PCDOE — Google Cloud Certified Professional Cloud DevOps Engineer
Google

Google Cloud Certified Professional Cloud DevOps Engineer (PCDOE) Practice Questions

★★★★★ 5.0 124 verified reviews
75 questions
2026-06-22 updated
✓ Online quiz simulator

Domain coverage

  • Applying Site Reliability Engineering principles
  • Building and implementing CI/CD pipelines
  • Implementing service monitoring strategies
  • Managing service incidents
  • Optimizing service performance and cost

Sample Questions (8 of 75 shown)

Q1 Bootstrapping a Google Cloud organization for DevOps
Your company runs applications in Google Kubernetes Engine (GKE). Application developers frequently create cloud resources to support their applications. You need to give developers the ability to manage infrastructure as code while adhering to Google-recommended practices. You want to manage infrastructure as code through Kubernetes Custom Resource Definitions (CRDs) and ensure that your chosen setup can be supported by the Google Cloud Support Portal. What should you do?
  1. Configure Cloud Build with a Terraform builder to execute the terraform plan and terraform apply commands.
  2. Install and configure Crossplane in GKE.
  3. Configure a GitHub Action with a Terraform builder to execute the terraform plan and terraform apply commands as part of the pull request process.
  4. Install and configure Config Connector in GKE.
✓ Correct Answer: D
D. Config Connector manages GCP resources via Kubernetes CRDs as IaC with Google Cloud Support Portal compatibility. Crossplane (B) is open-source, not Google-supported.
Q2 Bootstrapping a Google Cloud organization for DevOps
Your company runs services on Google Cloud. Each team runs their applications in a dedicated project. New teams and projects are created regularly. Your security team requires that all logs are processed by a security information and event management (SIEM) system. The SIEM ingests logs by using Pub/Sub. You must ensure that all existing and future logs are scanned by the SIEM. What should you do?
  1. Create an organization-level aggregated sink with a siem log bucket as the destination. Set an inclusion filter to include all logs.
  2. Create a folder-level aggregated sink with a siem Pub/Sub topic as the destination. Set an inclusion filter to include all logs. Repeat for each folder.
  3. Create an organization-level aggregated sink with a siem Pub/Sub topic as the destination. Set an inclusion filter to include all logs.
  4. Create a project-level logging sink with a siem Pub/Sub topic as the destination. Set an inclusion filter to include all logs. Repeat for each project.
✓ Correct Answer: C
C. Organization-level aggregated log sink with Pub/Sub destination captures logs from all current and future projects in one configuration.
Q3 Bootstrapping a Google Cloud organization for DevOps
Your company allows teams to self-manage Google Cloud projects, including project-level Identity and Access Management (IAM). You are concerned that the team responsible for the Shared VPC project might accidentally delete the project, so a lien has been placed on the project. You need to design a solution to restrict Shared VPC project deletion to those with the resourcemanager.projects.updateLiens permission at the organization level. What should you do?
  1. Instruct teams to only perform IAM permission management as code with Terraform.
  2. Enable VPC Service Controls for the container.googleapis.com API service.
  3. Revoke the resourcemanager.projects.updateLiens permission from all users associated with the project.
  4. Enable the compute.restrictXpnProjectLienRemoval organization policy constraint.
✓ Correct Answer: D
D. compute.restrictXpnProjectLienRemoval org policy prevents Shared VPC project deletion by restricting lien removal to org-level permission holders.
Q4 Bootstrapping a Google Cloud organization for DevOps
Your organization is running multiple Google Kubernetes Engine (GKE) clusters in a project. You need to design a highly-available solution to collect and query both domain-specific workload metrics and GKE default metrics across all clusters, while minimizing operational overhead. What should you do?
  1. Use Prometheus operator to install Prometheus in every cluster and scrape the metrics. Configure remote-write to one central Prometheus. Query the central Prometheus instance.
  2. Enable managed collection on every GKE cluster. Query the metrics in BigQuery.
  3. Use Prometheus operator to install Prometheus in every cluster and scrape the metrics. Ensure that a Thanos sidecar is enabled on every Prometheus instance. Configure Thanos in the central cluster. Query the central Thanos instance.
  4. Enable managed collection on every GKE cluster. Query the metrics in Cloud Monitoring.
✓ Correct Answer: D
D. GKE Managed Collection sends metrics to Cloud Monitoring for all clusters with zero operational overhead.
Q5 Bootstrapping a Google Cloud organization for DevOps
Your company stores a large volume of infrequently used data in Cloud Storage. The projects in your company's CustomerService folder access Cloud Storage frequently, but store very little data. You want to enable Data Access audit logging across the company to identify data usage patterns. You need to exclude the CustomerService folder projects from Data Access audit logging. What should you do?
  1. Enable Data Access audit logging for Cloud Storage at the organization level, and configure exempted principals to include users of the CustomerService folder.
  2. Enable Data Access audit logging for Cloud Storage at the organization level, with no additional configuration.
  3. Enable Data Access audit logging for Cloud Storage for all projects and folders other than the CustomerService folder.
  4. Enable Data Access audit logging for Cloud Storage for all projects and folders, and configure exempted principals to include users of the CustomerService folder.
✓ Correct Answer: D
D. Organization-level Data Access audit logging with exempted principals excludes CustomerService folder users from logging.
Q6 Bootstrapping a Google Cloud organization for DevOps
You are designing a new multi-tenant Google Kubernetes Engine (GKE) cluster for a customer. Your customer is concerned with the risks associated with long-lived credentials use. The customer requires that each GKE workload has the minimum Identity and Access Management (IAM) permissions set following the principle of least privilege (PoLP). You need to design an IAM impersonation solution while following Google-recommended practices. What should you do?
  1. 1. Create a Google service account.
  2. 1. Create a Google service account.
  3. 1. Create a Google service account.
  4. 1. Create a Google service account.
✓ Correct Answer: C
C. Workload Identity links Kubernetes SA to Google SA via workloadIdentityUser role, enabling per-pod IAM without managing keys.
Q7 Bootstrapping a Google Cloud organization for DevOps
You work for a healthcare company and regulations require you to create all resources in a United States-based region. You attempted to create a secret in Secret Manager but received the following error message: Constraint constraints/gcp.resourceLocations violated for [orgpolicy:projects/000000] attempting to create a secret in [global] You need to resolve the error while remaining compliant with regulations. What should you do?
  1. Remove the organization policy referenced in the error message.
  2. Create the secret with an automatic replication policy.
  3. Create the secret with a user-managed replication policy.
  4. Add the global region to the organization policy referenced in the error message.
✓ Correct Answer: C
C. Secret Manager with user-managed replication to a US region satisfies the location org policy constraint. Automatic replication (B) uses 'global', violating the policy.
Q8 Bootstrapping a Google Cloud organization for DevOps
You have a pool of application servers running on Compute Engine. You need to provide a secure solution that requires the least amount of configuration and allows developers to easily access application logs for troubleshooting. How would you implement the solution on GCP?
  1. ג€¢ Deploy the Stackdriver logging agent to the application servers. ג€¢ Give the developers the IAM Logs Viewer role to access Stackdriver and view logs.
  2. ג€¢ Deploy the Stackdriver logging agent to the application servers. ג€¢ Give the developers the IAM Logs Private Logs Viewer role to access Stackdriver and view logs.
  3. ג€¢ Deploy the Stackdriver monitoring agent to the application servers. ג€¢ Give the developers the IAM Monitoring Viewer role to access Stackdriver and view metrics.
  4. ג€¢ Install the gsutil command line tool on your application servers. ג€¢ Write a script using gsutil to upload your application log to a Cloud Storage bucket, and then schedule it to run via cron every 5 minutes. ג€¢ Give the developers the IAM Object Viewer access to view the logs in the specified bucket.
✓ Correct Answer: A
A. IAP TCP forwarding tunnels RDP to Windows VMs without external IPs, based on identity and context.

You've viewed 3 of 75 questions. Start the free practice exam to answer all questions with instant feedback.

Exam overview

The Google Cloud Professional Cloud DevOps Engineer (PCDOE) certification validates your ability to implement SRE principles and build efficient CI/CD pipelines on Google Cloud. This exam goes beyond tool knowledge to test your understanding of Site Reliability Engineering culture—defining SLIs and SLOs, managing error budgets, implementing progressive delivery strategies, and building observability into every layer of your infrastructure.

Our PCDOE practice test suite covers the full DevOps lifecycle: from code commit to production deployment and incident response. With 400+ questions spanning SRE fundamentals, CI/CD pipeline design with Cloud Build and Cloud Deploy, GKE deployment automation, and monitoring with Cloud Operations suite, each question reinforces the operational mindset that distinguishes DevOps engineers from traditional sysadmins.

The PCDOE exam uniquely tests your ability to balance speed and stability—a core SRE tension. Questions ask you to evaluate deployment strategies (canary vs blue-green vs rolling), configure appropriate monitoring alerts based on SLO burn rates, and design incident management workflows. At $200, PCDOE is ideal for DevOps engineers, SRE practitioners, and platform engineers who want to validate their Google Cloud operational expertise.

Official Exam Domains & Weighting

  • Domain 1: Applying Site Reliability Engineering principles — SLI/SLO/SLA definitions, error budget policies, toil reduction, blameless postmortems.
  • Domain 2: Building and implementing CI/CD pipelines — Cloud Build, Cloud Deploy, Artifact Registry, Container Registry, binary authorization.
  • Domain 3: Implementing service monitoring strategies — Cloud Monitoring, Cloud Logging, Cloud Trace, Cloud Profiler, alerting policies based on SLOs.
  • Domain 4: Managing service incidents — Incident response workflows, escalation policies, Cloud Monitoring uptime checks, debugging production issues.
  • Domain 5: Optimizing service performance and cost — GKE autoscaling, resource optimization, committed use discounts, preemptible VMs.

What Our Customers Say 124 verified reviews

5.0 ★★★★★ Based on 124 reviews
★★★★★★
The progress tracking feature for PCDOE really motivated me. Seeing my improvement over time was incredibly satisfying.
— Daniel H.
★★★★★★
I work full time and study at night. The PCDOE question bank allowed me to learn efficiently without wasting precious time.
— Harper S.
★★★★★
Ended up buying three different PCDOE prep resources and this was by far the most helpful one. Don’t waste money on others.
— Penelope W.
★★★★★★
Used this PCDOE prep extensively for three weeks. The progress tracking feature kept me accountable.
— Violet W.
★★★★★★
I was preparing for the PCDOE exam while juggling a newborn at home. The flexibility of this platform was a lifesaver.
— Cooper D.
★★★★★★
I was pleasantly surprised by the quality of the PCDOE questions for the price. Comparable to much more expensive prep courses.
— Blake C.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

PCDOE focuses on operations and reliability. PCD is developer-focused; PCA is architect-focused. PCDOE tests SRE principles, CI/CD pipeline design, and incident management—the "how do we keep it running" skills.

SLI (Service Level Indicator) definition, SLO (Service Level Objective) setting, error budget calculation, and burn rate alerting are core topics. You must understand how to translate business requirements into measurable reliability targets.

Significant—Cloud Build, Cloud Deploy, and Artifact Registry are heavily tested. Expect questions on pipeline design, artifact promotion across environments, and canary deployment strategies with traffic splitting.