Google Professional Cloud Developer Exam Guide (2026)

If you can say whether the stem is buying a Cloud Run service, a GKE Deployment, or a Compute Engine guest, whether the store is a document, a regional SQL engine, or a global ledger, and whether the next step is a Cloud Build test or an Eventarc trigger, you are reading the right outline.
Professional Cloud Developer is the Google Cloud certification for people who build and configure scalable, secure applications with Google-recommended tools. The Professional Cloud Developer certification page is the source for length, fee, question count, and recommended experience. The Professional Cloud Developer exam guide is the source for the four scored sections and the product names used on the sitting.
The sitting is live. There is no prerequisite exam. Google recommends 3 or more years of industry experience, including 1 or more years designing and managing solutions using Google Cloud. This guide is for people scheduling the current standard exam, people who already hold the title and need the current task list, and people moving from Associate Cloud Engineer work into the application-developer role.
Who this exam is for
Take it as a map of the Google Cloud developer job the current exam guide scores. The audience profile asks for someone who can hold a runtime, hold a store, hold a build, and then stay with production when a request, a secret, or a trace breaks. The same profile expects Google-recommended tools, not a private toolchain the sitting never names. The certification page also names generative AI APIs and AI-assisted development tools as part of that job. Those names appear on the outline as Gemini Cloud Assist, AI coding assistants, MCP servers, and AI-assisted observability. They are not a fifth section.
The responsibility list on the certification page is concrete. Design highly scalable, secure, and reliable cloud-native applications. Build and test applications. Configure cloud-native applications for deployment. Integrate applications with Google Cloud services. Those four verbs are the four scored sections. The sitting punishes people who treat the role as a catalog of logos and rewards people who can read a constraint and pick the runtime, the store, the build, and the signal that match it.
There is no required prior certification. The recommended experience is the gap check. If projects, Identity and Access Management roles, Cloud Storage buckets, and gcloud are still a catalog rather than weekly work, sit Associate Cloud Engineer first. The developer sitting assumes those controls and then asks which runtime and which client library to recommend. If the goal is the language of Google Cloud rather than the operation of an application, Cloud Digital Leader is the closer match. Service definitions, shared responsibility, and product families belong there. They appear here as the vocabulary inside a service, not as the whole job.
Skip it if the work you actually want is deploying someone else's design day to day without owning the container, the schema, or the deploy trigger. That job is Associate Cloud Engineer. Skip it if the work you actually want is the compute shape, the network path, and a named case-study constraint across an entire solution. Those decisions are the Professional Cloud Architect sitting. Application products appear there as one recommendation among many. They are scored here as the entire job. Skip it if the stem you actually want is a Beam job or a warehouse reservation. BigQuery appears here as a write target for analytics. It is not the Professional Data Engineer sitting. Skip it if the stem you actually want is a Cloud Build promotion sequence, an SLO, or a PromQL query. Cloud Build and Artifact Registry appear on this outline as the developer build. They are not the Professional Cloud DevOps Engineer sitting. Skip it if the work you actually want is the identity, the key, and the compliance folder. Secret Manager, Cloud KMS, Identity-Aware Proxy, and Binary Authorization appear here as application controls. They are scored as the entire job on the Professional Cloud Security Engineer sitting. Skip it if the stem you actually want is a VPC path, a hybrid circuit, or a Cloud NGFW rule. Direct VPC egress appears here as a Cloud Run network attachment. It is not the Professional Cloud Network Engineer sitting.
The current professional developer credential Google publishes for this role is this one. Use this page for the Professional Cloud Developer task list. Use the Google Associate Cloud Engineer exam guide when the stem is an operator control that happens to sit on a service. Use the Google Professional Cloud Architect exam guide when the stem is a solution recommendation that happens to include Cloud Run. Use the Google Professional Cloud DevOps Engineer exam guide when the stem is a promotion sequence rather than a unit test. Use the Google Professional Cloud Security Engineer exam guide when the stem is an identity, a key, or a finding rather than an application secret. Use the Google Professional Data Engineer exam guide when the stem is a data platform rather than an application write. Use the Google Professional Cloud Network Engineer exam guide when the stem is a packet path rather than a Direct VPC attachment.
Exam shape and how a pass is decided
The current exam guide publishes four sections and marks each weight as an approximation.
| Section | Weight | What gets tested |
|---|---|---|
| Designing highly scalable, secure, and reliable cloud-native applications | about 32% | Compute Engine, GKE, and Cloud Run, containers, regional and zonal services, load balancers, session affinity, Memorystore, HTTP REST and gRPC APIs, Apigee and Cloud API Gateway, Eventarc and Pub/Sub, resource and cost limits, zonal and regional failover, traffic splitting on Cloud Run or GKE, Workflows, Cloud Tasks, and Cloud Scheduler, Cloud Storage lifecycle and retention locks, Identity-Aware Proxy, Web Security Scanner, Artifact Analysis, Security Command Center, Secret Manager, Cloud Key Management Service, Workload Identity Federation, Application Default Credentials, Cloud SQL Auth Proxy, AlloyDB Auth Proxy, Identity Platform, Cloud Service Mesh, Kubernetes Network Policies, Direct VPC egress, Binary Authorization, AlloyDB, Spanner, Bigtable, Firestore, Cloud SQL, signed URLs, and BigQuery writes |
| Building and testing applications | about 23% | Local emulation with the Google Cloud CLI, Google Cloud console, Cloud SDK, Cloud Code, Gemini Cloud Assist, Cloud Shell, Cloud Workstations, IDE integrations including AI tooling and MCP servers, Cloud Build, Artifact Registry, build provenance for Binary Authorization, unit tests with AI coding assistants, and automated integration tests in Cloud Build |
| Configuring cloud-native applications for deployment | about 24% | Cloud Run from source, Eventarc and Pub/Sub triggers and receivers, Apigee versioning and API exposure, GKE container deploys, Kubernetes health checks, and Horizontal Pod Autoscaler attributes |
| Integrating applications with Google Cloud services | about 21% | Connections to Cloud SQL, Firestore, and Cloud Storage, read and write paths, publish and consume messaging, enabling services, Cloud Client Libraries, REST, gRPC, and API Explorer, batching, restricted return data, pagination, caching, exponential backoff, service accounts for API calls, metrics, logs, and traces in Google Cloud Observability, Error Reporting, correlated trace IDs, and AI-assisted observability |
Do the arithmetic on those approximations before building a plan. The four midpoints total 100%. Google still prints a tilde on every band, so no exact split exists to memorize. Section 1 is the heaviest band. Section 3 sits next. Section 2 sits next. Section 4 is the lightest band. Any study plan that gives four equal weeks overweights integration and underweights design.
The logistics come off the certification page. The standard sitting is 2 hours. The format is 50 to 60 multiple choice and multiple select questions. Languages are English and Japanese. The registration fee is 200 USD, and tax where applicable. Delivery is online-proctored from a remote location or onsite-proctored at a testing center. Prerequisites are none. The certification page does not print a Validity period field this pass. Google Cloud Certification Exam Policies and Exam Terms and Conditions say a Professional Certification is valid for two years from the date of issue.
Case studies are not a scored share on this sitting. The certification page and the official exam guide PDF name no companies and no case-study percentage. Do not study a fifth company a dump site invented. Do not carry Professional Cloud Architect case-study habits onto this timer as if they were official here.
Scoring is the part most third-party pages get wrong. The certification page and the exam guide do not publish a numeric passing score, a scaled range, or a percent hedge. Exam Terms and Conditions say that if you pass an Exam, you will receive a digital certificate after Google has validated your score. That is the official pass language. This guide does not invent a 700 mark or a 70 percent story for a vendor that did not publish one.
The same terms page is the source for retakes and for how long the credential lasts. Associate and Professional exams allow a maximum of four attempts in a two year period. After a failed attempt, the wait is 14 days. After a second failed attempt, the wait is 60 days. After a third failed attempt, the wait is 365 days before a fourth attempt. Each attempt requires payment. Passing a Professional exam during renewal extends validity for two years from the date of passing.
Renewal on this title follows the exam path. Professional renewal eligibility on the terms page begins 60 days before expiration. The certification page sends holders to Renewal FAQs for the eligibility window. That page does not publish a shorter 1 hour sitting, a 20 question count, or a 100 USD fee for this title. Do not invent those numbers from a different Google exam. After the eligibility window, the path back is the standard exam.
Two more details change how the sitting is taken. Google may update exam content at any time to reflect changes to Google Cloud technology. The certifications hub says exams are being updated for product updates announced at Google Cloud Next '26, including Gemini Enterprise Agent Platform and Google Cloud's data and analytics stack. The current Professional Cloud Developer guide does not score Gemini Enterprise Agent Platform. It names Gemini Cloud Assist, AI coding assistants, MCP servers, and AI-assisted observability. The product names that matter on this timer are the names on the current exam guide, not the names on last month's console banner.
What the current outline changed
The exam guide does not publish a Microsoft-style change-log table. The official delta is the set of names the current pages print.
The certification page for this title opens with a branding-change banner this pass. The exam was updated to reflect recent branding changes. The exam guide is the place to review the product names used on the exam. The current guide already says Cloud Run, GKE, Compute Engine, Memorystore, Apigee, Cloud API Gateway, Eventarc, Pub/Sub, Workflows, Cloud Tasks, Cloud Scheduler, Identity-Aware Proxy, Web Security Scanner, Artifact Analysis, Security Command Center, Secret Manager, Cloud KMS, Workload Identity Federation, Cloud SQL Auth Proxy, AlloyDB Auth Proxy, Identity Platform, Cloud Service Mesh, Direct VPC egress, Binary Authorization, AlloyDB, Spanner, Bigtable, Firestore, Gemini Cloud Assist, Cloud Code, Cloud Workstations, Cloud Build, Artifact Registry, MCP servers, and AI-assisted observability.
The certifications hub is more specific about the product wave. Exams are being updated to reflect product updates announced at Google Cloud Next '26, including Gemini Enterprise Agent Platform and Google Cloud's data and analytics stack. The current Professional Cloud Developer guide does not put Gemini Enterprise Agent Platform on a scored section. A study plan that treats that name as a developer extra is studying a different professional exam.
Current product docs have already moved some of those names. The sitting has not finished every move.
| Name on the exam guide | Name on current first-party docs | What that means on the sitting |
|---|---|---|
| Cloud Run | Cloud Run services, jobs, and worker pools | A request or event container without a cluster is Cloud Run, not a leftover App Engine-only story |
| Cloud API Gateway | API Gateway | A lighter API front door next to Apigee is Cloud API Gateway |
| Gemini Cloud Assist | Gemini Cloud Assist overview | An assistant in the console, Cloud Shell, or an IDE is Gemini Cloud Assist, not Gemini Enterprise Agent Platform |
| Artifact Analysis | Container scanning in Artifact Analysis | A CVE in an image is Artifact Analysis. A deploy-time allow or deny is Binary Authorization |
| Direct VPC egress | Direct VPC with a VPC network | Cloud Run into a VPC is Direct VPC egress, not a Serverless VPC Access connector by default |
| Google Cloud Observability | Observability in Google Cloud, the current family page | Metrics, logs, and traces sit under that family. Error Reporting is still its own product |
Validity and renewal changed the calendar around the sitting even when the four section names stayed close. Professional Cloud Developer lasts 2 years on the terms page. Foundational and Associate credentials last 3 years on the same page. Mixing those clocks is how people schedule the wrong renewal door.
Three things follow for anyone holding older material.
The four section names are still the spine. Design, build and test, deploy, and integrate are still the scored map. Notes organized on those four headings are still structurally useful.
The product names inside those headings are in motion. Cloud Run, Gemini Cloud Assist, Direct VPC egress, and Cloud API Gateway are the names the exam guide prints. A flashcard that only knows last year's console label, and cannot map it back to the outline, is already off the current PDF.
This sitting has no official case-study PDFs. Time spent on invented company names is time taken from section 1.
How a compute shape gets picked
Section 1 is about 32%, the heaviest band. The same habit shows up in deploy stems and integration stems as often as in design ones. The skill is small. Name whether the stem is buying a guest operating system, a Kubernetes cluster, or a fully managed container that should cost nothing when idle.

Select a managed container runtime environment is the Architecture Center page that turns those names into a decision. The page compares Cloud Run and GKE Autopilot after the team states its requirements. What is Cloud Run says Cloud Run is a fully managed application platform for running code. The page names services, jobs, and worker pools. GKE and Cloud Run draws the line in one table. Cloud Run is the path when the team provides source or a container and does not want to create a cluster. It fits stateless request or event-driven services, web services, and functions. Billing is pay-per-use, rounded to the nearest 100 milliseconds. GKE is the path when the team needs the Kubernetes API, a stateful cluster pattern, custom networking, or deep cluster control. GKE bills for the cluster by the hour. The same container image can run on both platforms. The Cloud Run Admin API v1 is designed to be compatible with the Kubernetes API. A retail front end on Cloud Run and a stateful inventory service on GKE is a documented hybrid, not a contradiction.
Compute Engine overview is the guest-operating-system path. The team picks the machine type, the disk, the image, and the kernel behavior. Custom machine types, GPUs, and TPUs live here. A stem that wants full control of the operating system, a line-of-business installer that cannot be containerized, or a specialized machine that only exists as a virtual machine, is a Compute Engine stem. Putting that installer on Cloud Run because Cloud Run is this week's flashcard is the trap when the stem never asked for a container contract.
Choose a load balancer is the official decision page. Choose an Application Load Balancer for HTTP or HTTPS. Choose a proxy Network Load Balancer for TCP proxy load balancing. Choose a passthrough Network Load Balancer when you must preserve the client source IP or support UDP. External load balancers take internet clients. Internal load balancers take clients already on the VPC or a hybrid path. Session affinity is a design bullet on this outline. A stem about HTTPS with URL maps is an Application Load Balancer. A stem about raw TCP that must keep the client IP is a passthrough Network Load Balancer.
APIs have two front doors on the exam guide. What is Apigee? is API management. Versioning, exposing, securing, rate limiting, and a developer-facing proxy are Apigee. About API Gateway is the lighter Cloud API Gateway the outline names next to Apigee. HTTP REST and gRPC are the two application protocols the PDF prints. A stem about a managed API program is Apigee. A stem about a simpler serverless API front door is Cloud API Gateway. Treating those as one "API product" story is how section 1.1 is lost.
Async work is four answers, not one. What is Pub/Sub is the service-to-service bus. Latencies are typically on the order of 100 milliseconds. Publishers send events. Subscribers process them. Pub/Sub is not the path for a mobile client talking to one backend. Eventarc overview routes events from Google sources to Cloud Run and other targets. Workflows overview is serverless orchestration. A workflow is a YAML or JSON definition. The service scales as needed and incurs no charges while idle. A workflow can hold state, retry, poll, or wait for up to a year. Understand Cloud Tasks is the asynchronous service-call and queue path. About Cloud Scheduler is cron. A stem about fan-out before anyone transforms the payload is Pub/Sub. A stem about a Google source that must wake Cloud Run is Eventarc. A stem about a multi-step HTTP sequence that must cost nothing when idle is Workflows. A stem about a deferred HTTP task is Cloud Tasks. A stem about every Monday at 09:00 is Cloud Scheduler.
Memorystore for Redis overview is the cache. It is a fully managed in-memory store built for sub-millisecond access. A stem about a session key or a hot object is Memorystore. A stem about a durable checkout ledger is not.
Rollbacks, gradual rollouts, and traffic migration is how Cloud Run splits traffic for a gradual rollout, a rollback, or an A/B test. The exam guide names the same traffic-splitting habit on GKE. A stem about sending 10 percent of requests to a new Cloud Run revision is traffic splitting. Rewriting the service on GKE because the team already has a cluster is the trap when the stem never asked for the Kubernetes API.
| Control | What the stem is buying | First Google Cloud product | What it does not do well |
|---|---|---|---|
| Guest OS | A kernel, an installer, or a machine type that only exists as a VM | Compute Engine | Scale-to-zero containers |
| Managed container | Source or a container, no cluster, idle cost near zero | Cloud Run | A StatefulSet and a custom CNI |
| Kubernetes API | `kubectl`, a sidecar mesh, or a stateful cluster pattern | GKE | An idle API that must cost nothing |
| HTTP front door | HTTPS, URL maps, or session affinity | Application Load Balancer | Raw UDP |
| API program | Versioning, rate limits, and a managed proxy | Apigee | A one-route Cloud Run URL |
| Light API door | A simpler serverless API front | Cloud API Gateway | A full developer portal |
| Fan-out bus | Many subscribers, 100 millisecond class delivery | Pub/Sub | A mobile client channel |
| Event route | A Google source that must wake a service | Eventarc | A long HTTP saga |
| Saga | A multi-step HTTP sequence with retries | Workflows | A Kafka-style bus |
| Task queue | A deferred HTTP call | Cloud Tasks | Fan-out to many subscribers |
| Cron | A clock trigger | Cloud Scheduler | An event from Cloud Storage |
| Cache | Sub-millisecond keys | Memorystore | A durable ledger |
| Traffic split | 10 percent to a new revision | Cloud Run traffic migration | A new GKE cluster |
Read the constraint the stem is buying. An existing server that must move with the guest intact is Compute Engine. A stateless container the team will only deploy is Cloud Run. A container whose team must keep the Kubernetes API is GKE. A public checkout page that needs URL maps is an Application Load Balancer. A managed API program is Apigee. Events that must fan out before anyone transforms them are Pub/Sub. A Google source that must wake Cloud Run is Eventarc. A short HTTP sequence that must cost nothing when idle is Workflows.
How a data store gets picked
Storage sits inside section 1.3 and again in the connection bullets of section 4.1. Most of those questions reduce to one skill. Name whether the stem is about an object, a document, a regional relational engine, a PostgreSQL HTAP ledger, a global relational ledger, a wide-column key, a cache, or a warehouse. Then name the service that implements that model.

Design an optimal storage strategy for your cloud workload still sorts Google Cloud storage into block, file, and object. The exam guide's own storage bullet is more specific for this sitting. It names AlloyDB and Spanner for structured schemas, Bigtable and Firestore for unstructured schemas, and Cloud SQL, Cloud Storage, and BigQuery in the same family of decisions. Read the access pattern before reading the brand.
| Model | What it is built for | First Google Cloud services to consider | What it does not do well |
|---|---|---|---|
| Object | Media, backups, signed downloads | Cloud Storage, with Standard, Nearline, Coldline, or Archive | Multi-row transactions |
| Document | Flexible JSON, mobile clients | Firestore | Warehouse-scale analytics |
| Relational, regional | MySQL, PostgreSQL, or SQL Server with managed backups | Cloud SQL | Horizontal write scale across regions without a redesign |
| Relational, PostgreSQL HTAP | Analytical queries on live PostgreSQL transactions | AlloyDB | A cheap lift of SQL Server |
| Relational, global | Horizontal writes, strong consistency, multi-region | Spanner | A cheap lift of a single-zone SQL Server with no rewrite budget |
| Wide-column operational | High throughput, single key, low latency | Bigtable | Complex multi-row SQL as the system of record |
| Cache | Sub-millisecond keys, session state | Memorystore | A durable system of record |
| Warehouse | Analytics after the fact | BigQuery | The system of record for a checkout ledger |
Cloud SQL overview is the managed MySQL, PostgreSQL, or SQL Server service. Cloud SQL handles backups, high availability and failover, encryption, connectivity, storage, export and import, replication, maintenance, monitoring, and logging. A stem about lifting those engines with the least rewrite is Cloud SQL. A stem that names a SQL Server feature the team refuses to give up is still Cloud SQL, not Spanner.
AlloyDB overview is the managed PostgreSQL-compatible service built for demanding applications and for hybrid transactional and analytical processing. The product page says it runs complex analytical queries against live transactional data. A stem about PostgreSQL that must serve analytics on the live ledger is AlloyDB. A stem about SQL Server is not.
Spanner is the globally distributed relational database with horizontal scale and strong consistency. A stem about a checkout ledger that must take writes in more than one region without the team sharding by hand is Spanner. A stem about a regional reporting database that already runs on PostgreSQL and must move this quarter is Cloud SQL or AlloyDB, depending on the analytical load.
Firestore overview is the Native mode document model. A stem about a mobile client that syncs documents is Firestore. JSON in Cloud Storage does not make that bucket a document database.
Bigtable overview is the wide-column operational store. It is built for large amounts of single-keyed data with low latency and high read and write throughput. A stem about a row key, a column family, or a high-throughput time series is Bigtable. Putting that series in BigQuery because the analyst wants SQL later is the trap when the stem is still the application write path.
Cloud Storage is the object landing zone. Storage classes pick the cost curve. Standard has no minimum duration and no retrieval fee, and it is the class for data that is read often. Nearline has a 30 day minimum and a retrieval fee, and it is the class for data read about once a month. Coldline has a 90 day minimum and is the class for data read about once a quarter. Archive has a 365 day minimum, is the lowest-cost class, and still returns data in milliseconds. Signed URLs grant time-bounded object access without making the bucket public. Object Lifecycle Management ages objects. Bucket Lock locks a retention policy so it cannot be shortened or removed. A stem about a private download that must expire is a signed URL. A stem about last year's objects that must stay cheap but still open quickly is Archive. A stem about a retention policy that must not move is Bucket Lock.
BigQuery overview is the warehouse. Compute and storage are separate. Section 1.3 asks the developer to write data to BigQuery for analytics and AI/ML workloads. A stem about a dashboard after the fact is BigQuery. A stem about a checkout that must take writes in two regions with strong consistency is not.
Consistency is its own bullet. The exam guide names eventual and strongly consistent replication for AlloyDB, Bigtable, Cloud SQL, Spanner, and Cloud Storage. A stem about a read that must see the write it just made in another region is Spanner or a strongly consistent Cloud Storage read. A stem that can wait for a replica is a different answer. Mixing those two is how section 1.3 is lost.
Application security sits in section 1.2 next to the store, because the secret and the key are how the application reaches the store. Secret Manager overview stores, versions, and rotates secrets. Cloud Key Management Service overview stores encryption keys. Workload Identity Federation is how an external workload gets a Google token without a downloaded key. About the Cloud SQL Auth Proxy and About the AlloyDB Auth Proxy are the named database auth paths. How Application Default Credentials works is how client libraries find credentials in order. Identity-Aware Proxy overview is application-level access in front of Cloud Run, Compute Engine, or GKE. Overview of Web Security Scanner finds application vulnerabilities. Container scanning overview finds CVEs in images. Binary Authorization overview is the deploy-time allow or deny. Cloud Service Mesh overview is service-to-service identity and traffic policy. Direct VPC with a VPC network is how Cloud Run reaches private backends without treating a connector as the only story. A stem about a password in source is Secret Manager. A stem about a customer-managed key is Cloud KMS. A stem about GitHub Actions talking to Google APIs is Workload Identity Federation. A stem about a user at a URL is Identity-Aware Proxy. A stem about a CVE in an image is Artifact Analysis. A stem about blocking that image at deploy is Binary Authorization.
How build, test, and deploy get picked
Section 2 is about 23%. Section 3 is about 24%. Together they are almost half the sitting. The skill is small. Name whether the stem is buying a local emulator, an IDE, a build, an image store, a Cloud Run revision, or a GKE rollout.

Google Cloud SDK overview is the local surface. The exam guide asks for emulating Google Cloud services with the Google Cloud CLI for local application development and local unit testing. Cloud Code extensions put that surface in an IDE. Gemini Cloud Assist overview is the named assistant. Cloud Workstations overview is a managed IDE on a VPC. Cloud Shell documentation is the browser shell. A stem about writing a unit test against an emulator is the Google Cloud CLI. A stem about an IDE that must stay inside the VPC is Cloud Workstations. A stem about a browser terminal is Cloud Shell. Naming Gemini Enterprise Agent Platform for those stems is how the Next '26 hub sentence is misread.
Overview of Cloud Build builds containers from source. Artifact Registry overview stores those containers. The exam guide names provenance in Cloud Build as the Binary Authorization input. A stem about a Dockerfile becoming an image is Cloud Build. A stem about where that image lives is Artifact Registry. A stem about proving who built it is provenance. A stem about blocking an unsigned image at GKE or Cloud Run is Binary Authorization. Treating Artifact Analysis and Binary Authorization as one "image security" answer is how section 2.2 is lost. Artifact Analysis finds the CVE. Binary Authorization decides whether the image may run.
Testing has two clocks. Unit tests run locally and may use AI coding assistants. Automated integration tests run in Cloud Build. A stem about a function that must pass on a laptop is a unit test. A stem about a Cloud Run service that must talk to a real Firestore in a pipeline is an integration test. Skipping the Cloud Build job because the laptop already passed is the trap when the outline already named automated integration tests.
Deploy services from source code is section 3.1. Cloud Run can take source and build the container. Eventarc and Pub/Sub are the two invoke paths the exam guide names. Versioning, exposing, and securing APIs in those applications is Apigee again. A stem about gcloud run deploy from a directory is source deploy. A stem about a bucket event that must wake that service is Eventarc. A stem about a topic that must wake it is Pub/Sub. A stem about wrapping that URL in an API product is Apigee.
GKE is section 3.2. Deploy the container. Implement Kubernetes health checks so the platform restarts or withholds traffic when a Pod is sick. The exam guide names those health checks. Current first-party GKE probe how-to URLs opened this pass were leftovers, so the draft keeps that bullet on the official PDF and on the GKE sitting next to Horizontal Pod autoscaling. HPA scales Pods from metrics. A stem about CPU crossing a threshold is HPA. A stem about a load balancer probe on a forwarding rule is a different control. Health checks overview is the Cloud Load Balancing page. Do not mix those two probes.
| Control | What the stem is buying | First Google Cloud product | What it does not replace |
|---|---|---|---|
| Local emulator | Unit tests against a fake Google API | Google Cloud CLI | A Cloud Build integration test |
| Browser shell | A terminal in the console | Cloud Shell | A VPC-bound IDE |
| Managed IDE | An editor inside the VPC | Cloud Workstations | Cloud Shell |
| IDE plugin | Deploy and debug from the desktop editor | Cloud Code | A pipeline |
| Assistant | Help in the console or the IDE | Gemini Cloud Assist | Gemini Enterprise Agent Platform |
| Build | Source to a container | Cloud Build | The image store |
| Image store | Versioned containers | Artifact Registry | The CVE scanner |
| Provenance | Who built this digest | Cloud Build provenance | A liveness probe |
| CVE scan | Vulnerabilities in the image | Artifact Analysis | A deploy policy |
| Deploy policy | Allow or deny that digest | Binary Authorization | A scanner |
| Source deploy | A directory onto Cloud Run | Cloud Run source deploy | A GKE Deployment |
| Event invoke | A Google source wakes Cloud Run | Eventarc | A cron job |
| Topic invoke | A Pub/Sub message wakes Cloud Run | Pub/Sub | Eventarc |
| Pod scale | More Pods when a metric rises | Horizontal Pod Autoscaler | A Cloud Run revision split |
| LB probe | A forwarding rule checks backends | Cloud Load Balancing health check | A Kubernetes probe |
Read the constraint. A laptop test against an emulator is the Google Cloud CLI. A pipeline that must build and scan is Cloud Build and Artifact Analysis. A digest that must not land on GKE is Binary Authorization. A directory that must become a URL is Cloud Run source deploy. A metric that must add Pods is HPA. Naming Cloud Build for every one of those is how the deploy band is wasted.
How integration and observability get picked
Section 4 is about 21%, the lightest band, and it is still the difference between a service that compiles and a service that can be operated. Name whether the stem is buying a client library habit, a connection to a store, a message, a log, a metric, a trace, or an error group.
Client libraries and Cloud APIs explained is the call-style page. The exam guide names Cloud Client Libraries, REST, gRPC, and API Explorer. Enable the service first. Then pick the client. Batch requests when the API supports it. Restrict return data so the payload stays small. Paginate results. Cache results that do not change. Handle errors with exponential backoff. How Application Default Credentials works is how those clients find a credential. Service accounts make the Cloud API calls. A stem about a downloaded JSON key in a repo is already the weaker design when Workload Identity Federation or a runtime service account is on the outline.
Connections in section 4.1 are the same stores from section 1.3, now from application code. Manage connections to Cloud SQL, Firestore, and Cloud Storage. Read and write. Publish and consume with a messaging service. Pub/Sub is still the Google-native bus. A stem about a Cloud SQL connection from Cloud Run is the Cloud SQL Auth Proxy or a private path, not a public IP in source. A stem about a signed download is still a signed URL. A stem about a topic the service both publishes to and subscribes to is Pub/Sub.
Observability in Google Cloud is the family page. Instrument code so metrics, logs, and traces land in Google Cloud Observability. Cloud Logging overview is the log. Cloud Monitoring overview is the metric. Cloud Trace overview is the span. Use trace IDs to correlate spans across services. Error Reporting documentation groups application errors. Gemini Cloud Assist returns here as AI-assisted observability. A stem about "which request crossed three services" is a trace ID. A stem about a new exception class is Error Reporting. A stem about request latency is Cloud Trace or a metric. A stem about a line the service printed is Cloud Logging. Naming Cloud Logging for every one of those is how the observability band is wasted.
| Control | What the stem is buying | First Google Cloud product | What it does not replace |
|---|---|---|---|
| Client library | Idiomatic calls from application code | Cloud Client Libraries | A raw curl in production |
| REST or gRPC | A protocol the library must speak | Cloud APIs | A warehouse reservation |
| Explorer | A one-off call from the console | API Explorer | A service account in production |
| Backoff | Retries that must not stampede | Exponential backoff | A larger machine type |
| Credential search | Libraries finding a token | Application Default Credentials | A checked-in key |
| DB socket | Cloud SQL from a container | Cloud SQL Auth Proxy | A public IP in source |
| Object grant | A time-bounded download | Signed URL | A public bucket |
| Message | Publish and consume | Pub/Sub | A Cloud SQL transaction |
| Log line | What the process printed | Cloud Logging | A distributed trace |
| Metric | A number on a dashboard | Cloud Monitoring | An exception group |
| Trace | Spans across services | Cloud Trace | A single log line |
| Error group | The same crash, counted | Error Reporting | A trace waterfall |
| Assist | Help reading those signals | Gemini Cloud Assist | A new log sink |
Read the constraint. A service that must call Cloud Storage from Python is a Cloud Client Library and Application Default Credentials. A download that must expire is a signed URL. A request that crossed Cloud Run and GKE is a trace ID. A new NullPointerException class is Error Reporting. A latency SLO the developer did not own is still a metric, and the Professional Cloud DevOps Engineer sitting is the one that scores the SLO. This sitting scores the instrumentation that makes that SLO possible.
How to study the current blueprint
Order the weeks by the weight bands, not by the order the products appear in a catalog.
Week 1. Design, the band near 32%. Draw one API three ways. Put the same HTTP handler on Compute Engine, on Cloud Run, and on GKE, and write down which operating-system task, which scale-to-zero behavior, and which Kubernetes API each one removed. Deploy one Cloud Run service from source and one Cloud Run job that exits. Create an Application Load Balancer in front of the service and write down why that is not a passthrough Network Load Balancer. Create a Pub/Sub topic with two subscribers. Create an Eventarc trigger onto the Cloud Run service. Write a Workflows definition that calls one HTTP endpoint and one Cloud Run service, and write down why that definition incurs no charge while idle. Create a Cloud Tasks queue and a Cloud Scheduler job and write down which one is a clock. Create a Memorystore instance and write down why it is not Firestore. Finish the week on Apigee versus Cloud API Gateway. For each recommendation, name the constraint that forced the product.
Week 2. Stores and application security, still inside the 32% band. Create one object, one document, and one relational engine. Put the same file in Cloud Storage as Standard, Nearline, Coldline, and Archive, and write down the minimum duration and the retrieval fee for each class. Create a signed URL and confirm it expires. Set a lifecycle rule and a locked retention policy. Create Cloud SQL for one engine the outline still names, then open the AlloyDB overview and write down the constraint that would have forced PostgreSQL HTAP instead. Open the Spanner product page and write down the constraint that would have forced global writes. Create a Firestore document and a Bigtable table and write down why neither is the warehouse. Write one row into BigQuery from the application. Then build the secret path. Store a secret in Secret Manager. Store a customer-managed key in Cloud KMS. Connect Cloud Run to Cloud SQL with the Cloud SQL Auth Proxy. Turn on Identity-Aware Proxy in front of the Cloud Run service. Scan an image with Artifact Analysis. Attach a Binary Authorization policy. Connect Cloud Run to a VPC with Direct VPC egress. Write down why that attachment is not Cloud NGFW.
Week 3. Build and test near 23%, deploy near 24%. Install the Google Cloud SDK and run one unit test against a local emulator. Open Cloud Code in an IDE. Open Cloud Workstations and Cloud Shell and write down which one is the VPC IDE. Use Gemini Cloud Assist only as far as the exam guide names it. Create a Cloud Build trigger that builds from source, pushes to Artifact Registry, and records provenance. Run an integration test in that build. Deploy the same digest to Cloud Run from source and to GKE as a Deployment. Split Cloud Run traffic 90 and 10. Add an Eventarc trigger and a Pub/Sub trigger. Put Apigee in front of the Cloud Run URL only when the stem is API management. On GKE, add a Horizontal Pod Autoscaler and write down the metric it watches. Keep Kubernetes health checks on the official exam guide. Do not invent a leftover GKE probe URL.
Week 4. Integration near 21%, and a full review. Call one Google API four ways. Use a Cloud Client Library, a REST call, a gRPC call, and API Explorer. Enable the service first. Batch one request, restrict the returned fields, paginate, cache, and force an error so exponential backoff is not theoretical. Publish a message and consume it. Open Cloud Logging, Cloud Monitoring, Cloud Trace, and Error Reporting on the same Cloud Run request and write down which signal each product held. Copy a trace ID across two services. Ask Gemini Cloud Assist to read a log only as far as the outline names AI-assisted observability. Then sit with the exam guide and, for each bullet, name the product, the runtime, and the constraint that would have forced that product.
Take any official sample questions the certification page still mentions and walk the exam tutorial at least once before using this outline against a clock. The sample set exists so the question format costs nothing on the timer. This guide does not reprint those items.
Traps that look like easy elimination
Developer items rarely give one plausible answer and three absurd ones. They give two runtimes that both sound correct and one detail that picks between them.
- There is no prerequisite certification. Recommended experience is still 3 or more years, including 1 or more years designing and managing solutions using Google Cloud. Showing up with only vocabulary from Cloud Digital Leader is how section 1 is lost.
- The standard sitting is 50 to 60 questions in 2 hours. Notes that quote a 40 to 50 question professional sitting are quoting a different exam.
- Google does not publish a numeric passing score on the certification page or the exam guide. A third-party 700 or 70 percent figure is not official language for this sitting.
- This sitting has no official case-study PDFs. A company name that does not appear on the exam guide is not part of the outline.
- Cloud Run is source or a container with no cluster and pay-per-use billing. GKE is the Kubernetes API and a cluster bill. Compute Engine is the guest operating system.
- The same container image can run on Cloud Run and on GKE. That fact does not make every stem a GKE stem.
- Apigee is API management. Cloud API Gateway is the lighter front door. Those are two answers.
- Pub/Sub fans out messages. Eventarc routes a Google source to a target. Workflows orchestrates HTTP steps. Cloud Tasks queues a deferred call. Cloud Scheduler is cron. Those are five answers.
- Memorystore is the cache. Firestore is documents. Cloud SQL is the managed engine lift. AlloyDB is PostgreSQL HTAP. Spanner is global relational. Bigtable is the operational wide-column store. Cloud Storage is objects. BigQuery is the warehouse.
- Signed URLs grant time-bounded object access. A public bucket is not that control. Bucket Lock locks retention. Lifecycle ages objects.
- Secret Manager stores secrets. Cloud KMS stores keys. Workload Identity Federation avoids a downloaded key. Identity-Aware Proxy is application-level access. Those are four answers.
- Artifact Analysis finds CVEs. Binary Authorization allows or denies a digest. Those are two answers.
- Direct VPC egress attaches Cloud Run to a VPC. It is not Cloud NGFW and it is not the Professional Cloud Network Engineer sitting.
- Cloud Build builds. Artifact Registry stores. Provenance proves who built the digest.
- Unit tests run locally, including with AI coding assistants. Integration tests run in Cloud Build.
- Kubernetes health checks are not Cloud Load Balancing health checks.
- Gemini Cloud Assist is the assistant this outline names. Gemini Enterprise Agent Platform is a Next '26 hub theme and a Professional Cloud Security Engineer product. It is not a scored name on this exam guide.
- Professional Cloud Architect case studies are not this exam. Professional Cloud DevOps Engineer SLOs are not this exam. Professional Cloud Security Engineer identity folders are not this exam. Professional Data Engineer warehouses are not this exam. Professional Cloud Network Engineer circuits are not this exam. Associate Cloud Engineer operator clicks are the floor, not the sitting.
If deleting the scenario still lets you pick the answer from the service name, the question is easier than the live exam.
How this maps to CloudFluently
Start with the official material. The Professional Cloud Developer certification page carries the audience profile, the 2 hour timer, the 50 to 60 question format, the 200 USD fee, and the recommended experience. The Professional Cloud Developer exam guide carries the four sections and the product names. Exam Terms and Conditions explain what it means to pass an Exam, how long a Professional Certification lasts, and the 14 day, 60 day, and 365 day retake waits.
Professional Cloud Developer sits on top of Google Cloud vocabulary and Google Cloud operations, and that ground is already live here. Shared responsibility, product families, and the idea of a cloud bill are the Cloud Digital Leader study notes. The Cloud Digital Leader exam guide is the vocabulary companion. Projects, IAM, Compute Engine, Cloud Storage, VPC networks, and the operator form of Cloud Run and GKE are the Associate Cloud Engineer study notes. The Associate Cloud Engineer exam guide is the operator companion.
The architect reading of Cloud Run or GKE, when the stem is still a solution recommendation rather than an application control, is the Professional Cloud Architect exam guide. The delivery reading of Cloud Build, when the stem is a promotion sequence rather than a unit test, is the Professional Cloud DevOps Engineer exam guide. The security reading of Secret Manager, Cloud KMS, Identity-Aware Proxy, or Binary Authorization, when the stem is an identity, a key, or a finding rather than an application secret, is the Professional Cloud Security Engineer exam guide. The warehouse reading of BigQuery, when the stem is a pipeline or a reservation rather than an application write, is the Professional Data Engineer exam guide. The network reading of Direct VPC egress, when the stem is a packet path rather than a Cloud Run attachment, is the Professional Cloud Network Engineer exam guide.
Work those until the vocabulary, the operator controls, and the neighboring professional habits are automatic, then use this page and the official exam guide for the developer-only skills: the runtime, the store, the build, and the signal that holds them.
What is the passing score for Professional Cloud Developer? Google does not publish a numeric passing score on the certification page or the exam guide. Exam Terms and Conditions say that if you pass an Exam, you receive a digital certificate after Google has validated your score.
How long is the exam and how many questions are there? The standard sitting is 2 hours with 50 to 60 multiple choice and multiple select questions.
Does this exam use case studies? The certification page and the official exam guide do not publish case studies for this sitting. Study the four sections and the named products.
Is there a prerequisite? No. Google recommends 3 or more years of industry experience, including 1 or more years designing and managing solutions using Google Cloud.
How long does the certification last? A Professional Certification is valid for two years from the date of issue. Renewal is the applicable Exam during the professional eligibility window, which the terms page starts 60 days before expiration. Passing that Exam extends validity for two years from the date of passing.
Can I retake it if I fail? Associate and Professional exams allow four attempts in two years. The waits are 14 days after the first fail, 60 days after the second, and 365 days after the third. Each attempt is paid.
What changed on the current outline? The certification page says the exam was updated for branding. The current guide already names Cloud Run, Gemini Cloud Assist, Cloud API Gateway, Eventarc, Direct VPC egress, AlloyDB, Binary Authorization, Cloud Build provenance, and AI-assisted observability. The certifications hub points at Google Cloud Next '26 product updates. The product names that matter are the names on the current exam guide.
Which section is heaviest? Designing highly scalable, secure, and reliable cloud-native applications is about 32%. Configuring cloud-native applications for deployment is about 24%. Building and testing applications is about 23%. Integrating applications with Google Cloud services is about 21%.
Does Google publish a 700 or 70 percent pass mark? No. That figure is not on the certification page, the exam guide, or the terms page opened for this guide.
How does this exam relate to Associate Cloud Engineer, Professional Cloud Architect, and the other professional titles? Cloud Digital Leader scores vocabulary. Associate Cloud Engineer scores the operator controls. Professional Cloud Architect scores the solution recommendation. Professional Cloud DevOps Engineer scores the pipeline stage. Professional Cloud Security Engineer scores the identity, the key, and the finding. Professional Data Engineer scores the data platform. Professional Cloud Network Engineer scores the path, the balancer, and the circuit. Professional Cloud Developer scores the runtime, the store, the build, and the application signal. The official outline is the Professional Cloud Developer exam guide. Use Google for the task statements. Use this page for how those statements get picked, what the current names are, and how to sequence the blueprint.
