
Google Cloud Professional Cloud DevOps Engineer
The Google Cloud Professional Cloud DevOps Engineer certification validates your ability to design and operate reliable, efficient, and secure software delivery systems on Google Cloud. It is intended for DevOps engineers and SREs who build and manage CI/CD pipelines, monitor services, and optimize for reliability and performance. Earning this credential demonstrates that you can apply SRE principles and Google Cloud best practices to keep production workloads healthy and continuously improving.
520 practice questions · Updated 2026-07-30
PROFESSIONAL-CLOUD-DEVOPS-ENGINEER Curriculum
Every domain, objective, and concept the PROFESSIONAL-CLOUD-DEVOPS-ENGINEER exam measures.
- Resource hierarchy design
- Project organization patterns
- Folder structure and policies
- Shared VPC setup
- VPC Network Peering
- Private Service Connect
- Multi-project monitoring
- Centralized logging
- IAM roles at organization level
- Organization policies
- Service account lifecycle
- Service account keys and impersonation
- Data residency considerations
- Infrastructure-as-Code (IaC) tooling and managed services
- Google-recommended practices for infrastructure changes
- Automation with scripting languages
- Cloud Build fundamentals
- Cloud Build CI pipeline design
- Cloud Deploy fundamentals
- Kustomize for environment customization
- Skaffold for continuous development and delivery
- Artifact Registry configuration
- Integrating third-party CI/CD tools
- Securing CI/CD pipelines
- Ephemeral environment lifecycle
- Ephemeral environment provisioning
- Configuration management across environments
- Policy management across environments
- GKE fleet management
- GKE cluster lifecycle management
- Safe patching practices
- Secure upgrading practices
- Rollback and recovery strategies
- Cloud Workstations configuration
- Cloud Shell usage
- Custom image creation for development environments
- IDE and Cloud SDK setup
- Bootstrapping environments with tooling
- Gemini Code Assist
- Gemini Cloud Assist
- Gemini CLI
- CI/CD for Applications
- CI/CD for Infrastructure
- Artifact Registry Fundamentals
- Artifact Lifecycle and Security
- Hybrid and Multi-Cloud Deployment
- GKE Deployment Strategies
- Pipeline Trigger Types
- Trigger Conditions and Filtering
- Approval Flows in Deployments
- Deployment Process Configuration
- Audit deployment history
- Track artifact provenance
- Trace pipeline execution
- Compare deployment strategies
- Implement feature flags
- Define deployment success metrics
- Set up automated rollback criteria
- Diagnose failed deployments
- Mitigate deployment issues
- Validate ML pipeline deployments
- Cloud KMS key management
- Secret Manager usage
- Certificate Manager usage
- Parameter Manager usage
- Workload Identity Federation
- Build-time secret injection
- Runtime secret injection
- Comparing build vs runtime secret handling
- Artifact Analysis
- Vulnerability Scanning Integration
- Binary Authorization
- SLSA Framework
- Supply Chain Security Best Practices
- Environment-Based IAM Policies
- Separation of Duties
- SLI definition
- SLO definition
- SLA definition
- Error budget calculation
- Error budget usage in Cloud Service Mesh
- Opportunity cost of risk
- Number of nines interpretation
- Service lifecycle planning
- Service deployment strategies
- Service maintenance operations
- Service retirement process
- Understanding quotas and limits
- Reservations for capacity
- Dynamic Workload Scheduler
- Autoscaling fundamentals
- Managed instance group autoscaling
- Cloud Run autoscaling
- GKE autoscaling
- Traffic draining
- Traffic redirecting
- Capacity scaling
- Rollback strategies
- Ops Agent
- OpenTelemetry
- Cloud Audit Logs
- VPC Flow Logs
- Cloud Service Mesh Telemetry
- Log Filtering
- Log Sampling
- Log Exclusions
- Log Cost Management
- Log Source Considerations
- Application Metrics Collection
- Platform Metrics Collection
- Networking Metrics Collection
- Cloud Service Mesh Metrics
- Google Cloud Managed Service for Prometheus
- Hybrid and Multi-Cloud Metrics
- Synthetic Monitor Creation
- Synthetic Monitor Workflows
- Custom Metrics Creation
- Log-Based Metrics
- Logs Explorer navigation
- Logging query language basics
- Advanced query techniques
- Log-based metrics and alerts
- Log sinks and routing
- Log retention and lifecycle
- Exporting logs to BigQuery
- Exporting logs to Pub/Sub
- Exporting logs to Cloud Storage
- Sensitive data identification
- Log redaction with processors
- Data masking and de-identification
- Gemini Cloud Assist for log analysis
- Integrating Gemini with Logs Explorer
- Metrics Explorer fundamentals
- Metrics querying and filtering
- Dashboard creation and customization
- Dashboard filtering and sharing
- Dashboard playbooks
- PromQL for dashboards
- Alerting policy fundamentals
- SLI and SLO-based alerting
- Alert cost control
- Third-party alerting integration
- Gemini Cloud Assist for metrics
- OpenTelemetry tracing fundamentals
- Instrumenting applications for tracing
- Trace context propagation
- Reading trace waterfalls
- Analyzing span attributes and events
- Correlating trace IDs with structured logs
- Using Gemini Cloud Assist for trace analysis
- Infrastructure issue identification
- Infrastructure issue troubleshooting
- CI/CD pipeline failure analysis
- CI/CD pipeline troubleshooting
- Application error diagnosis
- Application issue resolution
- Observability data gap detection
- Observability tooling troubleshooting
- Performance bottleneck analysis
- Latency issue diagnosis
- Application performance monitoring
- Active Assist insights
- Active Assist recommendations
- Observability costs
- Spot VMs basics
- Using Spot VMs
- Resource optimization principles
- Committed-use discounts
- Sustained-use discounts
- Network tier selection
- Cost recommenders
- Security and performance recommenders
- Manageability and reliability recommenders
- GKE cost optimization
- Cloud Run cost optimization
- Compute Engine cost optimization
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for PROFESSIONAL-CLOUD-DEVOPS-ENGINEER, so none is invented.