Google Professional Cloud DevOps Engineer Exam Guide (2026)

If you can say whether the stem is a Cloud Build trigger, a Cloud Deploy promotion, or an Artifact Registry digest, whether the reliability control is an SLO or an error budget, and whether the next clue lives in a log, a metric, a trace, or a synthetic probe, you are reading the right outline.
Professional Cloud DevOps Engineer is the Google Cloud certification for people who implement processes through the systems development lifecycle, keep delivery speed and reliability in the same plan, and then stay with production for performance and cost. The Professional Cloud DevOps Engineer certification page is the source for length, fee, question count, and recommended experience. The Professional Cloud DevOps Engineer exam guide is the source for the five scored sections and the product names used on the sitting.
The sitting is live. There is no prerequisite exam. Google recommends 3 or more years of industry experience, including 1 or more years designing and managing production systems using Google Cloud. This guide is for people scheduling the current standard exam, people who already hold the title and need the current task list, and people moving from Associate Cloud Engineer work into the delivery and reliability role.
Who this exam is for
Take it as a map of the Google Cloud DevOps job the current exam guide scores. The audience profile asks for someone who can bootstrap an organization, hold a pipeline, hold an SLO, and then read production when the deploy or the budget goes wrong. The same profile expects Google-recommended methods and tools, not a private toolchain the sitting never names.
The responsibility list on the certification page is concrete. Bootstrap and maintain a Google Cloud organization. Apply site reliability engineering practices. Build and implement CI/CD pipelines, including continuous testing, for application, infrastructure, and machine learning workloads. Implement observability practices and troubleshoot issues. Optimize performance and cost. Those five verbs are the five scored sections. The sitting punishes people who treat the role as a catalog of logos and rewards people who can read a constraint and pick the pipeline stage, the reliability control, and the telemetry signal that match it.
There is no required prior certification. The recommended experience is the gap check. If projects, Identity and Access Management roles, Cloud Storage buckets, and gcloud are still a catalog rather than weekly work, sit Associate Cloud Engineer first. The DevOps sitting assumes those controls and then asks which pipeline and which SLO to recommend. If the goal is the language of Google Cloud rather than the operation of a production system, Cloud Digital Leader is the closer match. Service definitions, shared responsibility, and product families belong there. They appear here as the vocabulary inside a pipeline, not as the whole job.
Skip it if the work you actually want is deploying someone else's design day to day without owning the promotion sequence, the error budget, or the log sink. That job is Associate Cloud Engineer. Skip it if the work you actually want is the compute shape, the network path, and a named case-study constraint across an entire solution. Those decisions are the Professional Cloud Architect sitting. Delivery products appear there as one recommendation among many. They are scored here as the entire job. Skip it if the stem you actually want is a Beam job, a warehouse model, or a slot reservation. Pipelines appear on this outline as application, infrastructure, and machine learning delivery. They are not the Professional Data Engineer sitting.
The current professional DevOps credential Google publishes for this role is this one. Use this page for the Professional Cloud DevOps Engineer task list. Use the Google Associate Cloud Engineer exam guide when the stem is an operator control that happens to sit on a pipeline. Use the Google Professional Cloud Architect exam guide when the stem is a solution recommendation that happens to include a deploy. Use the Google Professional Data Engineer exam guide when the stem is a data platform rather than a delivery platform.
Exam shape and how a pass is decided
The current exam guide publishes five sections and marks each weight as an approximation.
| Section | Weight | What gets tested |
|---|---|---|
| Bootstrapping and maintaining a Google Cloud organization | about 20% | Resource hierarchy, Shared VPC, VPC Network Peering, Private Service Connect, multi-project monitoring and logging, IAM and organization policies, service accounts, data residency, Infrastructure Manager, Cloud Foundation Toolkit, Config Connector, GitOps, Terraform, Helm, Cloud Build, Cloud Deploy with Kustomize and Skaffold, Artifact Registry, Git, Jenkins, Argo CD, Packer, kpt, ephemeral environments, GKE fleets, Cloud Workstations, Cloud Shell, Gemini Code Assist, Gemini Cloud Assist, and Gemini CLI |
| Building and implementing CI/CD pipelines, including continuous testing, for application, infrastructure, and machine learning workloads | about 25% | Pipeline design, Artifact Registry, hybrid and multi-cloud including GKE, triggers, approval flows, Cloud Build, Cloud Deploy, Cloud Audit Logs, canary, blue-green, rolling, traffic splitting, feature flags, success metrics from application or ML telemetry, Cloud Key Management Service, Secret Manager, Certificate Manager, Parameter Manager, Workload Identity Federation, build versus runtime secret injection, Artifact Analysis, Binary Authorization, and SLSA |
| Applying site reliability engineering practices | about 18% | SLIs, SLOs, SLAs, error budgets, Cloud Service Mesh, nines, service lifecycle, quotas, limits, reservations, Dynamic Workload Scheduler, autoscaling on managed instance groups, Cloud Run, and GKE, then drain or redirect traffic, add capacity, and roll back |
| Implementing observability practices and troubleshooting issues | about 25% | Ops Agent, OpenTelemetry, Cloud Audit Logs, VPC Flow Logs, Cloud Service Mesh, log filtering and sampling and exclusions, Google Cloud Managed Service for Prometheus, synthetic monitors, custom and log-based metrics, Logs Explorer, logging query language, routes to BigQuery, Pub/Sub, and Cloud Storage, redaction of PII and PHI, Gemini Cloud Assist for logs, Metrics Explorer, dashboards, PromQL, alerting, webhooks, PagerDuty, Rootly, traces, waterfalls and spans, correlated trace IDs, Gemini Cloud Assist for traces, and infrastructure, pipeline, application, observability, and latency issues |
| Optimizing performance and cost | about 12% | Application performance monitoring, Active Assist insights, observability costs, Spot VMs, committed-use discounts, sustained-use discounts, network tiers, recommenders for cost, security, performance, manageability, and reliability, and workload cost on GKE, Cloud Run, and Compute Engine |
Do the arithmetic on those approximations before building a plan. The five midpoints total 100%. Google still prints a tilde on every band, so no exact split exists to memorize. Sections 2 and 4 sit together at the top. Section 1 sits next. Section 3 sits next. Section 5 is the lightest band. Any study plan that gives five equal weeks overweights cost and underweights pipelines and telemetry.
The logistics come off the certification page. The standard sitting is 2 hours. The format is 50 to 60 multiple choice and multiple select questions. Languages are English and Japanese. The registration fee is 200 USD, and tax where applicable. Delivery is online-proctored from a remote location or onsite-proctored at a testing center. Prerequisites are none. The certification page does not print a Validity period field this pass. Google Cloud Certification Exam Policies and Exam Terms and Conditions say a Professional Certification is valid for two years from the date of issue.
Case studies are not a scored share on this sitting. The certification page and the official exam guide PDF name no companies and no case-study percentage. Do not study a fifth company a dump site invented. Do not carry Professional Cloud Architect case-study habits onto this timer as if they were official here.
Scoring is the part most third-party pages get wrong. The certification page and the exam guide do not publish a numeric passing score, a scaled range, or a percent hedge. Exam Terms and Conditions say that if you pass an Exam, you will receive a digital certificate after Google has validated your score. That is the official pass language. This guide does not invent a 700 mark or a 70 percent story for a vendor that did not publish one.
The same terms page is the source for retakes and for how long the credential lasts. Associate and Professional exams allow a maximum of four attempts in a two year period. After a failed attempt, the wait is 14 days. After a second failed attempt, the wait is 60 days. After a third failed attempt, the wait is 365 days before a fourth attempt. Each attempt requires payment. Passing a Professional exam during renewal extends validity for two years from the date of passing.
Renewal on this title follows the exam path. Professional renewal eligibility on the terms page begins 60 days before expiration. The certification page sends holders to Renewal FAQs for the eligibility window. That page does not publish a shorter 1 hour sitting, a 20 question count, or a 100 USD fee for this title. Do not invent those numbers from a different Google exam. After the eligibility window, the path back is the standard exam.
Two more details change how the sitting is taken. Google may update exam content at any time to reflect changes to Google Cloud technology. The certifications hub says exams are being updated for product updates announced at Google Cloud Next '26, including Gemini Enterprise Agent Platform and Google Cloud's data and analytics stack. The product names that matter on this timer are the names on the current exam guide, not the names on last month's console banner.
What the current outline changed
The exam guide does not publish a Microsoft-style change-log table. The official delta is the set of names the current pages print.
The certification page for this title does not open with a branding-change banner this pass. The exam guide is still the place to review the product names used on the exam. The current guide already says Gemini Code Assist, Gemini Cloud Assist, Gemini CLI, Parameter Manager, Cloud Service Mesh, Google Cloud Managed Service for Prometheus, Artifact Analysis, Binary Authorization, SLSA, Dynamic Workload Scheduler, Active Assist, Cloud Workstations, Cloud Deploy, Kustomize, and Skaffold.
The certifications hub is more specific about the product wave. Exams are being updated to reflect product updates announced at Google Cloud Next '26, including Gemini Enterprise Agent Platform and Google Cloud's data and analytics stack. The current Professional Cloud DevOps Engineer guide already puts Gemini assistance on development and on logs, metrics, and traces. A study plan that treats those names as optional extras is studying last year's job.
Current product docs have already moved some of those names. The sitting has not finished every move.
| Name on the exam guide | Name on current first-party docs | What that means on the sitting |
|---|---|---|
| Artifact Analysis | Artifact Analysis, formerly Container Analysis. The new name does not change existing products or APIs | A vulnerability-scan stem is still Artifact Analysis on the outline |
| Cloud Service Mesh | Cloud Service Mesh. The overview still addresses Anthos Service Mesh and Traffic Director customers | An error-budget or mesh-telemetry stem is still Cloud Service Mesh on the outline |
| Gemini Cloud Assist | Gemini Cloud Assist, a multi-agent assistant that uses infrastructure, code, policy, and live operations as context | A log, metric, or trace analysis stem that names Gemini is Gemini Cloud Assist |
| Gemini Code Assist | Gemini Code Assist Standard and Enterprise | A development-environment stem that names Gemini for code is Gemini Code Assist |
| Parameter Manager | Parameter Manager, an extension of Secret Manager for configuration | A feature-flag or connection-string stem is Parameter Manager. The password behind it is Secret Manager |
| Active Assist | Active Assist, the Recommender portfolio with six value categories | A cost, security, or reliability recommendation stem is Active Assist |
| Google Cloud Managed Service for Prometheus | Google Cloud Managed Service for Prometheus | A PromQL or Prometheus scrape stem is that managed service, not a self-managed Prometheus VM the outline never asked for |
Validity and renewal changed the calendar around the sitting even when the five section names stayed close. Professional Cloud DevOps Engineer lasts 2 years on the terms page. Foundational and Associate credentials last 3 years on the same page. Mixing those clocks is how people schedule the wrong renewal door.
Three things follow for anyone holding older material.
The five section names are still the spine. Organization, pipelines, SRE, observability, and cost are still the scored map. Notes organized on those five headings are still structurally useful.
The product names inside those headings are in motion. Artifact Analysis, Cloud Service Mesh, Parameter Manager, and Gemini Cloud Assist are the names the exam guide prints. A flashcard that only knows last year's console label, and cannot map it back to the outline, is already off the current PDF.
This sitting has no official case-study PDFs. Time spent on invented company names is time taken from sections 2 and 4.
How a CI/CD stack gets picked
Section 2 is about 25%, tied for the heaviest band, and the same discriminator shows up in organization stems and incident stems as often as in pipeline ones. Section 1.3 already named Cloud Build, Cloud Deploy, Artifact Registry, Kustomize, and Skaffold. Section 2 then scores the design, the promotion, the secret, and the deploy-time gate.

The exam guide maps delivery work to Cloud Build, Cloud Deploy, Artifact Registry, Artifact Analysis, Binary Authorization, and SLSA. Read the stage the stem is buying before reading the logo.
Cloud Build is the CI service. Overview of Cloud Build says the service executes builds on Google Cloud. It can import source from repositories or Cloud Storage, run the steps you specify, and produce artifacts such as Docker containers or Java archives. Each build step runs in a Docker container. A YAML or JSON build config is the script. Triggers start a new build from a code change. Integrations include Cloud Source Repositories, GitHub, and Bitbucket. Built artifacts can be pushed to Artifact Registry. Cloud Build features meet SLSA level 3. Each build gets an ephemeral virtual machine that is destroyed when the job finishes. A stem about unit tests, a Dockerfile, build provenance, or a trigger on a pull request is Cloud Build. Putting that work on Cloud Deploy because the team already has a delivery pipeline is the trap when the stem never asked for a promotion sequence.
Cloud Deploy is the CD service. Overview of Cloud Deploy says the service automates delivery to a series of target environments in a defined promotion sequence. A release lifecycle is managed by a delivery pipeline. Cloud Deploy uses Skaffold to render, deploy, and verify, so a skaffold.yaml file is part of the contract. The first call creates a release and a rollout to the first target. Later calls promote. A target can require approval. Approval events go to Pub/Sub. A rollback creates a new rollout against the last successful release. Downstream targets on that page are Google Kubernetes Engine, Cloud Run, and GKE attached clusters. A stem about staging, then canary, then production, or about an approval before prod, is Cloud Deploy. Rewriting that promotion as a second Cloud Build trigger is the trap when the stem asked for the sequence.
Artifact Registry is the store between those two. Artifact Registry overview says the service is the central place for packages and Docker container images. It stores artifacts from Cloud Build and deploys them to GKE, Cloud Run, Compute Engine, and App Engine flexible environment. It is the recommended container registry. Remote, connector, and virtual repositories give control over upstream dependencies. A stem about a digest, a repository IAM binding, or a trusted dependency cache is Artifact Registry. Leaving the image in a developer's laptop registry is the trap when the outline already named the store.
Artifact Analysis is the scan. The Artifact Analysis overview says the service was formerly Container Analysis and that the new name does not change existing products or APIs. Vulnerability scanning is based in Artifact Registry. A stem about CVEs on an image the pipeline just pushed is Artifact Analysis. Blocking the deploy of that image is Binary Authorization.
Binary Authorization is the deploy-time gate. Binary Authorization overview says the product implements software supply-chain security when you develop and deploy container applications. Enforcement allows only images that conform to a policy you define. Continuous validation can watch running Pods and write Cloud Logging entries when they drift. Supported platforms on that page include GKE, Cloud Run, Cloud Service Mesh, and Google Distributed Cloud. Related products named there include Artifact Registry, Artifact Analysis, Cloud Build, and Cloud Deploy. Attestations certify that an image completed a previous stage. At deploy time the policy checks the attestation instead of repeating the stage. A stem about "only images Cloud Build signed may reach prod" is Binary Authorization. Scanning the image and then deploying it anyway is the trap when the stem asked for the gate.
Secrets and keys are a different pair. Secret Manager overview stores API keys, passwords, and certificates as versions you can roll back. Secrets are encrypted in transit with TLS and at rest with AES-256. Customer-managed keys are optional. Regional secrets exist for data residency. Parameter Manager overview is an extension of Secret Manager for configuration. Connection strings, feature flags, and environment names live there. They can reference a secret without becoming the secret. Cloud Key Management Service manages cryptographic keys. You cannot extract the key bits. A stem about a password the app must read is Secret Manager. A stem about a feature flag the app must read is Parameter Manager. A stem about encrypting or signing is Cloud KMS. Injecting the secret at build time when the stem asked for runtime injection is the trap section 2.3 scores.
Workload Identity Federation is how a GitHub Action, a GitLab job, or an AWS workload reaches Google Cloud without a downloaded service account key. A stem about a key JSON in a pipeline secret is already the weaker control when the outline named federation.
| Stage | What the stem is buying | First Google Cloud product | What it does not do well |
|---|---|---|---|
| Build | Tests, images, provenance, SLSA level 3, ephemeral workers | Cloud Build | Promoting across environments |
| Store | Digests, repository IAM, trusted dependencies | Artifact Registry | Running the tests |
| Scan | Vulnerabilities on the stored image | Artifact Analysis | Blocking the cluster |
| Promote | Staging to production, approvals, rollback | Cloud Deploy | Compiling the source |
| Gate | Only attested images may deploy | Binary Authorization | Replacing the scanner |
| Secret | A value the app must read | Secret Manager | A feature flag |
| Config | A parameter the app must read | Parameter Manager | The password itself |
| Key | Encrypt or sign | Cloud KMS | Storing a readable password |
| Identity | A pipeline that must not download a key | Workload Identity Federation | A long-lived JSON key in the repo |
Read the constraint the stem is buying. A pull request that must run tests is Cloud Build. An image that must be stored and scanned is Artifact Registry and Artifact Analysis. A promotion that must stop for approval is Cloud Deploy. A cluster that must reject an unsigned digest is Binary Authorization. A password is Secret Manager. A feature flag is Parameter Manager. A GitHub job that must not hold a key file is Workload Identity Federation.
Infrastructure as code sits one layer earlier in section 1.2. Infrastructure Manager overview is a managed Terraform toolchain. It deploys Google Cloud resources from configurations in Cloud Storage, Git, or a local directory. It can preview a change before apply. It integrates with Cloud Build. It does not deploy applications onto those resources. Application delivery stays on Cloud Build and Cloud Deploy. Config Connector overview is a Kubernetes add-on that manages Google Cloud resources through Kubernetes. A stem about a Terraform blueprint is Infrastructure Manager. A stem about a Kubernetes custom resource that creates a Cloud SQL instance is Config Connector. A stem about a Helm chart that installs the app is still Helm. Those are three answers.
The organization around that stack is section 1.1. About resource hierarchy is organization, optional folders, then projects. IAM and organization policies inherit down. Projects belong to the organization, not the person who created them. Shared VPC designates a host project and attaches service projects so those projects can use subnets in the host network. Private Service Connect lets consumers reach services on their own internal addresses without leaving the VPC. A stem about one network for many application projects is Shared VPC. A stem about a private endpoint to a Google API or a published service is Private Service Connect. Flattening every team into one project to make logging easier is the trap when the outline already named multi-project monitoring.
Developer environments are section 1.5. Cloud Workstations overview is a preconfigured cloud IDE on a Compute Engine virtual machine with a persistent disk. A workstation cluster is a regional grouping in a VPC. It is not a GKE cluster. Cloud Shell is the browser terminal. Gemini Code Assist is the coding assistant. Gemini Cloud Assist is the operations assistant. Gemini CLI is the command-line assistant. A stem about a locked-down IDE in the VPC is Cloud Workstations. A stem about a five-minute terminal in the console is Cloud Shell.
How an SRE control gets picked
Section 3 is about 18%. The same habit shows up in pipeline success metrics and in alerting policies. The skill is small. Name whether the stem is buying a measurement, a target, a contract, or a budget. Then name the action when the budget is spent.

The Site Reliability Engineering page says SRE is a job function, a mindset, and a set of engineering practices to run reliable production systems. Google Cloud Observability is the named implementation surface. The exam guide is more specific. It names SLIs, SLOs, SLAs, error budgets, Cloud Service Mesh definitions, and the opportunity cost of nines.
An SLI is the measurement. Availability and latency are the examples the exam guide prints. An SLO is the target you set on that measurement. An SLA is the contract you sold. An error budget is the remainder. When the budget is healthy, change can move faster. When the budget is spent, reliability work outranks feature work. Cloud Service Mesh overview is the current name for the mesh that can hold those definitions. The overview still addresses Anthos Service Mesh and Traffic Director customers. A stem about a 99.9 percent availability target is an SLO. A stem about the refund clause in the customer contract is an SLA. A stem about whether the team may ship this week is an error budget. Treating those three words as synonyms is how section 3.1 is lost.
Service lifecycle is section 3.2. Planning, deployment, maintenance, and retirement are the verbs. Capacity planning on that bullet names quotas, limits, reservations, and Dynamic Workload Scheduler. Autoscaling names managed instance groups, Cloud Run, and GKE.
GKE overview is managed Kubernetes. Autopilot is the recommended mode. Google manages the control plane. Autopilot also manages worker nodes. Standard is the mode when the team must manage node pools. The same page tells teams to put the application pipeline on Cloud Build, Cloud Deploy, and Artifact Registry. How fleets work is the page for many clusters treated as one estate. Section 1.4 already named fleets. A stem about one cluster the team will size is GKE. A stem about many clusters that must share policy is a fleet.
What is Cloud Run is the serverless container platform. A service responds to HTTP on a stable HTTPS endpoint and can scale to zero. Billing granularity is 100 milliseconds. Traffic can split across revisions, roll forward, or roll back. A job runs to completion. A worker pool pulls background work. A stem about a stateless API that should cost nothing when idle is Cloud Run. A stem about a long-running process that needs a custom kernel is not. A stem about adding capacity during an incident can still be Cloud Run if the service just needs more instances. It can be a managed instance group if the estate is virtual machines. It can be a GKE node pool or Autopilot Pod scale if the estate is Kubernetes.
Incident impact is section 3.3. The three actions the exam guide prints are drain or redirect traffic, add capacity, and roll back. Cloud Deploy rollback creates a rollout against the last successful release. Cloud Run traffic management can send requests back to the previous revision. Binary Authorization does not roll back an incident. It prevents the next bad digest. A stem about users already hitting a bad revision is drain, redirect, add capacity, or roll back. A stem about the next digest is the pipeline gate.
| Control | What the stem is buying | First product or idea | What it does not do |
|---|---|---|---|
| SLI | The measurement, availability or latency | Instrumentation on the service or the mesh | The customer refund |
| SLO | The target on that measurement | Service monitoring | Permission to miss the target forever |
| SLA | The sold contract | The legal document | The error budget the team uses this week |
| Error budget | Whether change may continue | Remaining unreliability | A reason to skip telemetry |
| Autoscale | Add or remove instances from load | Managed instance groups, Cloud Run, GKE | A substitute for a rollback when the revision is wrong |
| Rollback | Return to the last good release | Cloud Deploy or Cloud Run traffic | A scan of a new image |
| Fleet | Many GKE clusters as one estate | Fleet management | A single Autopilot cluster |
Read the constraint. A dashboard that must show request success ratio is an SLI. A weekly target of 99.9 percent is an SLO. A contract that pays back the customer is an SLA. A freeze on deploys after a bad week is an error budget. A queue of requests and idle instances is autoscaling. A bad digest already in production is rollback. Ten clusters that must share policy are a fleet.
How telemetry gets picked
Section 4 is about 25%, tied with pipelines for the heaviest band. Most of those questions reduce to one skill. Name whether the stem is about a log, a metric, a trace, or a synthetic probe. Then name the Google Cloud surface that holds that signal.

Cloud Logging overview is a real-time log-management system with storage, search, analysis, and monitoring. Google Cloud resources send logs automatically. Applications can send logs through a client library. The Ops Agent can send stdout and stderr, and it can collect third-party logs such as nginx. Logs Explorer is the interface for individual entries and for troubleshooting. Observability Analytics is the SQL interface for trends. Log-based alerting policies fire on rare important events, such as a line in Cloud Audit Logs. Log-based metrics count matching entries or extract numeric values for charts. Route log entries is the sink page. The default route is a log bucket on the project, folder, or organization that produced the entry. A sink can send the same entry to a custom bucket, Cloud Storage, BigQuery, or Pub/Sub, including a destination in another project. A stem about "who did what" is Cloud Audit Logs. A stem about last year's logs in a cheap bucket is a Cloud Storage sink. A stem about SQL over logs is a BigQuery sink. A stem about a third-party pager is a Pub/Sub sink. Keeping every debug line forever is the cost trap section 4.1 already named with filtering, sampling, and exclusions.
Cloud Monitoring overview is the metrics, dashboard, and alerting family. Metrics Explorer is the ad-hoc query surface. Dashboards can filter, share, and hold playbooks. PromQL appears on the exam guide next to those dashboards. Alerting policies can watch SLIs, SLOs, and cost. Third-party tools on the outline include webhooks, PagerDuty, and Rootly. Google Cloud Managed Service for Prometheus is the managed Prometheus path the exam guide prints by name. A stem about a PromQL query or a scrape config is that managed service. Standing up a Prometheus VM the team will patch by hand is the trap when the outline already named the managed service.
Cloud Trace overview is the distributed tracing system. It tracks request latency across services and generative AI applications. Trace Explorer shows waterfalls and spans. Observability Analytics can join traces and logs. Cloud Run incoming and outgoing HTTP requests send latency automatically. The page recommends OpenTelemetry over vendor-specific Trace client libraries. Spans in the _Trace bucket are retained for 30 days. Section 4.4 also scores correlating trace IDs with structured logs. A stem about why one request was slow is a trace. A stem about how often that request fails is a metric. A stem about the error string inside that request is a log.
Synthetic monitors are the probe that does not wait for a user. The live overview is Synthetic monitoring overview. The exam guide says to create synthetic monitors that probe application endpoints and workflows. A stem about a checkout path that must be tested every minute when no customer is on the site is a synthetic monitor. Waiting for a real user to fail is the trap.
Gemini Cloud Assist appears three times in section 4. The Gemini Cloud Assist overview describes a multi-agent assistant that uses infrastructure, application code, organizational policies, and live operational state as context. Section 4.2 names it for log analysis. Section 4.3 names it for metrics interpretation. Section 4.4 names it for trace analysis. A stem about an assistant that reads the current incident is Gemini Cloud Assist. A stem about an assistant that writes the next function in Cloud Workstations is Gemini Code Assist.
Sensitive data in logs is its own bullet. The exam guide names log processors that redact personally identifiable information and protected health information. A stem about a raw access token in a request log is a redaction job before the sink. Routing that log to BigQuery without redaction is the trap when the outline already named PII.
| Signal | What the stem is buying | First Google Cloud surface | What it does not replace |
|---|---|---|---|
| Log | The event, the error string, who did what | Cloud Logging, Logs Explorer, Cloud Audit Logs | A latency waterfall |
| Metric | How often, how much, is the SLO burning | Cloud Monitoring, Managed Service for Prometheus | The exact request that failed |
| Trace | Why this request was slow | Cloud Trace, OpenTelemetry | A count of all requests |
| Synthetic | A probe when no user is present | Synthetic monitors | A substitute for in-process instrumentation |
| Route | Keep, discard, or export the log | Logging sinks to buckets, BigQuery, Cloud Storage, Pub/Sub | A reason to skip exclusions |
| Assistant | Read the incident with current context | Gemini Cloud Assist | Gemini Code Assist in the IDE |
Read the constraint. A 500 in a request log is Logging. A rising error ratio is Monitoring. A 2 second span on a downstream call is Trace. A probe of /healthz every minute is a synthetic monitor. A cheap year of audit logs is a Cloud Storage sink. An assistant that explains the waterfall is Gemini Cloud Assist.
Section 4.5 then asks the candidate to use those signals on infrastructure, CI/CD, application, observability, and latency issues. A failed Cloud Build is still a pipeline issue. A saturated GKE node is an infrastructure issue. A missing trace exporter is an observability issue. Naming Cloud Logging for every one of those is how the heaviest band is wasted.
Section 5 is the lightest band at about 12%, and it reuses the same telemetry. Application performance monitoring and Active Assist insights are the collection bullets. What is Active Assist is the Recommender portfolio. Recommenders produce insights in six value categories. The exam guide names cost, security, performance, manageability, and reliability. Spot VMs are the interruptible compute option. Committed use discounts are the 1 year or 3 year commitment. Observability cost is its own bullet. Filtering and sampling in section 4.1 are how that bullet is paid. A stem about a batch worker that can die is a Spot VM. A stem about a year of steady CPU is a committed-use discount. A stem about a debug log line that costs more than the application is an exclusion.
How to study the current blueprint
Order the weeks by the weight bands, not by the order the products appear in a catalog.
Week 1. Pipelines, the band near 25%. Create a Cloud Build trigger on a repository and watch a build config run unit tests, build a container, and push the digest to Artifact Registry. Open the Cloud Build security insights panel and write down the SLSA level and whether provenance exists. Turn on Artifact Analysis on that repository and read one vulnerability finding. Create a Cloud Deploy delivery pipeline with two targets and a skaffold.yaml file. Promote a release from the first target to the second. Require approval on the second target. Roll the release back and confirm Cloud Deploy created a new rollout against the last successful release. Create a Binary Authorization policy that requires a Cloud Build attestation before GKE or Cloud Run will take the image. Store a database password in Secret Manager and a feature flag in Parameter Manager. Bind a GitHub Action with Workload Identity Federation so the pipeline does not download a service account key. Finish the week by naming Jenkins, Argo CD, Packer, and kpt only when the stem already has them.
Week 2. Observability, the band near 25%. Install the Ops Agent on a virtual machine and confirm stdout reaches Cloud Logging. Write one structured application log that includes a trace ID. Open Logs Explorer and find that entry with the logging query language. Create a log exclusion for a noisy debug line and a log-based metric for a 500. Create a sink to BigQuery and a sink to Cloud Storage and write down why those destinations are different. Create a Cloud Monitoring dashboard with one SLI chart and one alerting policy. Open Google Cloud Managed Service for Prometheus and run one PromQL query. Create a synthetic monitor that probes an HTTPS endpoint. Send one OpenTelemetry trace to Cloud Trace, open the waterfall, and click from a span to the matching log. Ask Gemini Cloud Assist to interpret the same incident from the log, the metric, and the trace, and write down that this assistant is not Gemini Code Assist. Redact one field that looks like a personal identifier before the sink.
Week 3. Organization near 20%, SRE near 18%. Create an organization folder for platform and a folder for applications. Place a host project and two service projects. Attach Shared VPC so both service projects use subnets in the host network. Create one Private Service Connect endpoint. Grant an IAM role at the folder and an organization policy at the organization, then write down what each child inherited. Create a service account for Cloud Build and bind it with the least role that can push to Artifact Registry. Store a customer-managed key and encrypt one secret with it. Apply an Infrastructure Manager Terraform configuration from a Git repository and preview a change before apply. Apply one Config Connector resource in a GKE cluster and write down that this is not Cloud Deploy. Start a Cloud Workstation and a Cloud Shell session and write down which one is the locked-down IDE. Define one SLI, one SLO, and one error budget on a Cloud Run service or a GKE Service. Autoscale that service. Then drain traffic, add capacity, and roll back once each so section 3.3 is not theoretical. Open a fleet view if you have more than one cluster.
Week 4. Cost near 12% and a full review. Open Active Assist recommendations on a project and classify one finding as cost, security, performance, manageability, or reliability. Create a Spot VM for a batch job and write down that it can be reclaimed. Open committed-use discounts and write down the 1 year and 3 year terms. Price a Cloud Logging sink that keeps debug logs for a year and then add an exclusion so the cost bullet in section 4.1 is visible. Compare a Cloud Run service that scales to zero with a GKE Deployment that keeps a minimum replica. Then sit with the exam guide and, for each bullet, name the product, the stage, and the constraint that would have forced that product.
Take any official sample questions the certification page still links and walk the exam tutorial at least once before using this outline against a clock. The sample set exists so the question format costs nothing on the timer. This guide does not reprint those items.
Traps that look like easy elimination
DevOps items rarely give one plausible answer and three absurd ones. They give two controls that both sound correct and one detail that picks between them.
- There is no prerequisite certification. Recommended experience is still 3 or more years, including 1 or more years designing and managing production systems on Google Cloud. Showing up with only vocabulary from Cloud Digital Leader is how sections 2 and 4 are lost.
- The standard sitting is 50 to 60 questions in 2 hours. Notes that quote a 40 to 50 question professional sitting are quoting a different exam.
- Google does not publish a numeric passing score on the certification page or the exam guide. A third-party 700 or 70 percent figure is not official language for this sitting.
- This sitting has no official case-study PDFs. A company name that does not appear on the exam guide is not part of the outline.
- Cloud Build compiles and tests. Cloud Deploy promotes. A trigger is not a promotion sequence.
- Artifact Registry stores the digest. Artifact Analysis scans it. Binary Authorization gates it. Those are three answers.
- Cloud Build features meet SLSA level 3. SLSA is a framework name on the outline, not a fourth Google product you deploy instead of Cloud Build.
- Secret Manager holds the password. Parameter Manager holds the feature flag. Cloud KMS holds the key you cannot export. Workload Identity Federation is how the pipeline avoids a downloaded key.
- Infrastructure Manager applies Terraform to Google Cloud resources. Config Connector applies Kubernetes resources that create Google Cloud resources. Cloud Deploy deploys the application onto GKE or Cloud Run. Those are three answers.
- A Cloud Workstation cluster is not a GKE cluster. Cloud Shell is not a locked-down IDE in your VPC.
- Gemini Code Assist is the coding assistant. Gemini Cloud Assist is the operations assistant that reads logs, metrics, and traces. Gemini CLI is the command-line assistant. The current exam guide does not name Gemini Enterprise Agent Platform on this sitting.
- An SLI is the measurement. An SLO is the target. An SLA is the contract. An error budget is whether change may continue.
- Cloud Service Mesh is the exam-guide name. Older Anthos Service Mesh notes still have to map to that name.
- Autoscale adds capacity. Rollback returns the last good release. Binary Authorization does not undo a digest that already serves traffic.
- Logs hold the event. Metrics hold the rate. Traces hold the waterfall. Synthetics hold the probe when no user is present.
- A BigQuery sink is for analysis. A Cloud Storage sink is for retention. A Pub/Sub sink is for another system. An exclusion is for cost.
- Google Cloud Managed Service for Prometheus is the PromQL path on this outline. A self-managed Prometheus VM is not the first answer when the stem never asked to operate Prometheus.
- Active Assist is the Recommender portfolio. The marketing URL that only prints a broken title is not a source. Use the Recommender overview.
- Spot VMs can be reclaimed. Committed-use discounts are a 1 year or 3 year commitment. Those are not the same cost control.
- Professional Cloud Architect case studies are not this exam. Professional Data Engineer warehouses are not this exam. Associate Cloud Engineer operator clicks are the floor, not the sitting.
If deleting the scenario still lets you pick the answer from the service name, the question is easier than the live exam.
How this maps to CloudFluently
Start with the official material. The Professional Cloud DevOps Engineer certification page carries the audience profile, the 2 hour timer, the 50 to 60 question format, the 200 USD fee, and the recommended experience. The Professional Cloud DevOps Engineer exam guide carries the five sections and the product names. Exam Terms and Conditions explain what it means to pass an Exam, how long a Professional Certification lasts, and the 14 day, 60 day, and 365 day retake waits.
Professional Cloud DevOps Engineer sits on top of Google Cloud vocabulary and Google Cloud operations, and that ground is already live here. Shared responsibility, product families, and the idea of a cloud bill are the Cloud Digital Leader study notes. Projects, IAM, Compute Engine, Cloud Storage, VPC networks, and the operator form of Cloud Monitoring and Cloud Logging are the Associate Cloud Engineer study notes. The Associate Cloud Engineer exam guide is the operator companion.
The architect reading of a pipeline, when the stem is still a solution recommendation rather than a promotion sequence, is the Professional Cloud Architect exam guide. The data-platform reading of a pipeline, when the stem is a warehouse or a stream rather than an application deploy, is the Professional Data Engineer exam guide.
Work those until the vocabulary, the operator controls, and the neighboring professional habits are automatic, then use this page and the official exam guide for the DevOps-only skills: the pipeline stage, the reliability control, and the telemetry signal that holds them.
Frequently Asked Questions
What is the passing score for Professional Cloud DevOps Engineer? Google does not publish a numeric passing score on the certification page or the exam guide. Exam Terms and Conditions say that if you pass an Exam, you receive a digital certificate after Google has validated your score.
How long is the exam and how many questions are there? The standard sitting is 2 hours with 50 to 60 multiple choice and multiple select questions.
Does this exam use case studies? The certification page and the official exam guide do not publish case studies for this sitting. Study the five sections and the named products.
Is there a prerequisite? No. Google recommends 3 or more years of industry experience, including 1 or more years designing and managing production systems using Google Cloud.
How long does the certification last? A Professional Certification is valid for two years from the date of issue. Renewal is the applicable Exam during the professional eligibility window, which the terms page starts 60 days before expiration. Passing that Exam extends validity for two years from the date of passing.
Can I retake it if I fail? Associate and Professional exams allow four attempts in two years. The waits are 14 days after the first fail, 60 days after the second, and 365 days after the third. Each attempt is paid.
What changed on the current outline? The current guide already names Gemini Code Assist, Gemini Cloud Assist, Gemini CLI, Parameter Manager, Cloud Service Mesh, Google Cloud Managed Service for Prometheus, Artifact Analysis, Binary Authorization, SLSA, Dynamic Workload Scheduler, Active Assist, and Cloud Workstations. The certifications hub points at Google Cloud Next '26 product updates. The product names that matter are the names on the current exam guide.
Which section is heaviest? Building and implementing CI/CD pipelines is about 25%. Implementing observability practices and troubleshooting issues is about 25%. Bootstrapping and maintaining a Google Cloud organization is about 20%. Applying site reliability engineering practices is about 18%. Optimizing performance and cost is about 12%.
Does Google publish a 700 or 70 percent pass mark? No. That figure is not on the certification page, the exam guide, or the terms page opened for this guide.
How does this exam relate to Associate Cloud Engineer, Professional Cloud Architect, and Professional Data Engineer? Cloud Digital Leader scores vocabulary. Associate Cloud Engineer scores the operator controls. Professional Cloud Architect scores the solution recommendation. Professional Data Engineer scores the data platform. Professional Cloud DevOps Engineer scores the pipeline stage, the reliability control, and the telemetry signal. The official outline is the Professional Cloud DevOps Engineer exam guide. Use Google for the task statements. Use this page for how those statements get picked, what the current names are, and how to sequence the blueprint.
