Cloud Digital Leader Practice Test.
63 free practice questions with answers and explanations.
No signup required. Choose a topic and review each answer.
Start practicing →About these practice questions
These are original study questions written from published exam objectives—not recalled, copied, or confidential live-exam items. Always confirm current coverage with the official sources linked on this page.
Exam format and study resources
The Cloud Digital Leader is administered by Google Cloud, with a 1 hour 30 minutes time limit.
This free Cloud Digital Leader practice test has 63 original questions written to Google Cloud's official content outline, last checked against it on July 18, 2026. Every question shows a worked explanation, and nothing here requires a signup.
As of 2026, the Cloud Digital Leader exam fee is $99.
Browse all questions & answers
1. A retail company wants to reduce the time between a business idea and a working prototype so it can test market fit faster. Which concept from Google Cloud's digital transformation framework best describes this goal?
- A. Increasing capital expenditure on owned data centers
- B. Reducing time to market for new products and services
- C. Migrating all workloads to a single availability zone
- D. Replacing all managed services with self-hosted alternatives
Show answer & explanation
Answer: B
Reducing time to market is one of the core business drivers Google Cloud describes for digital transformation, letting organizations iterate and launch faster using cloud-native tools. Increasing capex on owned data centers runs counter to cloud economics, a single zone reduces resilience rather than speeding delivery, and self-hosting managed services typically slows teams down rather than accelerating them.2. A finance leader is comparing cloud spending to traditional data center spending and wants to understand the shift in cost model. Which statement best describes this shift?
- A. Cloud computing shifts spend from capital expenditure (CapEx) toward operational expenditure (OpEx)
- B. Cloud computing eliminates all IT spending entirely
- C. Cloud computing requires larger upfront hardware purchases than on-premises
- D. Cloud computing converts OpEx spend into long-term fixed asset depreciation
Show answer & explanation
Answer: A
A widely cited business benefit of cloud adoption is moving from upfront capital expenditure on hardware to a pay-as-you-go operational expenditure model. Cloud does not eliminate IT spending, it typically reduces upfront hardware purchases rather than increasing them, and it moves away from fixed asset depreciation rather than toward it.3. A manufacturing company's CIO wants to identify measurable outcomes to track after migrating order-processing systems to the cloud. Which pairing best reflects an appropriate business outcome and its typical driver?
- A. Reduced operational costs, driven by paying only for resources consumed
- B. Increased operational costs, driven by eliminating all automation
- C. Reduced customer reach, driven by global points of presence
- D. Increased time to market, driven by managed infrastructure services
Show answer & explanation
Answer: A
Pay-as-you-go consumption is a key driver of reduced operational costs after cloud migration, since organizations avoid paying for idle capacity. The other options invert the expected relationships: automation reduces cost rather than eliminating it, global points of presence increase customer reach rather than reducing it, and managed services typically decrease time to market rather than increase it.4. A candidate is planning how to renew their Cloud Digital Leader certification before it lapses and wants to know how long the credential remains valid once earned. What is the validity period from the date of certifying?
- A. 3 years
- B. 1 year
- C. 5 years
- D. 10 years
Show answer & explanation
Answer: A
The Cloud Digital Leader certification is valid for 3 years from the date the individual certifies, after which renewal is required to maintain the credential. One year is shorter than the actual validity period, and five or ten years both overstate how long the certification remains valid before renewal is needed.5. A candidate is budgeting time to prepare for and schedule the standard Cloud Digital Leader exam. Approximately how many multiple-choice questions should they expect within the standard 90-minute session?
- A. 50 to 60 questions
- B. 5 to 10 questions
- C. 200 to 250 questions
- D. Exactly 1,000 questions
Show answer & explanation
Answer: A
The standard Cloud Digital Leader exam consists of 50 to 60 multiple choice questions delivered in 90 minutes, giving candidates roughly 1.5 minutes per question on average. Five to ten questions would be far too few for a meaningful certification assessment, while 200-250 or 1,000 questions would be far more than the exam actually contains and would not fit in the allotted time.6. A candidate is allocating study time proportionally across the exam's six domains and wants to prioritize the two sections given the highest weighting. Based on the exam guide's approximate domain weightings, which sections should receive the most study emphasis?
- A. Digital Transformation, Modernize Infrastructure and Applications, Trust and Security, and Scaling Operations, each approximately 17%
- B. Only the Data Transformation section, weighted at 90% of the exam
- C. Only the Artificial Intelligence section, weighted at 75% of the exam
- D. All six sections are weighted at exactly 50% each
Show answer & explanation
Answer: A
According to the exam guide, Digital Transformation, Modernize Infrastructure and Applications, Trust and Security, and Scaling with Google Cloud Operations are each approximately 17% of the exam, making them tied for the highest weighting alongside each other, while Data Transformation and AI are each approximately 16%. Claiming any single section is weighted at 90%, 75%, or that all six are weighted at exactly 50% each grossly misrepresents the documented proportional breakdown, since weightings across six sections must sum to roughly 100%.7. A logistics company stores raw GPS tracking data, semi-structured JSON event logs, and structured shipment records all in different formats. Which term describes this mix of data types collectively?
- A. Structured, semi-structured, and unstructured data
- B. Only relational data
- C. Only encrypted data
- D. Only archival data
Show answer & explanation
Answer: A
Structured data (like shipment records in tables), semi-structured data (like JSON logs), and unstructured data (like raw sensor streams) are the standard categories used to describe varied data types in data transformation discussions. The other options describe narrower or unrelated properties, not the general classification of data variety.8. A retailer wants a fully managed, petabyte-scale data warehouse to run SQL analytics across years of sales data without managing servers. Which type of Google Cloud service category fits this need?
- A. A serverless, managed analytics data warehouse
- B. A raw block storage volume attached to a single virtual machine
- C. An on-premises tape backup system
- D. A single-node relational database limited to gigabytes of data
Show answer & explanation
Answer: A
A serverless, managed data warehouse is designed specifically for large-scale SQL analytics without the customer managing infrastructure, matching the retailer's need. Block storage volumes are for VM disks rather than analytics queries, tape backups are for offline archival rather than active analysis, and a single-node database limited to gigabytes cannot support petabyte-scale analytics.9. An operations team wants to move data from multiple source systems, transform it into a consistent schema, and load it into a central analytics warehouse. Which term best describes this overall workflow?
- A. Object storage lifecycle management
- B. Extract, Transform, Load (ETL)
- C. Virtual private cloud peering
- D. Identity and access management provisioning
Show answer & explanation
Answer: B
ETL (Extract, Transform, Load) describes the standard workflow of pulling data from source systems, transforming it into a consistent format, and loading it into a destination like a data warehouse. Object storage lifecycle management concerns retention and tiering of stored objects, IAM provisioning concerns access permissions, and VPC peering concerns network connectivity, none of which describe a data pipeline workflow.10. A company's data team wants to reduce the risk of vendor lock-in while still taking advantage of managed cloud data services. Which practice most directly supports this goal?
- A. Favoring open formats and standard SQL interfaces where possible
- B. Storing all data exclusively in a single proprietary binary format with no export option
- C. Avoiding any use of managed services entirely
- D. Disabling all data governance controls to move faster
Show answer & explanation
Answer: A
Using open data formats and standard SQL interfaces makes it easier to migrate or integrate with other systems later, reducing lock-in risk while still benefiting from managed services. A proprietary format with no export option increases lock-in, avoiding managed services entirely sacrifices the productivity benefits of the cloud, and disabling governance introduces risk rather than reducing dependency on a vendor.11. A grocery chain wants to forecast weekly demand for perishable goods at each store using historical sales, weather, and promotional data. Which category of solution is most appropriate?
- A. A machine learning model trained to predict demand from historical patterns
- B. A static spreadsheet formula that never updates with new data
- C. A firewall rule limiting network traffic to the point-of-sale system
- D. A DNS-based traffic routing policy
Show answer & explanation
Answer: A
Machine learning models are well suited to forecasting problems like demand prediction because they can learn patterns from historical sales, weather, and promotional data and generalize to new situations. A static spreadsheet formula cannot adapt to new data patterns, and firewall rules or DNS routing policies address networking concerns unrelated to demand forecasting.12. A customer support team wants to automatically categorize incoming support tickets by topic and route them to the right specialist team without writing custom rules for every possible phrase. Which approach best fits this need?
- A. A pre-trained natural language processing model for text classification
- B. A manually maintained list of exact keyword matches updated by hand every day
- C. A physical server rack dedicated to ticket storage
- D. A VPN tunnel between offices
Show answer & explanation
Answer: A
Natural language processing models for text classification can learn to categorize varied phrasing of support tickets without requiring an exhaustive manually maintained keyword list, making them well suited to this use case. A manually maintained exact-match list does not scale to natural language variation, and a server rack or VPN tunnel address infrastructure and connectivity, not text classification.13. An executive asks the difference between artificial intelligence and machine learning when evaluating vendor proposals. Which statement most accurately describes the relationship?
- A. Machine learning is a subset of artificial intelligence focused on learning patterns from data
- B. Artificial intelligence is a subset of machine learning
- C. The two terms are unrelated and never used together
- D. Machine learning refers only to robotics hardware
Show answer & explanation
Answer: A
Machine learning is a subset of the broader field of artificial intelligence, specifically the branch concerned with algorithms that learn patterns from data rather than following only explicitly programmed rules. AI is the broader field, not a subset of ML, the two terms are closely related rather than unrelated, and machine learning is a software and data discipline, not limited to robotics hardware.14. A company wants to add a conversational chatbot to its website that can answer customer questions in natural language and hand off to a human agent when needed. Which Google Cloud AI concept is most directly relevant?
- A. Conversational AI, which combines natural language understanding with dialogue management
- B. Object storage lifecycle policies
- C. Load balancer health checks
- D. Virtual private network routing tables
Show answer & explanation
Answer: A
Conversational AI combines natural language understanding and dialogue management to interpret customer questions and manage a multi-turn conversation, including escalation to a human, which matches the described chatbot use case. Object storage lifecycle policies concern data retention, load balancer health checks concern traffic routing to healthy backends, and VPN routing tables concern network paths, none of which relate to building a chatbot.15. A data science team is deciding whether to build a custom machine learning model from scratch or use a pre-built AI API for a common task like sentiment analysis on customer reviews. What is the main tradeoff they should weigh?
- A. Pre-built APIs offer faster time to value with less customization, while custom models offer more control but require more time and expertise
- B. Pre-built APIs always require more training data than custom models
- C. Custom models are always cheaper and faster to deploy than pre-built APIs
- D. There is no meaningful difference between the two approaches
Show answer & explanation
Answer: A
The realistic tradeoff is that pre-built AI APIs get teams to a working solution quickly for common tasks but offer less customization, whereas building a custom model offers more control at the cost of additional time, data, and expertise. Pre-built APIs typically require less training data from the customer, not more, custom models are generally slower and more resource-intensive to build than using an API, and there is a meaningful, well-documented tradeoff between the two approaches.16. An organization deploying an AI model for loan approval decisions is concerned about the model producing biased outcomes against certain demographic groups. Which responsible AI practice most directly addresses this concern?
- A. Using the model only on weekends to reduce exposure
- B. Evaluating the model for fairness and testing for disparate impact across groups before deployment
- C. Deploying the model immediately without any evaluation to save time
- D. Removing all documentation about how the model makes decisions
Show answer & explanation
Answer: B
Evaluating a model for fairness and testing for disparate impact across demographic groups is a core responsible AI practice meant to catch and mitigate biased outcomes before deployment. Deploying without evaluation increases risk rather than reducing it, removing documentation undermines transparency and accountability, and limiting usage to certain days does not address the underlying bias in the model's decisions.17. A startup expects highly variable and unpredictable traffic to its new web application and does not want to manage or provision servers directly. Which compute approach best fits this requirement?
- A. A serverless compute platform that scales automatically with incoming requests
- B. A single fixed-size on-premises server purchased for peak capacity
- C. A tape backup system
- D. A manually racked server that must be resized by hand each month
Show answer & explanation
Answer: A
Serverless compute platforms automatically scale with incoming request volume and remove the need to provision or manage servers, matching the startup's unpredictable traffic and preference to avoid server management. A fixed-size on-premises server requires sizing for peak load in advance and wastes resources during quiet periods, tape backup systems are for data archival, and manually resized servers reintroduce the operational burden the startup wants to avoid.18. An enterprise is migrating an existing application to the cloud with minimal code changes, primarily moving virtual machines as-is to reduce migration time. Which migration strategy does this describe?
- A. Building an entirely new application in a different business domain
- B. Decommissioning the application entirely
- C. Lift and shift (rehosting)
- D. Full application rewrite (re-architecting) using cloud-native serverless functions
Show answer & explanation
Answer: C
Lift and shift, also called rehosting, describes moving existing workloads such as virtual machines to the cloud with minimal changes, which matches the described low-effort, fast migration approach. Re-architecting to serverless functions involves substantial code changes, decommissioning means retiring the application rather than migrating it, and building a new application in a different domain is unrelated to migrating an existing workload.19. A development team wants to package an application with all its dependencies so it runs consistently across a developer's laptop, a test environment, and production. Which technology best supports this goal?
- A. Containers
- B. Physical bare-metal servers only
- C. Paper-based deployment checklists
- D. Manually copying files over FTP each time
Show answer & explanation
Answer: A
Containers package an application with its dependencies into a portable unit that runs consistently across different environments, directly addressing the consistency goal described. Bare-metal servers alone do not solve environment consistency, and paper checklists or manual FTP transfers are error-prone manual processes rather than a technology solution for portability.20. A company wants to build new business logic as small, independently deployable functions that run only in response to specific events, such as a file upload, without managing any servers. Which compute model fits this scenario?
- A. Event-driven serverless functions
- B. A monolithic application deployed on a single dedicated physical server
- C. A mainframe batch job scheduled to run once a year
- D. A manually maintained cron job on a personal laptop
Show answer & explanation
Answer: A
Event-driven serverless functions are designed to execute small units of logic in response to specific triggers, like a file upload, without the developer managing underlying servers, matching the scenario exactly. A monolithic application on a dedicated server does not match the small, independent, event-driven nature described, an annual batch job does not respond to real-time events, and a personal laptop cron job is not a reliable or scalable production solution.21. A company is deciding between a monolithic application architecture and a microservices architecture for a new product. Which factor most strongly favors microservices?
- A. The need to independently deploy, scale, and update different parts of the application
- B. A requirement that the entire application must be deployed as one single unit forever
- C. A preference for the simplest possible architecture with no service boundaries
- D. A requirement to avoid using APIs between components
Show answer & explanation
Answer: A
Microservices architectures are favored when teams need to independently deploy, scale, and update separate components, since each service can evolve on its own release cycle. Requiring the whole application to deploy as a single unit, preferring no service boundaries, or avoiding APIs between components all describe characteristics of a monolithic approach rather than reasons to choose microservices.22. A company wants to adopt a hybrid cloud strategy that runs some workloads on-premises and others in the cloud, using a consistent set of tools and APIs across both. What is the primary benefit of this consistency?
- A. It reduces operational complexity and retraining by letting teams manage workloads similarly regardless of location
- B. It guarantees zero network latency between on-premises and cloud environments
- C. It eliminates the need for any identity and access management
- D. It requires completely different tools for each environment, increasing complexity
Show answer & explanation
Answer: A
A consistent tool and API layer across on-premises and cloud environments in a hybrid strategy reduces operational complexity and the retraining burden on teams, since workflows stay similar regardless of where a workload runs. Consistency does not eliminate network latency, which is a physical reality, does not remove the need for identity and access management, and the entire point of consistency is to avoid requiring completely different tools per environment.23. Under the shared responsibility model commonly described for public cloud providers, which task is typically the customer's responsibility rather than the provider's?
- A. Maintaining the physical security of the data center building
- B. Patching the physical hardware powering the underlying infrastructure
- C. Configuring identity and access management permissions for their own applications and data
- D. Ensuring the global network backbone between data centers is operational
Show answer & explanation
Answer: C
In the shared responsibility model, the customer is responsible for configuring identity and access management and securing their own data and application-level access, while the provider secures the underlying infrastructure. Physical data center security, hardware patching, and the global network backbone are the provider's responsibility, not the customer's, under this model.24. A company wants to enforce the principle that employees should only have the minimum access necessary to perform their job duties. Which security concept describes this practice?
- A. The principle of least privilege
- B. Full administrative access for all employees by default
- C. Disabling all access controls to simplify onboarding
- D. Sharing a single shared account across the whole department
Show answer & explanation
Answer: A
The principle of least privilege states that users should be granted only the access necessary to perform their specific job functions, minimizing risk if credentials are compromised. Granting full administrative access to everyone, disabling access controls, or sharing one account across a department all increase risk and directly contradict least privilege.25. A security team wants to require a second verification step, such as a one-time code, in addition to a password before allowing access to sensitive cloud resources. Which control are they implementing?
- A. Multi-factor authentication (MFA)
- B. Data encryption at rest
- C. Network firewall rules
- D. Data retention policies
Show answer & explanation
Answer: A
Multi-factor authentication requires a second verification factor beyond a password, such as a one-time code, adding an additional layer of identity assurance before granting access. Encryption at rest protects stored data from unauthorized reading, firewall rules control network traffic flow, and retention policies govern how long data is kept, none of which describe requiring a second authentication factor.26. A company operating in the European Union must ensure its data handling practices comply with regulations governing personal data privacy and protection. Which broad category of requirement is this?
- A. Regulatory compliance requirements
- B. Hardware procurement requirements
- C. Marketing brand guidelines
- D. Internal office seating arrangements
Show answer & explanation
Answer: A
Laws governing personal data privacy and protection, such as regional data protection regulations, fall under regulatory compliance requirements that organizations must satisfy when handling personal data. Hardware procurement, marketing brand guidelines, and office seating arrangements are unrelated organizational concerns that do not address legal obligations around data privacy.27. A security architect wants to segment a cloud network so that a compromised web server in one segment cannot directly reach a sensitive database in another segment without passing through controlled checkpoints. Which concept describes this design goal?
- A. Network segmentation to limit lateral movement between resources
- B. Placing all resources on one flat network with no boundaries
- C. Granting every service account project owner permissions
- D. Disabling encryption in transit between internal services
Show answer & explanation
Answer: A
Network segmentation isolates resources into separate logical zones so that a breach in one segment does not automatically grant access to others, directly supporting the architect's goal of limiting lateral movement. A single flat network increases the ability for an attacker to move laterally, granting broad owner permissions to every service account increases blast radius, and disabling encryption in transit weakens security rather than containing a breach.28. An organization wants visibility into who accessed which cloud resources and when, in order to investigate a suspected security incident after the fact. Which capability is most essential for this?
- A. Audit logging that records access and administrative activity
- B. A load balancer configured with round-robin routing
- C. A content delivery network cache policy
- D. A DNS record time-to-live setting
Show answer & explanation
Answer: A
Audit logging records who accessed which resources and when, along with administrative actions, which is exactly what is needed to investigate a security incident after it occurred. Load balancer routing algorithms, CDN cache policies, and DNS TTL settings are operational and performance configurations that do not provide the access history needed for incident investigation.29. A company wants to track spending across dozens of cloud projects and get alerted before costs exceed a planned monthly amount. Which practice addresses this need?
- A. Setting up budgets and alerts tied to billing accounts or projects
- B. Disabling all billing exports and reports
- C. Deleting the billing account entirely
- D. Ignoring cost until the end of the fiscal year
Show answer & explanation
Answer: A
Setting budgets with threshold-based alerts tied to billing accounts or projects lets an organization proactively track spending and get notified before costs exceed planned amounts. Disabling billing exports removes visibility rather than adding it, deleting the billing account would stop cloud usage entirely, and waiting until year-end to review costs defeats the purpose of proactive cost management.30. An operations team wants a single view showing the CPU utilization, error rates, and request latency for an application running across many services in the cloud. Which category of tool best supports this need?
- A. Cloud monitoring and observability dashboards
- B. A physical whiteboard updated manually once a week
- C. A spreadsheet emailed once a month with no automation
- D. A static webpage with no live data connections
Show answer & explanation
Answer: A
Cloud monitoring and observability tools are designed to aggregate metrics like CPU utilization, error rates, and latency from many services into unified, near-real-time dashboards. A manually updated whiteboard, a monthly emailed spreadsheet, and a static webpage all lack the automation and real-time data needed to observe a distributed application's health.31. A company running a customer-facing application defines a target that 99.9% of requests should succeed each month, and tracks how much allowed failure remains against that target. What is this remaining allowance commonly called?
- A. Error budget
- B. Marketing budget
- C. Capital expenditure budget
- D. Headcount budget
Show answer & explanation
Answer: A
An error budget represents the amount of acceptable unreliability remaining against a service level objective, such as 99.9% success, and is a core site reliability engineering concept for balancing reliability with the pace of change. A marketing budget concerns advertising spend, a capital expenditure budget concerns asset purchases, and a headcount budget concerns staffing costs, none of which relate to tracking allowed service failures.32. An operations team notices that a specific microservice frequently runs out of memory under moderate load, causing outages. Following incident response best practices, what should the team do immediately after resolving the outage?
- A. Conduct a blameless postmortem to identify root cause and prevent recurrence
- B. Immediately delete all logs related to the incident
- C. Assign personal blame to the on-call engineer and end the discussion
- D. Take no further action since the immediate outage is resolved
Show answer & explanation
Answer: A
A blameless postmortem after an incident focuses on identifying root cause and systemic fixes, which is a core site reliability practice for preventing recurrence rather than just resolving the immediate symptom. Deleting logs destroys evidence needed for root cause analysis, assigning personal blame discourages open reporting of future issues, and taking no further action leaves the underlying memory issue unaddressed and likely to recur.33. An organization describes digital transformation as its goal. What distinguishes it from simply adopting new technology?
- A. It means replacing all existing systems with newer versions
- B. It changes how the business operates and delivers value, with technology as the enabler rather than the objective
- C. It is complete once the migration finishes
- D. It refers exclusively to migrating servers to a cloud provider
Show answer & explanation
Answer: B
Transformation is measured in business outcomes such as faster delivery, new revenue models or better customer experience rather than in systems replaced. Programmes that treat migration as the destination commonly reproduce existing processes on new infrastructure and capture little of the value that justified the investment.34. A company weighs the risk of not modernizing. What is the principal argument for acting?
- A. Competitors able to iterate and respond faster erode market position, so the cost of inaction accumulates rather than staying constant
- B. Existing systems will stop functioning on a known date
- C. Regulators mandate cloud adoption in most industries
- D. Legacy systems cannot be secured at all
Show answer & explanation
Answer: A
The competitive argument rests on the rate of change rather than on any single deadline, since an organization that ships quarterly loses ground steadily to one shipping weekly. Legacy systems can be secured and maintained, so the honest case is about speed and capability rather than imminent failure.35. An organization must decide between modernizing an application and simply migrating it as it is. What favours migrating first?
- A. It captures the full benefit of managed services immediately
- B. It is always cheaper to operate afterward
- C. It removes the need to modernize later
- D. Speed and reduced risk when a data centre exit has a deadline, accepting that modernization follows as a second phase
Show answer & explanation
Answer: D
Migrating unchanged is fastest and least risky, which matters when a lease expires or hardware is failing, and it buys time to modernize deliberately afterward. It does not capture managed service benefits and often costs more to run than the equivalent on-premises deployment until the workload is right-sized.36. A workload is refactored into containers running on a managed orchestration platform. What benefit is most directly gained?
- A. Consistent packaging and portability with automated scaling and self-healing, at the cost of the operational knowledge orchestration requires
- B. Elimination of the need to monitor the application
- C. A guarantee that the application cannot fail
- D. Automatic rewriting of the application's code
Show answer & explanation
Answer: A
Containers standardize how software is packaged and run, and orchestration adds scheduling, scaling and replacement of failed instances. The trade is a platform that must itself be understood and operated, which is why fully managed and serverless options exist for teams whose requirements do not need that control.37. A team chooses a serverless compute option for a new service. What characterizes this model?
- A. No servers to provision or manage, scaling to demand including to zero, with billing tied to actual usage
- B. Dedicated servers reserved for the workload
- C. Manual capacity planning based on forecast demand
- D. A fixed monthly cost independent of usage
Show answer & explanation
Answer: A
Serverless removes capacity management and matches cost to usage, which suits variable or unpredictable workloads. The trade-offs are cold start latency after idle periods and constraints such as execution duration limits, which make the model unsuitable for some long-running or latency-critical work.38. An organization operates workloads across its own data centre and a cloud provider and wants consistent management. What approach addresses this?
- A. A hybrid and multi-cloud management layer providing consistent tooling, policy and observability across environments
- B. Managing each environment with its own separate tooling and policies
- C. Migrating everything immediately to remove the hybrid state
- D. Accepting that consistent policy is not achievable across environments
Show answer & explanation
Answer: A
Divergent tooling per environment multiplies operational effort and creates policy gaps at the seams, which is where incidents concentrate. A consistent management layer is what makes a long-lived hybrid estate manageable, since many organizations retain on-premises workloads indefinitely for regulatory or latency reasons.39. A business wants to analyse very large datasets without managing infrastructure. What characterizes a serverless data warehouse for this purpose?
- A. Storage and query compute scale independently with no cluster to size, and cost relates to data stored and queried rather than to provisioned capacity
- B. A fixed cluster must be sized in advance for peak query load
- C. Data must be moved to a local machine to be analysed
- D. Only structured data of a fixed schema can ever be queried
Show answer & explanation
Answer: A
Separating storage from compute removes cluster sizing and lets an occasional large query run without maintaining capacity for it year-round. Because cost follows data scanned, query design such as partitioning, clustering and selecting only needed columns has a direct and often substantial financial effect.40. An organization distinguishes a data warehouse from a data lake. What is the difference?
- A. A warehouse holds structured data modelled for analysis while a lake holds raw data of any structure, with schema applied when it is read
- B. A lake holds only structured data and a warehouse holds raw files
- C. The two are alternative names for the same system
- D. A warehouse cannot be queried with SQL
Show answer & explanation
Answer: A
The warehouse applies structure on write, producing a curated model that analysts can rely on, while the lake defers structure to read time, preserving raw fidelity and flexibility. Most organizations run both, with the lake receiving raw ingestion and curated data flowing into the warehouse, and governance over the lake is what prevents it becoming unusable.41. A business must process events as they arrive rather than in nightly batches. What does this require?
- A. A streaming ingestion and processing pipeline, since batch processing introduces latency equal to its interval
- B. A larger batch window to accommodate the volume
- C. Moving the batch job to run twice daily
- D. Storing the events in a spreadsheet for manual review
Show answer & explanation
Answer: A
Batch latency is bounded below by the interval, so a use case requiring seconds cannot be served by shortening a nightly job. Streaming introduces its own complexity around late-arriving and out-of-order events, which is why the requirement should genuinely need low latency before accepting that cost.42. A data governance programme is established alongside a data platform. What does it address?
- A. Ownership, classification, quality, access and retention of data, so it can be trusted and used lawfully
- B. The physical arrangement of servers in the data centre
- C. The programming language used by the analytics team
- D. The vendor selected for the data platform
Show answer & explanation
Answer: A
Without ownership and quality standards a platform accumulates datasets nobody can vouch for, which is how organizations end up with several conflicting versions of the same metric. Lineage and cataloguing make it possible to answer where a number came from, which is what turns available data into trusted data.43. A retailer wants to predict which customers are likely to stop purchasing. Which analytics category is this?
- A. Predictive analytics, which estimates future outcomes from historical patterns
- B. Descriptive analytics, which reports what has already happened
- C. Diagnostic analytics, which explains why something happened
- D. Prescriptive analytics, which recommends an action to take
Show answer & explanation
Answer: A
The four categories form a progression from reporting the past through explaining it to forecasting and then recommending action, with value and difficulty rising together. Predicting churn is forecasting, while deciding what offer to make to a predicted churner is prescriptive and requires modelling the effect of the intervention as well.44. A company considers building a custom machine learning model rather than using a pre-trained API. What favours the pre-trained API?
- A. The task is a common capability such as speech transcription or image labelling, so no training data or specialist expertise is required
- B. The task depends on patterns unique to the company's own data
- C. The company has a large labelled dataset and data science staff
- D. Complete control over the model architecture is required
Show answer & explanation
Answer: A
Pre-trained APIs deliver common capabilities immediately without data or expertise, which suits anything a general model already does well. Custom models earn their cost where the pattern is specific to the organization, such as predicting demand for its own products, which no general service can know.45. A generative AI assistant is deployed for internal knowledge search. What is the principal quality risk to manage?
- A. Confident but unsupported answers, mitigated by grounding responses in retrieved documents and displaying citations
- B. The model refusing to respond to any question
- C. The model requiring users to write code
- D. The model producing responses too quickly to read
Show answer & explanation
Answer: A
Fluency and accuracy are separate properties, so an assistant can produce a well-written answer with no basis in any source document. Grounding in retrieved content with visible citations lets a reader verify a claim, which converts an unverifiable assertion into a checkable one.46. An organization adopts AI and must address responsible use. What does this require in practice?
- A. Assessing fairness, transparency, privacy and accountability for each use case, proportionate to the consequences of the system being wrong
- B. A single organization-wide policy applied identically to every use case
- C. Avoiding AI entirely in customer-facing processes
- D. Relying on the provider's model safeguards as sufficient
Show answer & explanation
Answer: A
Risk-proportionate assessment scales the rigour of evaluation and oversight to what failure would cost, so a marketing copy assistant and a credit decision system are not treated identically. Provider safeguards are a general baseline that cannot encode an organization's specific policy or the consequences within its context.47. A team asks whether their data is used to train the provider's models when they call a managed AI service. What determines the answer?
- A. The contractual terms of the specific service and tier, which must be verified rather than assumed
- B. The programming language used to call the service
- C. The size of the data sent in each request
- D. Whether the data is sent over an encrypted connection
Show answer & explanation
Answer: A
Training use, retention period and processing location are contractual commitments that differ between services and tiers, and enterprise offerings commonly provide stronger assurances than consumer products. Verifying the terms for the specific service in use is a governance prerequisite rather than a detail, since the answer determines whether the data may lawfully be sent at all.48. A shared responsibility model applies to cloud security. Which responsibility never transfers to the provider?
- A. Managing who has access to the organization's data and how that data is classified and used
- B. Physical security of the data centre facilities
- C. Maintenance of the underlying hardware
- D. Patching of the provider's hypervisor
Show answer & explanation
Answer: A
Identity and data responsibilities remain with the customer in every service model, which is why the most common cloud security incidents involve misconfigured access rather than provider infrastructure failures. The boundary for operating systems and runtimes moves with the service model, but data and access do not.49. An organization must satisfy a regulator that data stays within a specific country. What determines whether this holds?
- A. The nationality of the staff operating the system
- B. The location of the organization's headquarters
- C. The currency in which the invoice is denominated
- D. The region selected for each service and whether any service in the architecture operates globally or replicates outside the boundary
Show answer & explanation
Answer: D
Residency follows the regions chosen per service, and services differ in whether they are regional or global, so one globally replicated component can breach a boundary every other component respects. Verifying the behaviour of each service in the architecture, including logging and backup destinations, is what makes a residency claim defensible.50. A defence-in-depth approach is applied to a cloud environment. What does it mean in practice?
- A. Multiple independent controls across identity, network, workload and data layers, so no single failure results in compromise
- B. A single strong perimeter firewall protecting everything behind it
- C. Encrypting data and applying no other controls
- D. Restricting access to a single administrator
Show answer & explanation
Answer: A
Layering assumes each control will eventually fail, so protection depends on an attacker defeating several independent mechanisms. The layers must be genuinely independent, since controls sharing a common dependency such as a single identity provider fail together despite appearing layered.51. An organization applies the principle of least privilege to cloud access. What does this require ongoing effort to maintain?
- A. Periodic review, since permissions accumulate as people change roles and temporary grants become permanent
- B. Granting every user identical permissions for consistency
- C. Increasing permissions as staff gain seniority
- D. Nothing, since permissions granted correctly at the outset remain correct
Show answer & explanation
Answer: A
Privilege creep is the predictable outcome of role changes and temporary access that is never revoked, so least privilege is a state to be maintained rather than achieved once. Time-bound elevation for administrative access reduces the standing privilege that accumulation otherwise produces.52. Cloud costs rise faster than expected after migration. What is the most common structural cause?
- A. Resources provisioned for peak and never right-sized, alongside forgotten resources nobody owns, since cost is now continuous rather than a one-time purchase
- B. The provider changing prices without notice
- C. Insufficient bandwidth to the provider
- D. Cloud pricing being inherently higher than on-premises for every workload
Show answer & explanation
Answer: A
In a capital purchase model an oversized server is a sunk cost, whereas in the cloud it bills every hour, so habits carried over from on-premises sizing produce continuing expense. Ownership through tagging, right-sizing recommendations and identifying idle resources are what convert visibility into savings.53. A finance team adopts a cloud financial management practice. What does it establish?
- A. Shared accountability between finance, technology and business teams for cloud spending, with visibility, attribution and optimization as ongoing activities
- B. A single annual budget approval with no further involvement
- C. Transfer of all cost decisions to the finance department
- D. A prohibition on any resource creation without finance approval
Show answer & explanation
Answer: A
Cloud spending is created continuously by engineering decisions, so annual budgeting alone cannot control it and centralizing approval destroys the speed that justified cloud adoption. Shared accountability with attribution means teams see the cost of their own choices, which is what makes optimization happen where the decisions are made.54. Site reliability practice defines a service level objective. What does it enable?
- A. An agreed reliability target that makes the trade-off between shipping features and improving reliability explicit rather than argued case by case
- B. A guarantee that the service never fails
- C. A contractual penalty owed to customers
- D. A requirement that all changes be manually approved
Show answer & explanation
Answer: A
An objective sets the reliability the business actually needs, and the error budget it implies is what turns reliability into a quantity that can be spent on change. Exhausting the budget provides an agreed trigger for slowing releases, which replaces the recurring argument between delivery and operations with a rule both accepted in advance.55. An organization measures operations with mean time to recovery rather than only mean time between failures. What does this reflect?
- A. That recovery time is easier to measure than failure frequency
- B. That in complex systems failures are inevitable, so how quickly service is restored matters as much as how rarely it breaks
- C. That failure frequency is irrelevant to users
- D. That failures can be eliminated entirely with sufficient investment
Show answer & explanation
Answer: B
Optimizing only for rarity produces systems that fail infrequently but catastrophically because recovery was never practised. Measuring and improving recovery time drives investment in observability, runbooks and rollback capability, which reduces the impact of the failures that will occur regardless.56. A blameless post-incident review is held. What is the reasoning behind the blameless framing?
- A. People withhold information when they expect blame, so the framing exists to surface the systemic causes that would otherwise stay hidden
- B. Individual actions never contribute to incidents
- C. Accountability is unnecessary in operations
- D. Incidents should not be documented
Show answer & explanation
Answer: A
Blameless does not mean consequence-free but recognizes that a system permitting a single mistake to cause an outage is the more useful thing to fix. Where blame is expected, the detail needed to find the systemic cause is exactly what people stop volunteering, so the framing is a practical measure rather than a cultural nicety.57. An organization moves from quarterly releases to continuous delivery. What change makes this safe?
- A. Reducing the number of people permitted to deploy
- B. Automated testing and deployment with the ability to roll back quickly, so smaller changes carry less risk each and failures are cheaper to reverse
- C. Batching more changes into each release
- D. Longer manual testing cycles before each release
Show answer & explanation
Answer: B
Smaller and more frequent changes are individually less risky and far easier to diagnose when something breaks, which is the counterintuitive finding underpinning continuous delivery. Large batched releases concentrate risk and make attributing a failure to one of many simultaneous changes considerably harder.58. A cloud adoption programme stalls despite the technology working. What is the most common non-technical cause?
- A. Insufficient attention to skills, operating model and change management, since new capability requires people and processes to change with it
- B. Insufficient network bandwidth to the provider
- C. The provider's regional coverage
- D. The number of services available in the catalogue
Show answer & explanation
Answer: A
Transformation programmes fail on people and process far more often than on technology, since teams asked to work differently without training, incentives or changed governance revert to familiar practice. Executive sponsorship, a defined operating model and investment in skills are what convert available capability into realized change.59. A cloud centre of excellence is established. What is its purpose?
- A. Providing shared standards, reusable patterns and guidance so teams adopt cloud consistently without each solving the same problems independently
- B. Centralizing all cloud work so individual teams do not need cloud skills
- C. Approving every resource request before it is created
- D. Replacing the organization's existing operations function entirely
Show answer & explanation
Answer: A
The function is an enabling one, producing landing zones, reference architectures and policy that teams consume, rather than a gate every request must pass. A centre that becomes an approval bottleneck reproduces the delay that cloud adoption was meant to remove.60. An organization must choose which applications to migrate first. What selection approach is generally sound?
- A. Starting with applications that are lower risk and demonstrate value, building capability and confidence before tackling the most critical or complex ones
- B. Selecting applications at random to avoid bias
- C. Migrating everything simultaneously to complete the programme quickly
- D. Starting with the most business-critical application to prove the platform
Show answer & explanation
Answer: A
Early migrations build organizational capability, so sequencing them from lower risk upward means the hardest workloads are attempted by a team that has already learned. Beginning with the most critical application maximizes the consequence of the mistakes an inexperienced team is most likely to make.61. A business case for cloud migration is prepared. What should the comparison include beyond server costs?
- A. Facilities, power, hardware refresh cycles, staff time and the cost of capacity held for peak, since a like-for-like resource comparison understates the on-premises baseline
- B. Only the monthly compute charge against the server purchase price
- C. Only the migration project's one-time cost
- D. Only the provider's published list prices
Show answer & explanation
Answer: A
Total cost of ownership includes the facilities, power, refresh cycles and staff effort that never appear on a server invoice, along with capacity provisioned for peaks that sits idle most of the year. Omitting them produces a comparison that makes on-premises look cheaper than it is, which is why the analysis is done on a total basis rather than resource by resource.62. An organization uses APIs to expose internal capabilities to partners. What business benefit does this enable?
- A. New channels and partnerships without bespoke integration per partner, turning internal capability into a reusable product
- B. Elimination of the need to secure the underlying systems
- C. A guarantee that partners will adopt the integration
- D. Removal of any need for versioning or documentation
Show answer & explanation
Answer: A
A managed API turns a capability into something many partners can consume on the same terms, replacing bespoke point-to-point integrations that each require separate build and maintenance. Governance including versioning, documentation, rate limiting and access control is what makes the API a product rather than an exposed internal interface.63. A company adopts a multi-cloud strategy. What is the realistic trade-off?
- A. Reduced dependence on a single provider and access to differentiated services, against increased operational complexity, duplicated tooling and split expertise
- B. Lower cost in every case through provider competition
- C. Simpler operations through standardization
- D. Complete portability of workloads without any additional effort
Show answer & explanation
Answer: A
Multi-cloud reduces concentration risk and lets a team use the best service for a purpose, but each provider brings its own identity model, networking, tooling and skills requirement. Portability across providers is achievable but has a cost, often by restricting use to the lowest common denominator of services, which forfeits some of the benefit that motivated the choice.
More in this family
Explore more Technology & IT Certifications
In the same family
More in this category
- Certified Information Systems AuditorPractice questions →
- Certified Information Security ManagerPractice questions →
- ISC2 Certified in Cybersecurity (CC)Practice questions →
- Project Management Professional (PMP)Practice questions →
- Microsoft Certified: Power BI Data Analyst Associate (Exam PL-300)Practice questions →
- Salesforce Certified Platform AdministratorPractice questions →
- HashiCorp Certified: Terraform Associate (004)Practice questions →
- AWS Certified AI PractitionerPractice questions →
- AWS Certified Cloud PractitionerPractice questions →
- AWS Certified Developer - AssociatePractice questions →
- AWS Certified Solutions Architect – AssociatePractice questions →
2026 statistics
Key facts: Cloud Digital Leader exam
Every free resource for this exam
Get a free Cloud Digital Leader study plan
A week-by-week plan plus new practice questions, straight to your inbox.
Official sources
Primary documents used to verify the exam details shown on this page.
- Cloud Digital Leader Certification Exam GuideGoogle Cloudservices.google.com
- Cloud Digital Leader Certification — Exam OverviewGoogle Cloudcloud.google.com
- Cloud Certification Help — Certification RenewalGoogle Cloudsupport.google.com
- Cloud Certification Help CenterGoogle Cloudsupport.google.com
- Google Cloud Certification Exam Portal (Webassessor)Kryterion Webassessorwebassessor.com
Last verified against the official exam content outline:
Frequently asked questions
How many questions are on the Cloud Digital Leader exam, and how long do I get?
The standard Cloud Digital Leader exam consists of 50–60 multiple choice questions delivered in 90 minutes. That works out to roughly 90 to 108 seconds per question on average, so pacing yourself is manageable — but you shouldn't dwell too long on any single question. Because it's a foundational-level certification, the questions focus on your conceptual understanding of Google Cloud rather than hands-on technical configuration.
How much does the exam cost, and how do I register for it?
The standard exam costs $99 (plus tax where applicable). You register and schedule through the Webassessor portal operated by Kryterion, Inc. — create an account there and choose either an online-proctored appointment or an onsite test-center appointment. Whichever option you pick, you must comply with the testing requirements for proctored exams. Plan ahead and budget for the $99 fee plus any local tax when you book your slot.
What topics does the exam cover, and how is it weighted?
The exam guide outlines six content sections. Five of them carry roughly equal weight at about 17% each: Digital Transformation with Google Cloud (~17%), Modernize Infrastructure and Applications with Google Cloud (~17%), Trust and Security with Google Cloud (~17%), and Scaling with Google Cloud Operations (~17%). The two data- and AI-focused sections are slightly lighter: Exploring Data Transformation with Google Cloud (~16%) and Innovating with Google Cloud Artificial Intelligence (~16%). Since no single section dominates, it's worth studying all six areas fairly evenly rather than betting everything on one topic.
How long is the certification valid, and how do I renew it?
The Cloud Digital Leader certification is valid for 3 years from the date you certify — consistent with Google Cloud's policy that Foundational and Associate exams are valid for three years. To renew, you retake the standard certification exam, since foundational-level certifications are renewed that way. You can begin the renewal process up to 180 days before your certification's expiration date, so it's smart to mark your calendar roughly six months ahead to give yourself time to prepare and re-sit before your credential lapses.