Google Cloud · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
32% of exam · 6 sample questions below
A company is designing a cloud-native application on Google Cloud that requires low-latency access to a global user base. The application serves static content and dynamic APIs. Which strategy best minimizes latency while maintaining high availability?
Deploy the application in a single region and use Cloud Interconnect for global access.
Use Cloud CDN to cache static content and deploy the API across multiple regions with global load balancing.
Cloud CDN caches static assets at edge locations close to users, while multi-region API deployment behind global load balancing routes dynamic requests to the nearest healthy region. Together they minimise latency and sustain availability if a region fails.
Use Cloud Armor to protect the application and rely on Google's backbone for low latency.
Store all content in Cloud Storage and serve directly from there.
A team is migrating a monolithic application to a microservices architecture on Google Kubernetes Engine (GKE). They want to ensure that failures in one microservice do not cascade to others. Which design pattern should they implement?
Implement retry logic with exponential backoff for all inter-service calls.
Implement a circuit breaker pattern that opens when failure thresholds are exceeded.
A circuit breaker monitors calls to a failing microservice and, once failure thresholds are exceeded, opens to reject further requests immediately. This stops repeated timeouts and resource exhaustion from propagating, directly satisfying the requirement that one microservice's failures must not cascade to others.
Use synchronous HTTP calls with timeouts to detect failures quickly.
Use bulkheads to separate thread pools for each service.
A company is building a real-time analytics application on Google Cloud that ingests data from thousands of IoT devices. The data must be processed with sub-second latency and stored in a time-series database for querying. Which combination of services provides the best scalability and availability?
Cloud Pub/Sub, Cloud Dataflow, Cloud Datastore
Cloud Pub/Sub, Cloud Functions, Cloud SQL
Cloud Pub/Sub, Cloud Dataflow, Cloud Storage
Cloud Pub/Sub, Cloud Dataflow, Cloud Bigtable
Cloud Pub/Sub ingests the thousands of IoT device streams with horizontal scalability, while Cloud Dataflow provides autoscaling stream processing that meets the sub-second latency requirement. Cloud Bigtable stores the resulting time-series data with high throughput and availability, satisfying the querying constraint. Together they deliver the elasticity and resilience the scenario demands.
A team is designing a globally distributed application on Google Cloud that requires strong consistency for writes but can tolerate eventual consistency for reads. The application expects millions of concurrent users. Which two strategies should they implement? (Choose two.)
Use Cloud Spanner for write operations requiring strong consistency.
Cloud Spanner provides externally consistent reads and writes across global regions using TrueTime and atomic clocks, satisfying the strong consistency requirement for write operations in the stem. Its synchronous replication ensures that all writes are immediately visible to subsequent reads, directly addressing the need for write consistency despite eventual read tolerance.
Use Firestore in multi-region mode for all operations.
Use global HTTP(S) Load Balancer with Cloud CDN for read-heavy traffic.
Cloud CDN caches content globally, providing low-latency reads with eventual consistency.
Deploy Cloud SQL with cross-region replication for read scalability.
Use Cloud Bigtable for reading data with strong consistency.
An organization is migrating a critical application to Google Cloud and needs to ensure high availability and disaster recovery. The application runs on Compute Engine and uses a stateful database. Which three design choices should they make? (Choose three.)
Use managed instance groups distributed across multiple zones.
MIGs across zones provide auto-healing and high availability.
Use regional persistent disks for the database.
Regional persistent disks synchronously replicate data across zones.
Use a global load balancer to route traffic to the closest healthy region.
Global load balancer provides traffic distribution and failover across regions.
Use preemptible VMs to reduce costs for the database layer.
Deploy all instances in a single zone and use snapshots for backup.
A company is designing a global e-commerce platform on Google Cloud. The application requires low-latency access for users worldwide and must be highly available. Which load balancing solution should they use?
External TCP/UDP Network Load Balancer
External HTTP(S) Load Balancer
External HTTP(S) Load Balancer uses Google's global anycast edge, terminating user traffic at the closest point of presence and routing over Google's backbone. This delivers the low-latency worldwide access and cross-region high availability the platform requires.
Cloud CDN
Internal TCP/UDP Load Balancer
Want more Designing highly scalable, available, and reliable cloud-native applications practice?
Practice this domain24% of exam · 6 sample questions below
A team deploys a containerized web application on Google Kubernetes Engine (GKE) using a Deployment. They need to expose the application externally via a stable IP address and enable SSL termination. Which resource should they use?
HorizontalPodAutoscaler
Ingress with Google-managed SSL certificate
Ingress with a Google-managed certificate provisions a stable external IP through the load balancer and terminates SSL at the edge, meeting both the fixed-address and TLS-offload requirements that a plain Service of type LoadBalancer cannot fully satisfy.
Service type NodePort
Service type LoadBalancer
During a deployment to App Engine flexible environment, the new version fails to start and the logs show 'Container failed to start: context deadline exceeded'. The previous version remains serving traffic. What is the most likely cause?
The health check is misconfigured, causing the instance to be considered unhealthy.
The app requires an environment variable that is not set.
The container startup time exceeds the 10-minute timeout.
App Engine flexible waits up to 10 minutes for the container to answer health checks; exceeding that window produces 'context deadline exceeded' and the version is marked unhealthy. The previous version keeps serving because traffic only shifts after the new version passes startup.
The Dockerfile has a syntax error that prevents the container from building.
Which TWO statements about deploying applications on Google Kubernetes Engine (GKE) are correct?
HorizontalPodAutoscaler can use custom metrics from Cloud Monitoring.
HorizontalPodAutoscaler natively scales on CPU and memory, and also supports external and custom metrics surfaced through the Cloud Monitoring adapter. This lets autoscaling respond to application-specific signals rather than resource usage alone, which is valid for GKE deployments.
Kubernetes Secrets are encrypted at rest by default.
A zonal GKE cluster automatically uses regional persistent disks for high availability.
PodDisruptionBudget can be used to ensure a minimum number of pods are available during node repair.
A PodDisruptionBudget defines the minimum available replicas that voluntary disruptions, such as node repairs or upgrades, must respect. GKE's node repair process evicts pods through the Eviction API, which honours the budget, preventing the workload from dropping below the specified threshold during maintenance.
To expose a Deployment externally, you must create an Ingress resource.
Which THREE practices should be followed when deploying a containerized application to Cloud Run?
Avoid writing to the local filesystem for data that must persist across requests.
Cloud Run instances are ephemeral and may be replaced or scaled at any time, so the local filesystem is not durable. Writing persistent data there loses it across requests, violating the stateless execution model Cloud Run requires.
Set a maximum request timeout of 10 minutes to avoid cold starts.
Hardcode port 8080 in the container.
Design the application to be stateless, storing session data externally (e.g., Firestore).
Cloud Run scales instances horizontally and may route successive requests to different instances, so in-instance session state is unreliable. Storing sessions externally, such as Firestore, keeps the application stateless and consistent across instances and restarts.
Use Cloud Run's built-in autoscaling to handle traffic bursts.
Cloud Run's request-based autoscaling provisions instances dynamically as concurrency and traffic demand rise, satisfying the burst-handling constraint without manual capacity planning. Because instances scale to zero when idle, this practice also controls cost during quiet periods, making it the appropriate operational choice for unpredictable workloads.
A company wants to deploy a containerized application on Google Kubernetes Engine (GKE) with zero downtime during updates. The application is stateless and runs on a Deployment with 5 replicas. Which deployment strategy should be used?
Blue/green deployment
Recreate update
Canary deployment
Rolling update
Rolling updates replace pods incrementally, keeping the Deployment's 5 replicas available throughout. This satisfies the zero-downtime constraint by ensuring readiness probes pass before old pods terminate, so traffic never hits an empty backend. It suits stateless workloads, unlike recreate, which causes an outage.
A developer is deploying a Cloud Run service that needs to access a Cloud SQL instance. The service is deployed with the --no-allow-unauthenticated flag. What is the recommended way to grant the service access to the database?
Grant the Cloud SQL Client role to the Cloud Run service's runtime service account.
Cloud Run's runtime service account is the identity that authenticates to Cloud SQL. Granting it the Cloud SQL Client role permits the authorised connection via the Cloud SQL connector or socket, satisfying the requirement despite the service rejecting unauthenticated invocations.
Create a service account key and store it in Secret Manager, then mount it as a volume.
Use the default Compute Engine service account and grant it the Cloud SQL Client role.
Enable the Cloud SQL Admin API and use Application Default Credentials from the Cloud Run service.
Want more Deploying applications practice?
Practice this domain23% of exam · 6 sample questions below
A company is developing a microservices application on Google Cloud. Each service is deployed as a Docker container on Cloud Run. The development team wants to ensure that inter-service communication is encrypted and authenticated. What is the best approach?
Use Cloud Run's built-in IAM-based authentication and automatic TLS for internal requests.
Cloud Run's built-in IAM authentication issues identity tokens that receiving services validate, while automatic TLS encrypts traffic between revisions without extra configuration. This satisfies both the encryption and authentication requirements for inter-service communication directly, avoiding sidecar proxies or service mesh overhead the stem does not demand.
Configure mutual TLS (mTLS) between services using Cloud Endpoints.
Deploy a sidecar proxy on each Cloud Run service to handle TLS termination.
Assign a service account to each service and use its private key to sign requests.
A developer needs to test a Cloud Function locally before deploying. Which tool should they use?
Docker container with a custom entrypoint.
gcloud functions call command.
Cloud Code for VS Code or IntelliJ.
Functions Framework for your language.
The Functions Framework is an open-source runtime that emulates the Cloud Functions execution environment locally, letting developers invoke and debug the function on their machine. It satisfies the local testing requirement without deploying, supporting the same language runtimes and HTTP or event signatures used in production.
A company is migrating a monolithic Java application to microservices on Google Kubernetes Engine (GKE). The application uses a shared MySQL database. The team wants to adopt a testing strategy that validates service interactions without deploying to a full cluster. Which testing approach is most appropriate?
Load testing to simulate production traffic.
Unit testing with mocked dependencies.
Consumer-driven contract testing with tools like Spring Cloud Contract.
Consumer-driven contract testing with Spring Cloud Contract validates each microservice's interactions against agreed consumer expectations, running as fast in-process tests without a GKE cluster or shared MySQL instance. This directly satisfies the stem's constraint of verifying service interactions without full deployment, catching API mismatches early in the build pipeline.
End-to-end testing in a staging environment.
Which THREE steps are required to set up a CI/CD pipeline for Cloud Run using Cloud Build and GitHub? (Choose THREE.)
Enable the Cloud Build, Cloud Run, and Artifact Registry APIs.
Enabling these three APIs is mandatory because Cloud Build executes the build, Cloud Run hosts the deployed container, and Artifact Registry stores the built image. Without all three services active, the pipeline cannot build, push, or deploy, directly satisfying the stem's prerequisite requirement for a functioning CI/CD pipeline.
Grant the Cloud Build service account permission to deploy to Cloud Run.
Granting the Cloud Build service account the Cloud Run Developer role lets the pipeline deploy revisions without interactive authentication. Cloud Build executes builds under its own service account, so without this IAM binding the deploy step fails authorisation, regardless of trigger configuration. This satisfies the stem's requirement for a functioning CI/CD pipeline.
Create a cloudbuild.yaml file in the repository root.
A `cloudbuild.yaml` at the repository root defines the build, test and deploy steps Cloud Build executes, satisfying the pipeline-as-code requirement. Without it, Cloud Build cannot determine how to build the container image or deploy it to Cloud Run, so this step is mandatory for the CI/CD setup.
Push the container image to Container Registry.
Mirror the GitHub repository to Cloud Source Repositories.
A developer needs to build a CI/CD pipeline that automatically tests and deploys a Node.js application to Cloud Run whenever a pull request is merged to the main branch. Which Google Cloud service should be used to trigger the pipeline?
Cloud Functions
Cloud Deploy
Cloud Build
Cloud Build triggers natively on repository events such as pull request merges to the main branch, then runs the build, test and deploy steps to Cloud Run, satisfying the automatic CI/CD trigger requirement without additional orchestration services.
App Engine
A company deploys a Java application on Compute Engine with a preemptible VM instance group managed by an instance template. The application writes critical state to local SSD. After a preemption event, the new instance starts fresh and loses state. What is the best practice to ensure state persistence?
Modify the startup script to recover state from a snapshot
Refactor the application to write state to a persistent service like Cloud Storage
Writing state to Cloud Storage decouples it from the preemptible instance's ephemeral local SSD, which is wiped on preemption. Because Compute Engine preemptible VMs can terminate at any time, only an external durable store survives instance replacement, satisfying the stem's persistence requirement across the fresh instance.
Configure the managed instance group as stateful to preserve local SSD data
Use a regular (non-preemptible) VM instead of preemptible
Want more Building and testing applications practice?
Practice this domain21% of exam · 6 sample questions below
You need to monitor the CPU usage of a Compute Engine instance and trigger an alert when it exceeds 80% for 5 minutes. Which Google Cloud service should you use?
Cloud Debugger
Cloud Monitoring
Cloud Monitoring collects Compute Engine CPU metrics and its alerting policies fire when a metric exceeds a threshold for a sustained duration, such as 80% for 5 minutes. This matches the metric, threshold and duration specified.
Cloud Logging
Error Reporting
Your company uses Cloud SQL for MySQL to store transactional data. You need to perform a point-in-time recovery (PITR) to recover from a logical error that occurred 30 minutes ago. Which two prerequisites must be met? (Choose TWO.)
High availability (HA) is configured.
Binary logging is enabled.
Point-in-time recovery replays binary logs to reconstruct the database at a chosen moment, so binary logging must be enabled before the error occurs. Without it, Cloud SQL can only restore the most recent backup, losing the intervening transactions.
Automated backups are enabled.
Automated backups must be enabled because PITR replays binary logs onto a backup taken within the retention window; without a base backup and continuous log retention, Cloud SQL for MySQL cannot reconstruct the database to the point 30 minutes before the logical error.
The backup window is set to a time before the incident.
A read replica is configured.
You are designing a CI/CD pipeline using Cloud Build. You want to automatically trigger a build when code is pushed to a specific branch in Cloud Source Repositories. What is the correct configuration?
Create a Cloud Function that invokes Cloud Build via API when a push event occurs.
Add a build step in cloudbuild.yaml that polls the repository.
Configure a Cloud Pub/Sub topic to notify Cloud Build on push events.
Create a build trigger in Cloud Build with a regex pattern for the branch name.
A Cloud Build trigger with a branch regex filters incoming pushes from Cloud Source Repositories, firing the build only when the pushed ref matches the specified branch pattern. This satisfies the stem's requirement to trigger automatically on pushes to a specific branch, since regex matching targets that branch precisely rather than building every push.
A company is migrating a legacy monolithic application to Google Cloud. They want to minimize code changes and operational overhead while improving scalability. The application currently uses a relational database and stores user-uploaded images on a local filesystem. Which combination of Google Cloud services should they use?
Cloud Spanner for the database and Cloud Storage for images
Cloud Firestore for the database and Cloud Storage with Cloud CDN for images
Cloud SQL for the database and Cloud Storage with Cloud CDN for images
Cloud SQL provides a managed relational database requiring no schema rewrite, while Cloud Storage with Cloud CDN offloads image serving and scales globally. This pairing minimises code changes and operational overhead, matching the migration constraints in the stem.
Compute Engine with attached SSD persistent disks for both database and images
A company is using Cloud Storage to store sensitive customer data. They need to ensure data is encrypted at rest and access is controlled. Which TWO statements are true regarding data protection in Cloud Storage? (Choose two.)
By default, data in Cloud Storage is encrypted at rest using Google-managed encryption keys.
Cloud Storage encrypts all objects at rest by default using Google-managed encryption keys, with no configuration required. This satisfies the encryption-at-rest requirement automatically, though access control still needs IAM policies to restrict who can read the sensitive customer data.
Using a signed URL revokes the underlying object's ACL.
Enabling uniform bucket-level access disables encryption at rest.
Customer-managed encryption keys (CMEK) can be used to control the encryption keys used to protect data.
CMEK lets you supply Cloud KMS keys that wrap the data encryption keys protecting objects, giving control over key rotation, location and revocation. This satisfies the requirement to control encryption keys for sensitive data, unlike Google-managed keys which you cannot manage directly.
Bucket-level policies can restrict access to only compute instances with specific service accounts.
A company is running a critical application on Google Kubernetes Engine (GKE) that stores state in a Cloud SQL PostgreSQL instance. The application's latency-sensitive frontend needs to read data from Cloud SQL with minimal latency. The team wants to reduce read latency and offload read traffic from the primary database. What should they do?
Migrate the database to Cloud Spanner for better read scalability.
Use Memorystore for Redis as a cache layer between the application and Cloud SQL.
Create a read replica of the Cloud SQL instance and direct read traffic to the replica.
Read replicas asynchronously replicate the primary Cloud SQL instance and serve read-only queries, offloading read traffic and reducing latency for the frontend. This satisfies the stated goals of lower read latency and reduced primary load.
Use Cloud CDN to cache database responses.
Want more Integrating Google Cloud services practice?
Practice this domainThe PCD exam has 60 questions and must be completed in 120 minutes. The passing score is 720/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 4 domains: Designing highly scalable, available, and reliable cloud-native applications, Deploying applications, Building and testing applications, Integrating Google Cloud services. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Google Cloud PCD exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.