ExamDumpster

Free PCD sample questions

Real questions from the Professional Cloud Developer practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A financial services company is building a new real-time fraud detection system on Google Cloud. The system must process millions of transactions per second with extremely low latency. A key requirement is that the database must provide strongly consistent reads across multiple geographic regions (North America, Europe, and Asia) to prevent transnational fraud. The development team is evaluating database options. Which data storage solution is the most appropriate choice to meet these specific requirements?

Question 2Choose one

A development team is using Cloud Build for their CI/CD pipeline. To improve security, they need to ensure that only container images that have passed a specific 'QA-Approved' vulnerability scan level in Artifact Analysis are allowed to be deployed to their production GKE cluster. Any attempt to deploy an image that does not have this attestation should be blocked. What should the team implement to enforce this policy?

Question 3Choose one

You are instrumenting a Node.js application deployed on Cloud Run to send custom metrics to Cloud Monitoring. After deploying your code, you notice that no data appears in Metrics Explorer for your custom metric. The application logs in Cloud Logging show no errors related to authentication or metric publishing. You have already verified that the Cloud Monitoring API is enabled for the project. Which of the following is the most likely cause of the issue?

Question 4Choose one

A developer is building an event-driven processing pipeline. The architecture requires that when a file is uploaded to a Cloud Storage bucket, a message containing the file's metadata is sent to a Pub/Sub topic. This message should then trigger a Cloud Run service for processing. The developer wants to set this up using a direct, event-based mechanism without writing custom trigger code. Which Google Cloud service should be used to connect the Cloud Storage event to the Pub/Sub topic?

Question 5Choose one

A developer needs to deploy a containerized application to a new GKE cluster. The application has a web frontend and a backend processing service that communicate with each other. For security, the developer must prevent all other pods in the cluster from communicating with the backend service, while still allowing the frontend pods to reach it. Which Kubernetes object should be created to enforce this traffic rule?

Question 6Choose one

You are building a CI/CD pipeline using Cloud Build. The build process requires a specific version of a proprietary code analysis tool that is not available in the standard Cloud Build builder images. You want to make this tool available to your build steps while following security best practices and ensuring build reproducibility. What is the recommended approach?

Question 7Choose 2

A new developer on your team is using Gemini Code Assist in their IDE. They want to generate unit tests for a complex function they have written in Python. Which TWO of the following actions are best practices for effectively using Gemini Code Assist for this task? (Select TWO).

Question 8Choose one

You are deploying a new version of a critical microservice to Cloud Run. To minimize the risk of a faulty deployment affecting all users, you want to first deploy the new version without sending it any production traffic. After verifying its health through internal tests, you then want to gradually shift 100% of the traffic to it. Which deployment command sequence should you use?

Question 9Choose one

Your application, running on Compute Engine, needs to read sensitive configuration data stored in Secret Manager. To adhere to the principle of least privilege and avoid managing service account keys, what is the most secure method for the application to authenticate to the Secret Manager API?

Question 10Choose one

True or False: When using the Cloud SQL Auth Proxy to connect from a GKE pod to a Cloud SQL instance, you must configure a firewall rule to allow TCP traffic on port 3307 from the GKE nodes to the Cloud SQL instance's public IP address.

10 more free samples are waiting

Create a free account to unlock the whole PCD sample bank, or get full access to all 289 practice questions in the simulator.

Create account