Google Cloud · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
24% of exam · 6 sample questions below
A company is bootstrapping their Google Cloud organization for DevOps. They want to implement a least-privilege model for service accounts used by CI/CD pipelines. The pipelines need to deploy resources in multiple projects. What is the best practice for managing service account keys?
Use a user account for the CI/CD pipeline and assign it the necessary roles.
Store service account keys in Secret Manager and have the pipeline retrieve them at runtime.
Generate a single service account key and securely distribute it to the CI/CD system.
Use workload identity federation to allow the CI/CD system to impersonate a service account without keys.
Workload identity federation lets the CI/CD system exchange its own OIDC token for short-lived Google Cloud credentials, impersonating a service account without any long-lived key. This satisfies the least-privilege requirement across multiple projects, since IAM bindings grant scoped access per project and no downloadable key exists to leak or rotate.
A DevOps team is setting up a Google Cloud organization. They want to centralize logging and monitoring across all projects. What is the recommended approach?
Enable logging and monitoring in each project individually and use the Cloud Console to view them.
Create a dedicated project for logging and monitoring, and configure all other projects to send logs and metrics to that project.
A dedicated logging project centralises log storage and metrics, satisfying the requirement to aggregate data across every project in the organisation. Logging sinks and metrics scopes route entries from all projects into this single destination, giving the team one place to query and alert, and simplifying IAM and retention management.
Enable Cloud Audit Logs in the organization and view them from the Organization level.
Use Stackdriver (now Operations) to aggregate logs from all projects automatically.
Which THREE actions should be taken to ensure compliance with the principle of least privilege when bootstrapping a Google Cloud organization? (Choose 3)
Use service accounts for automated processes and grant them the minimum required roles.
Service accounts give automated processes their own identities, and granting only the minimum required roles limits each to precisely the permissions its task needs. This satisfies least privilege by removing standing broad access from automation.
Use custom roles that include only the necessary permissions.
Custom roles let you grant only the precise permissions each bootstrap identity needs, rather than bundling broad predefined permissions. This directly enforces least privilege by eliminating unnecessary entitlements during organisation setup, satisfying the requirement to avoid over-provisioning.
Grant roles at the project level rather than at the organization level when possible.
Granting roles at the project level scopes permissions to the specific resources an identity requires, rather than inheriting organisation-wide access. This limits the blast radius of any compromised principal, directly satisfying least privilege by avoiding excessive organisational-level grants.
Assign the Owner role at the organization level to a small group of administrators.
Use primitive roles (Owner, Editor, Viewer) to simplify management.
Which TWO are benefits of using a shared VPC in a Google Cloud organization? (Choose 2)
Centralized management of network resources.
A shared VPC lets the host project own and manage subnets, firewall rules and routes centrally, while service projects consume them. This centralised control is the benefit, satisfying the requirement for consistent network resource management across the organisation.
Eliminates the need for project administrators to have any IAM roles.
Ensures compliance with organizational policies.
Separation of network administration from project administration.
In a shared VPC, network administrators manage the host project's shared subnets and firewall rules, while project administrators control their own service project resources. This separation of duties satisfies the benefit of dividing network administration from project administration.
Automatically enables required APIs in all service projects.
You are a DevOps engineer tasked with bootstrapping a Google Cloud organization for a company that develops a SaaS product. The company has three teams: Platform, Application, and Data. Each team needs to manage their own projects, but the network should be centrally managed. You decide to use a shared VPC. You create a host project 'shared-vpc-host' and attach three service projects: 'platform-service', 'app-service', and 'data-service'. You grant the Network Admin role to the Platform team for the host project. The Application team needs to deploy Compute Engine instances in their service project, but they should not be able to modify network resources. You grant them the Compute Instance Admin role at the service project level. However, the Application team reports that they cannot create instances because they don't have permission to use the subnets in the shared VPC. What is the most likely missing step?
Grant the Application team the Compute Network Admin role on the host project.
Grant the Application team the Compute Network User role on the service project.
Grant the Application team the Compute Network User role on the host project or the specific subnets.
Shared VPC requires the Compute Network User role on the host project or specific subnets, which the Application team lacks. Without it, they cannot attach instances to shared subnets despite holding Compute Instance Admin on the service project.
Grant the Application team the roles/compute.subnetUser on the subnet.
Which TWO are best practices for bootstrapping a Google Cloud organization for DevOps?
Share a single service account key across multiple projects for simplicity.
Disable Organization Policies to allow maximum flexibility for DevOps teams.
Use a separate project to host shared CI/CD tools and artifacts.
A dedicated shared project isolates CI/CD tooling, build artefacts and service accounts from workload projects, so pipeline compromise does not expose production resources. It also gives a single place to apply IAM and Organization Policies governing the delivery toolchain.
Set up Organization Policies to enforce compliance requirements across projects.
Organization Policies are inherited constraints applied at organization, folder or project level, letting you enforce compliance rules such as location restrictions or uniform bucket-level access across every project without per-resource configuration. This satisfies the requirement for consistent, centrally governed compliance.
Create a single service account with broad permissions to be used by all projects.
Want more Bootstrapping a Google Cloud organization for DevOps practice?
Practice this domain18% of exam · 6 sample questions below
A DevOps engineer receives an alert that the error budget for a critical service has been exhausted. The service runs on Compute Engine behind an HTTP(S) load balancer. The team wants to reduce the impact on users while investigating. What should the engineer do first?
Roll back the most recent deployment
Rolling back quickly restores the previous stable version.
Begin a detailed postmortem analysis
Disable the alerting policy to reduce noise
Increase the number of instances in the managed instance group
A company uses Cloud Run for a stateless API service with concurrency set to 80. During a traffic spike, some requests return HTTP 500 errors and latency spikes. Cloud Monitoring shows container CPU utilization at 100% and memory usage at 70%. What is the most likely cause and the best first step?
Concurrency per container is too high; reduce concurrency to 10
Concurrency 80 lets each container accept 80 simultaneous requests, so CPU saturates at 100% and requests queue, producing HTTP 500s and latency spikes. Lowering concurrency to 10 reduces parallel load per container, restoring CPU headroom and stabilising response times.
Maximum instances limit is too low; increase from 10 to 100
Min idle instances is too low; set min idle to 5 to reduce cold starts
Memory limit is too low; increase memory from 256 MiB to 512 MiB
A team uses Cloud SQL for PostgreSQL. They receive an alert that the database's CPU utilization is above 95% for the past 30 minutes. Queries are taking longer than usual. They want to investigate without causing further impact. What should they do first?
Increase the number of vCPUs of the Cloud SQL instance
Restart the Cloud SQL instance to clear the cache
Migrate the database to Cloud Spanner
Use Cloud SQL Query Insights to find the most time-consuming queries
Cloud SQL Query Insights provides query-level telemetry, including per-query latency and wait-event breakdowns, without adding load to the instance. This satisfies the stem's constraint of investigating the sustained 95% CPU saturation without causing further impact, since it reads existing telemetry rather than executing diagnostic queries against the already-strained database.
A company's SRE team is designing an incident management process. They want to ensure that alerts are actionable and that on-call engineers are not overwhelmed by false positives. Which approach should they take?
Use only critical severity alerts and rely on manual dashboard review for lower severity
Create alerting policies for every available metric to ensure nothing is missed
Set all alert thresholds to 50% above the average value to avoid false positives
Define SLOs and set alert thresholds based on historical error budget consumption
SLOs with error-budget-based thresholds tie paging to actual user-impacting burn rate rather than raw resource metrics, so alerts fire only when reliability is genuinely degrading. This filters out non-actionable noise, preventing on-call engineers from being overwhelmed by false positives.
An incident is declared for a production service running on GKE. The on-call engineer suspects a recent code change may have introduced a memory leak. Which THREE actions should the engineer take to investigate and mitigate?
Increase the memory limit for the container as a temporary mitigation
Temporary increase buys time for a permanent fix.
Scale down the number of replicas to reduce memory pressure
Roll back the deployment immediately without further investigation
Check container logs for Out of Memory (OOM) killed messages
OOM messages confirm memory exhaustion.
Compare memory usage metrics before and after the deployment using Cloud Monitoring
Identifies if memory usage increased after the change.
A service experiences increased latency and HTTP 503 errors. The engineer finds that the backend managed instance group (MIG) is at max instances and CPU utilization is 90%. Which TWO actions should the engineer take to restore the service quickly?
Enable autoscaling based on HTTP load balancing utilization
Scales based on request rate, which is more responsive than CPU.
Increase the autoscaling target CPU utilization to 95%
Increase the maximum number of instances in the MIG
Allows the MIG to scale out further to handle load.
Reduce the autoscaling target CPU utilization to 50%
Reduce the number of instances to avoid resource contention
Want more Applying site reliability engineering practices practice?
Practice this domain12% of exam · 6 sample questions below
A company uses Cloud Storage to store archival data. They want to minimize storage costs while maintaining availability. Which storage class should they use?
Nearline storage class.
Standard storage class.
Archive storage class.
Archive storage class offers the lowest storage cost of Cloud Storage's classes while retaining high durability and availability, making it suitable for rarely accessed archival data where retrieval latency and retrieval fees are acceptable trade-offs.
Coldline storage class.
A company is using BigQuery for analytics and wants to control costs. They have many queries that scan large amounts of data. Which approach is most effective in reducing query costs?
Switch to flat-rate pricing to cap costs.
Partition tables by date and use partition pruning in queries.
Date partitioning lets BigQuery prune irrelevant partitions, so queries filtering on the partition column read only matching data rather than the full table. This directly reduces bytes scanned, which is the metric BigQuery on-demand pricing charges against.
Reserve BigQuery slots for dedicated capacity.
Use clustering to organize data within partitions.
A company runs a web application on Google Kubernetes Engine (GKE) with multiple services. They want to reduce costs without impacting performance. Which THREE actions should they take? (Choose three.)
Enable cluster autoscaling and manually scale nodes based on peak load.
Deploy a service mesh like Istio to optimize traffic routing.
Enable node auto-provisioning to automatically adjust node pools.
Node auto-provisioning ensures the cluster uses the right size and type of nodes.
Right-size CPU and memory requests and limits for each service.
Right-sizing avoids over-provisioning and reduces node resource waste.
Use preemptible VMs for stateless, fault-tolerant workloads.
Preemptible VMs are cheaper and suitable for fault-tolerant stateless services.
A DevOps team is analyzing Google Cloud costs and notices that spending on BigQuery has increased significantly. They want to reduce costs without impacting ongoing analytical workloads. Which TWO actions should they take? (Choose two.)
Switch to on-demand pricing to pay only for queries run.
Enable column-level security to restrict access to sensitive data.
Set custom cost controls like query quotas and maximum bytes billed per query.
Limits prevent expensive queries from running unbounded.
Delete unused datasets to reduce storage costs.
Implement flat-rate pricing with reservations for consistent workloads.
Flat-rate pricing caps costs for predictable usage, avoiding per-query charges.
Refer to the exhibit. The output shows a recommendation from the Cloud Cost Optimization recommender for an instance in us-central1-a. The instance is a production web server that consistently runs at 25% CPU utilization during peak hours. What should the DevOps engineer do to implement this recommendation with minimal risk?
Stop the instance, change the machine type to n2-standard-4, and start it again.
This directly implements the recommendation with minimal risk.
Ignore the recommendation because the instance is production and any change might cause downtime.
Add a second n2-standard-4 instance behind a load balancer to distribute load.
Use a custom machine type with 4 vCPUs and 32 GB memory to ensure enough RAM.
Match each SRE term to its description.
SLI: A carefully defined quantitative measure of some aspect of the level of service.
SLI stands for Service Level Indicator and is a specific metric used to measure the service's performance.
SLO: A target value or range of values for a service level that is measured by an SLI.
SLO (Service Level Objective) defines the desired state of the service as measured by SLIs.
SLA: An explicit or implicit contract with users that includes consequences of meeting (or missing) SLOs.
SLA (Service Level Agreement) is a formal agreement that often includes penalties or rewards based on SLO achievement.
Error Budget: The acceptable amount of unreliability remaining before the SLO is violated.
Error Budget is the inverse of the SLO: it's the allowed downtime or failures before breaching the objective.
SLI: The acceptable amount of unreliability remaining before the SLO is violated.
SLO: A contract with users that includes consequences.
Want more Optimizing performance and cost practice?
Practice this domain31% of exam · 6 sample questions below
A development team wants to automatically run unit tests and static code analysis on every push to a Cloud Source Repository, but only run integration tests on merges to the main branch. Which Cloud Build trigger configuration should they use?
Use a single trigger with a substitution variable like '_BRANCH' and set it to 'main' for integration tests.
Create one trigger with a build config that uses the 'branchName' substitution to conditionally skip integration test steps.
Create two triggers: one with a branch filter for '^main$' that runs integration tests, and another with a branch filter for '^.*$' that runs unit tests.
Branch filters are regex-matched against the branch ref, so '^main$' isolates merges to main for integration tests, while '^.*$' matches every branch push for unit tests and static analysis. This satisfies the requirement to split test types by branch.
Configure one trigger with no branch filter and rely on developers to manually trigger integration tests.
A company uses Spinnaker for continuous delivery across multiple GKE clusters. After a recent infrastructure change, the 'Canary' deployment strategy fails during the 'disable' phase of the old version. The error log shows: 'Unable to disable server group: Not authorized to perform compute.instanceGroups.update.' What is the most likely root cause?
The GKE cluster has reached its maximum node quota.
The Cloud Deploy pipeline is missing the required IAM role for the Spinnaker service account.
The Spinnaker service account lacks the compute.instanceGroups.update permission on the project.
Spinnaker disables the old server group by resizing its managed instance group, which calls compute.instanceGroups.update. The error names that exact permission, so the service account running Spinnaker lacks it on the project, blocking the disable phase.
The Kayenta canary analysis service is not configured correctly.
A Cloud Deploy pipeline fails during a rollout with: 'FAILED_PRECONDITION: The release is not in a state that can be promoted.' The Cloud Build service account has the IAM roles shown in the exhibit. What is the missing role or permission?
The service account is missing the 'roles/clouddeploy.jobRunner' role.
The service account is missing the 'roles/cloudbuild.builds.builder' role.
The service account is missing the 'roles/clouddeploy.operator' role.
The service account is missing the 'roles/clouddeploy.approver' role, which includes the 'clouddeploy.releases.promote' permission.
Approver role is needed for promotion.
A company is implementing CI/CD for a microservices application on Google Kubernetes Engine (GKE). The team wants to ensure that each service can be built and deployed independently without affecting other services. They also need to enforce that only successfully tested builds are deployed to production. Which CI/CD approach should they use?
Create separate Cloud Build triggers per microservice, each building a container image, and use Cloud Deploy to manage canary deployments to GKE with automated promotion after tests pass.
Separate Cloud Build triggers give each microservice an independent build pipeline, so one service's changes cannot block another's. Cloud Deploy enforces the tested-build constraint by gating promotion to production on automated test success, using canary rollouts on GKE.
Use Cloud Build to build all services and deploy to Cloud Run, then use traffic splitting to promote new versions.
Create a single Cloud Build trigger that builds all services and deploys to a staging cluster, then manually promote to production.
Use Spinnaker with a single pipeline that builds all services, and configure manual judgment gates for production promotion.
A DevOps team is troubleshooting a Cloud Build pipeline that fails intermittently when building a container image. The build step uses a custom build step that runs a vulnerability scan. The error log shows: 'Step #1: Error: failed to scan image: context deadline exceeded'. The build configuration includes 'timeout: 600s'. Which is the most likely cause and solution?
The scan tool requires a specific dependency; add an installation step before scanning.
There is network latency between Cloud Build and the container registry; use VPC Service Controls.
The build step is running out of memory; increase the machine type to e2-highcpu-8.
The scan step is taking longer than the build timeout; increase the timeout value in the build configuration.
The 'context deadline exceeded' error indicates the scan step exceeded the build's 600s timeout. Raising the timeout value in the build configuration gives the custom vulnerability scan step enough time to complete, resolving the intermittent failure.
An organization wants to implement a CI/CD pipeline that automatically deploys to a staging environment on every push to the main branch, and deploys to production only after a manual approval. They use Cloud Build and Cloud Deploy. What is the best way to configure this?
Configure a Cloud Deploy delivery pipeline with a staging target (automatic promotion) and a production target (require approval).
A Cloud Deploy delivery pipeline models sequential targets, so the staging target promotes automatically on each main-branch push, while the production target's approval requirement gates promotion until a human authorises it. This satisfies both constraints — automatic staging deployment and manual production approval — within one declarative pipeline.
Create a single Cloud Build pipeline that deploys to both staging and production using conditional steps based on branch name.
Use Cloud Build to deploy to Cloud Run, and configure traffic splitting to gradually shift traffic from staging to production.
Use Cloud Build triggers with two separate build configs: one for staging (automatic), one for production (manual trigger).
Want more Building and implementing CI/CD pipelines practice?
Practice this domain30% of exam · 6 sample questions below
A team is monitoring a production service on Google Kubernetes Engine (GKE) and notices that a deployment is occasionally returning HTTP 503 errors. The team has set up a ServiceMonitor in Prometheus to scrape metrics from the pods. What is the most likely cause of the intermittent 503 errors?
The pods are crashing and restarting frequently.
The Prometheus scrape interval is too long, causing missed metrics.
The readiness probes are failing, causing the pods to be removed from the service endpoints.
Failing readiness probes cause kube-proxy to remove pod IPs from the Service's endpoint list, so requests hitting a pod mid-removal return 503 until the endpoint update propagates. This directly explains the intermittent pattern, since healthy replicas continue serving traffic while individual pods cycle in and out of rotation.
The container resource limits are set too low, causing out-of-memory errors.
A cloud operations team is implementing monitoring for a microservices application deployed on Compute Engine. They want to create a custom dashboard in Cloud Monitoring that shows the 99th percentile latency of a specific service over the last hour. Which combination of Cloud Monitoring features should they use?
Use a gauge metric with the max alignment function in a Metrics Explorer chart.
Use a distribution metric with the 99th percentile alignment function in a Metrics Explorer chart.
Latency is recorded as a distribution metric, so the 99th percentile alignment function must be applied to extract the tail value rather than an average. Plotting that aligned series in Metrics Explorer produces the required one-hour percentile latency chart.
Use an uptime check metric and configure the latency percentile in the chart.
Create a logs-based metric from application logs and use the count alignment.
A company is running a stateful workload on Compute Engine and has configured a TCP health check on port 8080. The health check is failing, but the application is running and responding on port 8080 when tested manually from within the instance. What is the most likely cause of the health check failure?
The health check is configured to use port 80 instead of port 8080.
The firewall rules are not allowing traffic from the health check probe IP ranges.
Google Cloud health check probes originate from specific source ranges (130.211.0.0/22 and 35.191.0.0/16), not the instance's own network. A firewall rule permitting only internal or client traffic blocks probes, so the check fails while manual testing from the instance succeeds.
The instance's DNS resolution is failing, causing the health check to use the wrong IP.
The health check response timeout is set too low (e.g., 1 second).
Which TWO of the following are best practices for implementing service monitoring in Google Cloud? (Choose 2)
Set static alert thresholds without considering historical baselines.
Use Cloud Monitoring uptime checks to verify that services are reachable from external locations.
Uptime checks probe a service's endpoint from multiple global locations, detecting reachability and latency failures that internal metrics miss. This externally validates availability, satisfying the best practice of monitoring services from the user's perspective rather than only from inside the project.
Use the USE method (Utilization, Saturation, Errors) for service-level monitoring.
Define service level indicators (SLIs) using the RED method (Rate, Errors, Duration).
The RED method defines SLIs from request Rate, Error rate and Duration, which map directly to user-visible service health. These indicators feed SLOs and alerting, satisfying the best practice of measuring services by request outcomes rather than raw infrastructure metrics.
Alert on cause-based metrics (e.g., CPU utilization) rather than symptom-based metrics (e.g., latency).
A company uses Cloud Monitoring to track latency for a multi-region web application. The SLO is 99.9% of requests under 500ms over a 30-day rolling window. The error budget has been rapidly depleting over the last week. The operations team wants to understand the impact of recent deployments. Which approach should they use to correlate deployment changes with latency spikes?
Use Cloud Logging to search for deployment logs and manually compare with latency metrics
Use Cloud Trace to analyze latency distributions for each deployment version
Create a custom dashboard in Cloud Monitoring that includes latency charts and use annotation markers to indicate deployment times
Annotation markers overlay deployment timestamps directly onto latency charts, letting the team visually align release events with spikes inside the same 30-day window. This satisfies the correlation requirement without building separate tooling, unlike static thresholds or log-only inspection.
Configure Error Reporting to alert on latency threshold breaches
Which TWO are best practices for implementing service monitoring strategies in Google Cloud?
Monitor the four golden signals (latency, traffic, errors, saturation) for every service.
The four golden signals provide a high-level overview of service health.
Rely solely on synthetic monitoring to measure user experience.
Define Service Level Objectives (SLOs) and use them to drive alerting.
SLOs help focus on what matters and reduce alert fatigue.
Use multiple monitoring tools to cover all aspects of the system.
Manually analyze logs and metrics to identify issues.
Want more Implementing service monitoring strategies practice?
Practice this domain15% of exam · 6 sample questions below
A Cloud Run service is experiencing increased cold start latency. The service is written in Python and uses several large dependencies. Which action would most effectively reduce cold start latency?
Set concurrency to 1 to ensure each request gets a dedicated container.
Increase the CPU allocation to 4 vCPUs.
Set a minimum number of instances to keep containers warm.
Setting a minimum instance count keeps at least one container instance running, so requests bypass the cold start sequence of provisioning, image pull and Python dependency import entirely. This directly addresses the stem's latency constraint, though it trades cost for warmth since idle instances remain billable.
Increase memory to 2 GiB.
Your application uses Cloud SQL for MySQL and you notice that read replica lag is increasing. Which action would most likely reduce replica lag?
Configure automatic failover to the replica.
Decrease the memory of the primary instance.
Increase the machine type of the replica.
Replica lag occurs when the replica cannot apply writes as fast as the primary generates them. Increasing the replica's machine type adds CPU, memory and IOPS, letting it apply the replication stream faster and shrink the lag.
Promote the replica to a standalone instance.
Which TWO actions can reduce tail latency in a microservices architecture deployed on GKE? (Choose 2)
Run multiple replicas of each service and use a load balancer with least-request algorithm.
Multiple replicas spread load, and a least-request load balancer routes to the replica with fewest in-flight requests, avoiding overloaded instances that cause slow outliers. This reduces the tail latency the stem targets in the GKE microservices deployment.
Use a single large machine type for all services.
Enable session affinity to keep users on the same pod.
Increase the batch size for processing requests.
Implement request hedging by sending duplicate requests to multiple replicas.
Hedging issues duplicate requests to several replicas and returns the first response, so a single slow replica no longer dictates overall latency. This directly attacks the tail, where stragglers dominate, satisfying the requirement to reduce tail latency rather than average latency.
A team deploys a microservice on Google Kubernetes Engine (GKE) that processes user uploads. The service latency has increased over time. Monitoring shows that CPU utilization is low, but memory usage is high and garbage collection (GC) pauses are frequent. Which action is most likely to reduce latency?
Scale out the deployment by increasing the number of replicas.
Reduce the number of replicas to concentrate load.
Increase the CPU limit to allow faster processing.
Increase the memory limit and requests for the container.
Raising the container's memory limit and request gives the runtime more heap headroom, so garbage collection runs less often and its pauses shorten. That directly addresses the stem's high memory usage and frequent GC pauses, which are inflating latency despite low CPU.
A DevOps engineer is optimizing a Cloud Run service that experiences cold starts. The service is written in Python and uses several large libraries. Which change is most effective to reduce cold start latency?
Increase the maximum number of concurrent requests per container.
Set a minimum number of instances to keep containers warm.
Setting a minimum instance count keeps at least one container instance warm, so requests bypass the cold start entirely. This directly satisfies the stem's latency constraint, unlike code or dependency changes that only shrink, but never eliminate, Python's interpreter and large-library initialisation overhead.
Set a longer request timeout.
Increase the CPU allocation for the service.
An organization uses Cloud CDN with an HTTP(S) Load Balancer to serve static content. They observe that cache hit ratio is lower than expected. The content is immutable and has long Cache-Control headers. What is the most likely cause?
The requests include unique query parameters like session IDs.
Cloud CDN caches by full request URL, so unique query parameters such as session IDs make every request a distinct cache key. Even immutable content with long Cache-Control headers is then treated as uncacheable, depressing the hit ratio.
The Cache-Control max-age is set too short.
The load balancer is configured with SSL termination.
The content is served using signed URLs with expiration.
Want more Optimizing service performance practice?
Practice this domainThe PCDOE exam has 60 questions and must be completed in 120 minutes. The passing score is 720/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 6 domains: Bootstrapping a Google Cloud organization for DevOps, Applying site reliability engineering practices, Optimizing performance and cost, Building and implementing CI/CD pipelines, Implementing service monitoring strategies, Optimizing service performance. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Google Cloud PCDOE exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.