View Full Google Professional Cloud Developer Exam Dumps and Practice Test Dumps.
Question 1
Which Google Cloud service provides a fully managed environment for deploying containerized applications without managing the underlying infrastructure?
- Cloud Storage
- Cloud Run
- Cloud DNS
- Cloud Logging
Correct Answer: 2
Explanation
Cloud Run is a fully managed Google Cloud platform designed to run containerized applications without requiring developers to provision or maintain servers. It automatically scales instances based on incoming requests and can scale down to zero when there is no traffic. Developers can deploy container images and configure resources, networking, and authentication according to application requirements. Cloud Storage is an object storage service, Cloud DNS manages domain name resolution, and Cloud Logging collects and analyzes logs. Cloud Run is suitable for stateless web applications, APIs, and event-driven services packaged as containers.
Question 2
A developer needs to store application secrets, such as database passwords and API keys, securely in Google Cloud. Which service should be used?
- Cloud Monitoring
- Cloud Build
- Secret Manager
- Cloud CDN
Correct Answer: 3
Explanation
Secret Manager is a Google Cloud service for securely storing, managing, and accessing sensitive information such as passwords, API keys, certificates, and other application secrets. It supports versioning, access control through IAM, and audit logging, helping developers manage secret lifecycles without embedding credentials in source code. Applications can retrieve secrets at runtime using authorized identities. Cloud Monitoring focuses on observability, Cloud Build automates build processes, and Cloud CDN accelerates content delivery. Secret Manager helps reduce the risk of credential exposure and supports safer configuration practices across development and production environments.
Question 3
Which Google Cloud service is designed to build, test, and deploy application code using automated pipelines?
- Cloud Build
- Cloud Armor
- Cloud NAT
- Cloud Storage
Correct Answer: 1
Explanation
Cloud Build is a managed service for executing build, test, and deployment workflows. Developers can define build steps in configuration files, connect source repositories, and automate tasks such as compiling code, running tests, building container images, and deploying applications to Google Cloud services. It integrates with artifact repositories and supports triggers for continuous integration workflows. Cloud Armor provides application protection, Cloud NAT enables outbound network connectivity for private resources, and Cloud Storage stores objects. Cloud Build is therefore appropriate for automating repeatable software delivery processes and improving consistency between application releases.
Question 4
An application running on Google Cloud needs a managed relational database with support for SQL transactions and automated backups. Which service is appropriate?
- Cloud Bigtable
- Cloud Storage
- Cloud Pub/Sub
- Cloud SQL
Correct Answer: 4
Explanation
Cloud SQL is a managed relational database service supporting engines such as MySQL, PostgreSQL, and SQL Server. It provides database administration capabilities, including automated backups, maintenance, monitoring, and options for high availability. Applications can connect using supported database protocols and authentication configurations. Cloud SQL is useful when an application requires relational tables, SQL queries, transactions, and established database features without managing database servers directly. Cloud Bigtable is a wide-column NoSQL database, Cloud Storage is object storage, and Cloud Pub/Sub is a messaging service. Cloud SQL is therefore suitable for many conventional transactional application workloads.
Question 5
A developer is creating an event-driven application that must receive and process messages asynchronously from multiple producers. Which Google Cloud service should be selected?
- Cloud DNS
- Cloud Pub/Sub
- Cloud CDN
- Cloud Monitoring
Correct Answer: 2
Explanation
Cloud Pub/Sub is a messaging service that enables asynchronous communication between independent application components. Producers publish messages to topics, while subscribers receive messages through subscriptions and process them at their own pace. This architecture helps decouple services, absorb traffic fluctuations, and support event-driven workflows. Developers can use it for application events, data ingestion, task distribution, and integration between systems. Cloud DNS resolves domain names, Cloud CDN caches content closer to users, and Cloud Monitoring provides observability. Cloud Pub/Sub is appropriate when multiple producers need to communicate reliably with asynchronous message consumers.
Question 6
Which Google Cloud service provides a managed Kubernetes environment for deploying and operating containerized applications?
- App Engine
- Cloud Functions
- Google Kubernetes Engine
- Cloud Scheduler
Correct Answer: 3
Explanation
Google Kubernetes Engine (GKE) is a managed Kubernetes service for deploying, scaling, and operating containerized applications. It provides Kubernetes control-plane management and integrates with Google Cloud services for networking, logging, monitoring, identity, and storage. Developers can use Kubernetes deployment resources, services, and configuration objects to manage application workloads. GKE is useful when applications require Kubernetes orchestration capabilities, custom workload configuration, or coordination across multiple containers. App Engine is a platform for managed application hosting, Cloud Functions provides event-driven functions, and Cloud Scheduler triggers jobs on schedules. GKE is the appropriate choice for managed Kubernetes workloads.
Question 7
A developer wants to host a web application using a managed platform that automatically handles infrastructure provisioning and application scaling. Which service is designed for this purpose?
- Compute Engine
- Cloud VPN
- Cloud Storage
- App Engine
Correct Answer: 4
Explanation
App Engine is a platform-as-a-service offering that allows developers to deploy applications without directly managing the underlying server infrastructure. It provides managed runtime environments, application versioning, traffic management, and scaling capabilities. Developers focus primarily on application code and configuration while Google Cloud manages much of the platform operation. App Engine is useful for web applications and services that fit its supported runtimes and deployment model. Compute Engine provides virtual machines, Cloud VPN connects networks securely, and Cloud Storage stores objects. App Engine is appropriate when a managed application hosting platform is preferred over direct infrastructure management.
Question 8
A developer needs to store and distribute container images used by a CI/CD pipeline. Which Google Cloud service is designed for managing container artifacts?
- Artifact Registry
- Cloud Trace
- Cloud Scheduler
- Cloud DNS
Correct Answer: 1
Explanation
Artifact Registry is a managed service for storing, managing, and securing software artifacts, including container images and language-specific packages. It integrates with Google Cloud build and deployment services, allowing pipelines to publish versioned artifacts and retrieve them during application deployment. IAM permissions can control which identities are allowed to read, write, or administer repositories. Cloud Trace supports distributed tracing, Cloud Scheduler manages scheduled jobs, and Cloud DNS provides domain name resolution. Artifact Registry is therefore suitable for maintaining container images and other build outputs throughout a software delivery lifecycle.
Question 9
A developer wants to grant a Cloud Run service permission to read objects from a specific Cloud Storage bucket without using a user’s personal credentials. What should be configured?
- Public bucket access
- A service account with appropriate IAM permissions
- A shared administrator password
- An unrestricted firewall rule
Correct Answer: 2
Explanation
A service account provides an identity for an application or workload running on Google Cloud. By assigning an appropriate service account to the Cloud Run service and granting it the required Cloud Storage IAM permissions, the application can access the specified bucket without relying on a developer’s personal credentials. Permissions should be limited to the resources and operations the application actually needs. Public bucket access exposes data more broadly, shared administrator passwords weaken accountability, and firewall rules do not grant storage authorization. A dedicated service account with narrowly scoped IAM permissions supports secure workload-to-service access.
Question 10
Which Google Cloud service collects metrics, supports dashboards, and can alert developers when application performance thresholds are exceeded?
- Cloud Deploy
- Cloud Storage
- Cloud Monitoring
- Cloud NAT
Correct Answer: 3
Explanation
Cloud Monitoring collects metrics from Google Cloud resources and supported application integrations, allowing teams to observe system health and performance. Developers can create dashboards, define alerting policies, and configure notifications when monitored conditions exceed specified thresholds. Monitoring can help identify resource saturation, availability issues, latency increases, and other operational concerns. Cloud Deploy manages delivery workflows, Cloud Storage stores objects, and Cloud NAT provides outbound connectivity for private resources. Cloud Monitoring is therefore the appropriate service for tracking application and infrastructure metrics and notifying teams about potential reliability or performance problems.
Question 11
A developer needs to expose an application through a stable HTTPS endpoint and distribute incoming traffic across multiple backend instances. Which Google Cloud capability is most relevant?
- Cloud Load Balancing
- Secret Manager
- Cloud Scheduler
- Cloud Build
Correct Answer: 1
Explanation
Cloud Load Balancing distributes incoming application traffic across configured backend resources and can provide a stable frontend address. Google Cloud load balancers support features such as health checks, traffic distribution, and integration with managed certificate options, depending on the selected load-balancing configuration. This helps applications handle traffic across multiple instances and improves service availability when backends are configured appropriately. Secret Manager stores sensitive information, Cloud Scheduler triggers jobs at defined times, and Cloud Build automates software build processes. Cloud Load Balancing is therefore relevant when an application needs a stable HTTPS entry point and traffic distribution across backend instances.
Question 12
A developer wants to execute a small function in response to an event without managing a server or container platform directly. Which service should be considered?
- Cloud SQL
- Cloud Functions
- Artifact Registry
- Cloud DNS
Correct Answer: 2
Explanation
Cloud Functions provides a managed environment for running event-driven code without requiring developers to administer servers. Functions can respond to supported triggers, such as HTTP requests or events from integrated Google Cloud services. This model is useful for lightweight processing, automation, and application integration tasks where execution is initiated by an event. Developers can focus on the function logic, configuration, and permissions while the platform manages the execution environment. Cloud SQL provides relational databases, Artifact Registry stores software artifacts, and Cloud DNS manages DNS records. Cloud Functions is therefore appropriate for event-triggered application logic.
Question 13
A team wants to manage application source code, review changes, and collaborate through Git-based repositories integrated with Google Cloud development workflows. Which service is designed for source code hosting?
- Cloud CDN
- Cloud Armor
- Cloud Source Repositories
- Cloud NAT
Correct Answer: 3
Explanation
Cloud Source Repositories is a Google Cloud source code management service designed to host private Git repositories and integrate with development workflows. It can support collaboration, version control, and connections to services used for building and deploying applications. Teams can track changes, manage branches, and connect repository events to automated delivery processes where supported. Cloud CDN accelerates content delivery, Cloud Armor helps protect applications from web attacks, and Cloud NAT provides outbound network translation. Cloud Source Repositories is therefore the service associated with Git-based source code hosting in Google Cloud.
Question 14
An application needs to store large amounts of unstructured data, such as images, documents, and backup files, with high durability. Which service should be used?
- Cloud SQL
- Cloud Storage
- Cloud Pub/Sub
- Cloud Trace
Correct Answer: 2
Explanation
Cloud Storage is a scalable object storage service designed for unstructured data, including images, documents, media files, and backups. Objects are stored in buckets, and access can be controlled through IAM and other supported security features. Developers can use Cloud Storage APIs and client libraries to upload, retrieve, and manage objects from applications. Storage classes support different access patterns and cost considerations. Cloud SQL is a relational database, Cloud Pub/Sub handles asynchronous messaging, and Cloud Trace supports distributed tracing. Cloud Storage is therefore suitable for durable storage of application files and other unstructured content.
Question 15
A developer wants to schedule a recurring task, such as triggering a data-processing endpoint every night. Which Google Cloud service can initiate jobs on a defined schedule?
- Cloud Scheduler
- Cloud Trace
- Secret Manager
- Cloud Armor
Correct Answer: 1
Explanation
Cloud Scheduler is a managed service for scheduling jobs using cron-style schedules. It can invoke supported targets, such as HTTP endpoints or integrated Google Cloud services, enabling recurring tasks without requiring a continuously running scheduler application. Developers can configure schedules, target details, and authentication as appropriate for the workload. It is useful for nightly processing, periodic maintenance, scheduled reports, and other time-based automation. Cloud Trace provides tracing information, Secret Manager stores sensitive values, and Cloud Armor helps protect applications. Cloud Scheduler is therefore appropriate for initiating recurring tasks at defined times.
Question 16
A developer wants to trace requests as they pass through several services in a distributed application to identify latency between components. Which service is appropriate?
- Cloud DNS
- Cloud Storage
- Cloud Trace
- Cloud NAT
Correct Answer: 3
Explanation
Cloud Trace helps developers analyze latency across distributed applications by collecting and presenting trace information for supported instrumentation and integrations. It can show how requests move through application components and help identify where time is spent during processing. This is valuable for diagnosing slow API calls, inefficient service interactions, and performance bottlenecks in systems composed of multiple services. Cloud DNS handles name resolution, Cloud Storage stores objects, and Cloud NAT provides outbound connectivity. Cloud Trace is therefore appropriate when developers need to investigate request latency and understand performance across distributed application components.
Question 17
A developer needs to protect a public web application against common web attacks and apply security policies at the application edge. Which Google Cloud service is designed for this purpose?
- Cloud Scheduler
- Cloud Armor
- Cloud SQL
- Artifact Registry
Correct Answer: 2
Explanation
Cloud Armor provides application security capabilities for supported Google Cloud load-balancing configurations. It can enforce security policies that help protect public-facing applications against common web threats, including attacks addressed by configured filtering and web application firewall rules. Security teams can define policies based on application requirements and monitor relevant traffic activity. Cloud Scheduler triggers scheduled jobs, Cloud SQL provides managed relational databases, and Artifact Registry stores software artifacts. Cloud Armor is therefore appropriate when an organization needs to apply edge security policies to protect a web application from malicious or unwanted traffic.
Question 18
A developer wants to deploy an application to a Google Cloud environment while keeping application configuration separate from the source code. Which practice is appropriate?
- Hard-code all environment settings
- Store every setting in a public repository
- Use environment variables or managed configuration
- Embed production credentials in the container image
Correct Answer: 3
Explanation
Separating application configuration from source code allows the same application artifact to be deployed across environments with different settings. Environment variables and managed configuration services can supply values such as service endpoints, feature flags, and non-secret runtime options. Sensitive values should be stored in a secure service such as Secret Manager rather than embedded in source code, public repositories, or container images. Hard-coded settings make changes and deployments less flexible, while exposing credentials creates security risks. Using environment-specific configuration supports maintainability, safer deployments, and consistent application behavior across development, testing, and production.
Question 19
A developer needs to identify which application version is receiving traffic and gradually direct users to a newer release. Which deployment capability can support controlled traffic migration on App Engine?
- Traffic splitting
- Cloud NAT
- Object versioning
- Database replication
Correct Answer: 1
Explanation
App Engine traffic splitting allows requests to be distributed among application versions according to configured proportions. This can support gradual rollout strategies, enabling developers to expose a new version to a limited share of traffic before increasing its allocation. Teams can observe application behavior and use monitoring information to inform subsequent rollout steps. Traffic splitting can reduce the scope of an initial release, although it does not eliminate the need for testing, rollback planning, and compatibility checks. Cloud NAT, object versioning, and database replication serve different infrastructure or data-management purposes rather than controlling App Engine version traffic.
Question 20
A developer wants to grant a deployment pipeline permission to publish container images to a specific Artifact Registry repository, without granting broad project-wide access. What should be done?
- Make the repository public
- Grant the pipeline identity an appropriate repository-level IAM role
- Use an employee’s personal account
- Disable authentication
Correct Answer: 2
Explanation
Granting the deployment pipeline identity an appropriate IAM role at the Artifact Registry repository level follows the principle of least privilege. This allows the pipeline to perform required operations, such as publishing container images, without receiving unnecessary access across the entire project. The exact role should match the pipeline’s responsibilities, and its credentials or identity configuration should be protected. Making the repository public or disabling authentication can expose artifacts, while using an employee’s personal account creates operational and accountability concerns. Repository-level IAM permissions provide a more controlled approach to authorizing automated image publishing.