechanism to provide this access?
Show answer details
Correct answer: C
Signed URLs are the perfect solution for this scenario. A signed URL is a URL that provides time-limited resource access to anyone who has the URL, regardless of whether they have a Google account. The application, using its own service account credentials, can generate a signed URL with a specific expiration time and grant read access to a private object. This provides secure, temporary, and granular access.
- 4
You are tasked with deploying a containerized web application to GKE that requires a persistent, read-write filesystem accessible by multiple pods simultaneously. The data is primarily unstructured files, and the storage needs to be a managed service. Which storage solution should you configure for the pods' PersistentVolumeClaim?
Show answer details
Correct answer: D
The key requirement is a filesystem that can be mounted as read-write by multiple pods at the same time. This corresponds to the
ReadWriteMany(RWX) access mode in Kubernetes. Filestore is Google Cloud's managed NFS (Network File System) service, which is designed to provide shared file storage and supports the RWX access mode, making it the correct choice. Persistent Disks are block storage and typically only supportReadWriteOnce(RWO). - 5
An application is being developed to run in three different environments: on a developer's local machine, in a staging GKE cluster, and in a production Cloud Run environment. The developer wants to write a single authentication logic that works seamlessly across all three environments without requiring manual management of service account keys. Which authentication strategy should be used?
flowchart TD subgraph Local Machine A[gcloud auth application-default login] end subgraph GKE Cluster B[Workload Identity] end subgraph Cloud Run C[Attached Service Account] end AppCode[Application Code] -->|Uses ADC Library| D{ADC Logic} D --> |Finds User Creds| A D --> |Finds GKE Metadata| B D --> |Finds Compute Metadata| CShow answer details
Correct answer: B
Application Default Credentials (ADC) is the recommended strategy for portable authentication. The ADC library automatically searches for credentials in a specific order: first checking for environment variables, then looking for credentials created via the gcloud CLI (for local development), and finally querying the metadata server (for services like GKE with Workload Identity or Cloud Run). This allows the same code to authenticate correctly in each environment without modification.
- 6
A financial services company is building a new real-time fraud detection system on Google Cloud. The system must process millions of transactions per second with extremely low latency. A key requirement is that the database must provide strongly consistent reads across multiple geographic regions (North America, Europe, and Asia) to prevent transnational fraud. The development team is evaluating database options. Which data storage solution is the most appropriate choice to meet these specific requirements?
Show answer details
Correct answer: B
Cloud Spanner is the only horizontally scalable, strongly consistent, relational database service that is specifically designed for multi-regional deployments with strong consistency. This directly meets the core requirement for strongly consistent reads across geographic regions to prevent fraud. Cloud Bigtable offers eventual consistency for multi-cluster routing. AlloyDB and Cloud SQL are regional services and cannot provide strongly consistent reads across multiple regions.
- 7
A development team is using Cloud Build for their CI/CD pipeline. To improve security, they need to ensure that only container images that have passed a specific 'QA-Approved' vulnerability scan level in Artifact Analysis are allowed to be deployed to their production GKE cluster. Any attempt to deploy an image that does not have this attestation should be blocked. What should the team implement to enforce this policy?
Show answer details
Correct answer: C
Binary Authorization is the Google Cloud service designed for this exact purpose. It allows you to create policies that enforce deploy-time security controls, ensuring that only trusted container images are deployed on GKE. You would create an attestor (a trusted authority) and configure your Cloud Build pipeline to create an attestation for an image only after it passes the QA vulnerability scan. The Binary Authorization policy on the GKE cluster would then check for this specific attestation at deployment time.
- 8
You are instrumenting a Node.js application deployed on Cloud Run to send custom metrics to Cloud Monitoring. After deploying your code, you notice that no data appears in Metrics Explorer for your custom metric. The application logs in Cloud Logging show no errors related to authentication or metric publishing. You have already verified that the Cloud Monitoring API is enabled for the project. Which of the following is the most likely cause of the issue?
Show answer details
Correct answer: B
Before you can write time series data for a custom metric, you must first create a metric descriptor, which defines the metadata for the metric, including its type, kind, and labels. The Monitoring API will silently drop data points written for a metric that does not have a corresponding descriptor. Since there are no authentication errors, this is the most probable cause.
- 9
A developer is building an event-driven processing pipeline. The architecture requires that when a file is uploaded to a Cloud Storage bucket, a message containing the file's metadata is sent to a Pub/Sub topic. This message should then trigger a Cloud Run service for processing. The developer wants to set this up using a direct, event-based mechanism without writing custom trigger code. Which Google Cloud service should be used to connect the Cloud Storage event to the Pub/Sub topic?
Show answer details
Correct answer: C
Eventarc is designed to build event-driven architectures by creating triggers that route events from various Google Cloud sources (like Cloud Storage) to sinks (like Pub/Sub, Cloud Run, etc.). It provides a standardized way to manage the flow of events without needing to write custom code for the trigger mechanism itself.
- 10
A developer needs to deploy a containerized application to a new GKE cluster. The application has a web frontend and a backend processing service that communicate with each other. For security, the developer must prevent all other pods in the cluster from communicating with the backend service, while still allowing the frontend pods to reach it. Which Kubernetes object should be created to enforce this traffic rule?
Show answer details
Correct answer: C
A Kubernetes NetworkPolicy is the standard way to control traffic flow at the IP address or port level (OSI layer 3 or 4) between pods in a cluster. You can define an ingress rule for the backend pods that specifically allows traffic only from pods with the frontend's label, while denying all other in-cluster traffic by default.
