Skip to content

PCDOE Professional Cloud DevOps Engineer Practice Questions

Prepare for PCDOE with more than an answer.

180 questions in the full set20 sample questionsUpdated Jan 18, 2026
Exam fee
$200 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 5
  1. Bootstrapping and maintaining a Google Cloud organization17%
  2. Building and implementing CI/CD pipelines for applications and infrastructure27%
  3. Applying site reliability engineering practices to applications23%
  4. Implementing observability practices20%
  5. Optimizing performance and troubleshooting13%
  1. 1

    You are designing the Google Cloud resource hierarchy for a large enterprise. The enterprise has a central platform security team that needs to enforce security policies across the entire organization. You also need to provide isolated environments for the data science and web application development teams. Which folder and project structure best meets these requirements?

    Show answer details

    Correct answer: C

    This structure leverages the IAM policy inheritance of the resource hierarchy. By creating folders for each major business unit or function, you can grant permissions to the teams at the folder level, and those permissions will be inherited by all projects within that folder. The central security team can be granted organization-wide roles (like Security Reviewer) at the top-level Organization node, giving them the necessary visibility and control across all folders and projects while maintaining a clean separation of duties and environments for the development teams.

  2. 2

    What is the primary purpose of Cloud Profiler when diagnosing application performance issues?

    Show answer details

    Correct answer: C

    Cloud Profiler is a statistical, low-overhead profiler that collects CPU consumption and memory allocation data from your production applications. Its primary purpose is to help you understand the resource consumption of your code, so you can identify and eliminate performance bottlenecks. It visualizes this data as flame graphs, making it easy to see which functions are the most resource-intensive.

  3. 3

    You are deploying a Cloud Run service that needs to connect to a Cloud SQL database using a database password. To follow security best practices, you must avoid storing the password in the container image, in build logs, or as a plaintext environment variable. What is the recommended method to securely provide the password to the Cloud Run service at runtime?

    Show answer details

    Correct answer: C

    This is the most secure and manageable solution. Secret Manager is designed for storing secrets. Cloud Run has a direct integration with Secret Manager that allows you to mount a secret's value as a file in an in-memory volume or expose it directly as an environment variable. This process is handled by the Google Cloud infrastructure at runtime, ensuring the secret is never exposed in the container image, build process, or service configuration manifests. The Cloud Run service's runtime service account is granted IAM permission to access only the specific secret it needs.

  4. 4

    Your team's primary service has a 99.9% availability SLO. Due to a series of minor incidents, the service has completely consumed its error budget for the month with two weeks remaining. The product team wants to launch a new high-risk, high-reward feature immediately. According to SRE principles, what is the most appropriate course of action?

    Show answer details

    Correct answer: C

    The error budget is a data-driven tool for balancing reliability and feature velocity. When the budget is exhausted, the pre-agreed policy should be that the risk of further instability is too high. The team's focus must pivot from releasing new features (which introduce risk) to reliability-enhancing work. This could include fixing bugs, improving monitoring, automating manual tasks, or addressing root causes from recent incidents. The feature launch should be postponed until an adequate error budget is available again.

  5. 5

    The primary command-line interface (CLI) tool for interacting with and managing resources on Google Cloud Platform is known as the ______ CLI.

    Show answer details

    Correct answer: C

    The gcloud command-line tool is the main CLI for Google Cloud. It is part of the Google Cloud SDK and can be used to manage a wide range of products and services, including Compute Engine, GKE, Cloud Run, and IAM.

  6. 6

    An enterprise platform team manages dozens of GKE clusters for various development teams. They need to enforce a set of consistent security policies across all clusters, such as requiring all container images to be from a trusted Artifact Registry repository and disallowing pods from running with root privileges. What is the recommended Google Cloud solution to manage and enforce these policies at scale?

    Show answer details

    Correct answer: B

    GKE Enterprise (formerly Anthos) includes Policy Controller, which is built on the open-source Open Policy Agent (OPA) Gatekeeper project. It allows you to define policies as custom resources (constraints) and apply them centrally to a 'fleet' of GKE clusters. This provides a scalable, declarative, and GitOps-friendly way to enforce security and configuration consistency across an entire enterprise without manual intervention on individual clusters.

  7. 7

    During a postmortem for a cascading failure that impacted multiple services, your team identifies a lack of proper isolation as a key contributing factor. The failure of a non-critical downstream service caused a resource bottleneck that brought down a critical upstream service. Which THREE of the following SRE practices are most effective at preventing or mitigating such cascading failures? (Select THREE)

    flowchart TD A[Start Incident] --> B{Is critical service A affected?} B -- Yes --> C[Page Primary On-Call] B -- No --> D{Is non-critical service B affected?} C --> E[Execute Playbook A] D -- Yes --> F[Page Secondary On-Call] F --> G[Execute Playbook B] E --> H{Apply Mitigation} G --> H H --> I[Resolve Incident] I --> J[Conduct Postmortem]

    Show answer details

    Correct answer: A, C, E

    A circuit breaker wraps network calls. If a downstream service starts failing or timing out, the breaker 'trips' and immediately fails subsequent calls without waiting for a timeout. This prevents the upstream service from consuming resources (like threads or connections) waiting for a failing dependency, thus protecting it from the downstream failure.

    The bulkhead pattern partitions a service's resources (e.g., connection pools, thread pools) so that a failure in one area doesn't exhaust all resources and bring down the entire service. For example, calls to service A use one connection pool, and calls to service B use another. If service B fails, it only exhausts its own pool, leaving the pool for service A intact.

    Load shedding is the practice of intentionally dropping excess or low-priority requests when a system is overloaded. This ensures that the system can continue to serve high-priority traffic and remain stable, rather than failing completely for all users. It's a key strategy for preventing total collapse during unexpected load spikes or resource contention.

  8. 8

    A financial services company is building a CI/CD pipeline using Cloud Build and Cloud Deploy. To comply with internal security policies, they must ensure that only container images that have passed all vulnerability scans and integration tests are deployable to their production GKE clusters. Furthermore, the mechanism enforcing this must be resistant to tampering, even by users with project owner roles. Which combination of services should be implemented to meet these requirements?

    Show answer details

    Correct answer: C

    This is the most secure and tamper-resistant solution. Binary Authorization is a service specifically designed to enforce deployment-time policies on GKE. By creating a cryptographic attestation (a signature proving the image passed all checks) in a secure build environment and requiring that attestation in the GKE cluster's policy, you create a strong, auditable link. This enforcement happens at the GKE control plane level and cannot be easily bypassed, even by project owners, without modifying the Binary Authorization policy itself, which can be tightly controlled.

  9. 9

    You are the SRE lead for a critical order processing service composed of three microservices: an API Gateway, a Processing Service, and a Database Writer. The overall service is considered successful only if an order is accepted by the gateway, fully processed by the service, and successfully written to the database. The individual SLOs are: Gateway (99.95% availability), Processing Service (99.9% availability), and Database Writer (99.99% availability). Assuming these components fail independently, what is the correct composite SLO for the end-to-end user journey?

    Show answer details

    Correct answer: C

    For a user journey that depends on multiple components in series, the overall availability is the product of the individual component availabilities. Each component represents a potential point of failure for the entire transaction. Therefore, the composite SLO is calculated by multiplying the individual SLOs: 0.9995 * 0.999 * 0.9999 ≈ 0.9984, or 99.84%. This demonstrates that serial dependencies decrease overall reliability.

  10. 10

    You are managing a multi-tenant GKE cluster where each tenant application runs in its own namespace. One tenant deployed a custom Fluentd configuration as a DaemonSet to forward their specific application logs to an external analytics service. Shortly after, your central Cloud Logging view stops receiving any logs from the nodes where this tenant's pods are running. Logs from other applications on the same nodes are also missing. What is the most likely cause of this issue?

    Show answer details

    Correct answer: B

    GKE uses a managed Fluentd DaemonSet as its default logging agent on each node. When a user deploys another log-forwarding DaemonSet, especially one that also tries to read from standard log locations like /var/log, it can create resource contention or configuration conflicts. The most common issue is that the custom agent 'steals' the log files or interferes with the default agent's ability to read them, effectively stopping the flow of logs to Cloud Logging for that entire node.

Create an account to continue.