PCNE logo
Focused certification exam prep
Start practice

PCNE Exam Domains 2026: Complete Guide to All 6 Content Areas

TL;DR
  • The PCNE exam guide (file 042426) defines six domains weighted from 13% to 21% of the exam.
  • Domain 1 (network design) and Domain 2 (implementation) together make up roughly 41% of all questions.
  • The exam has 50-60 questions in 2 hours, delivered via Pearson VUE or OnVUE remote proctoring.
  • Hybrid/multicloud connectivity and managed services each carry 16% weight - don't skip them for VPC topics.

Domain Overview: How the Six Areas Fit Together

The Professional Cloud Network Engineer exam guide, identified by Google as file 042426, organizes the certification into six domains. Each domain carries an approximate percentage weight that reflects how many of the 50-60 scored questions you can expect from that area. Unlike some certifications that publish vague topic lists, Google's guide is specific about sub-bullets under each domain - which is exactly why memorizing the domain names alone won't get you through the exam.

This guide breaks down all six domains in the order Google lists them, with the concrete technical skills each one tests. If you want a broader walkthrough of how to structure your prep around these weights, pair this with our PCNE Study Guide 2026, and if you're still deciding whether the investment makes sense for your career, see Is the PCNE Certification Worth It?

Why domain weights matter: Domains 1 and 2 - VPC design and VPC implementation - combine for roughly 41% of the exam. Any study plan that treats all six domains equally is misallocating time before you've opened a single practice question.

Domain 1: Designing and Planning a VPC Network (21%)

This is the largest domain and the conceptual foundation for everything else on the exam. It tests whether you can architect a Virtual Private Cloud topology before you ever touch implementation details.

What Domain 1 Actually Tests

Candidates need to reason through network topology decisions the way a Google Cloud architect would - balancing cost, latency, isolation, and scalability.

  • Choosing between shared VPC and standalone VPC architectures for multi-team organizations
  • Designing IP address allocation and subnet ranges across regions, including secondary ranges for alias IPs
  • Selecting appropriate routing modes (regional vs. global dynamic routing) for a given topology
  • Planning for scalability constraints such as project and subnet limits
  • Deciding when to use Network Connectivity Center for hub-and-spoke designs

Design questions on the exam are frequently scenario-based: you're given a company's constraints (multiple business units, compliance boundaries, planned expansion) and asked which topology best satisfies them. There is rarely a single "correct" technology - the correct answer is the one that fits the stated constraints.

Domain 2: Implementing a VPC Network (20%)

Where Domain 1 is architectural, Domain 2 is operational. It assumes you've already decided on a design and now must build it correctly in the Google Cloud console, gcloud CLI, or Terraform-style configuration.

Core Implementation Skills

  • Creating custom-mode VPCs, subnets, and firewall rules with correct priority and direction
  • Configuring Cloud Routers and static/dynamic routes, including custom route priorities
  • Implementing Private Service Connect and Private Google Access for API/service reachability
  • Setting up Shared VPC with correct host and service project permissions
  • Configuring internal and external load balancing tiers appropriately for the traffic pattern

Expect questions that present a partially built network and ask you to identify the missing or misconfigured piece - a firewall rule with the wrong priority, a route that's shadowed by a more specific one, or a subnet that lacks the secondary range a GKE cluster needs. This diagnostic style repeats throughout the exam, not just in the troubleshooting domain.

Key Takeaway

Practice building VPCs hands-on rather than only reading documentation. Domains 1 and 2 reward candidates who have actually configured firewall rules, routes, and Shared VPC permissions, not just read about them.

Domain 3: Configuring Managed Network Services (16%)

This domain covers Google Cloud's higher-level networking products - the services that sit on top of raw VPC infrastructure.

Managed Services You Must Know

  • Cloud Load Balancing - differentiating global external, regional external, and internal load balancer use cases
  • Cloud CDN configuration and cache behavior tied to load balancer backends
  • Cloud DNS - public zones, private zones, DNS forwarding, and peering scenarios
  • Cloud NAT configuration for outbound-only internet access from private instances
  • Traffic Director and service mesh basics for managed traffic control

Many candidates underestimate this domain because it feels "product-focused" rather than conceptual. But questions here often ask you to match a business requirement (e.g., "instances need outbound internet access without public IPs") to the single correct managed service - a pattern-matching skill you build only through repetition.

Domain 4: Hybrid and Multicloud Interconnectivity (16%)

Domain 4 tests your ability to connect Google Cloud to on-premises data centers and other cloud providers - a skill set that's increasingly relevant as enterprises adopt multicloud strategies.

Connectivity Options to Master

  • Cloud VPN - choosing between HA VPN and Classic VPN, and understanding tunnel redundancy
  • Cloud Interconnect - Dedicated vs. Partner Interconnect, and when each is appropriate
  • Cloud Router BGP configuration for dynamic route exchange over hybrid links
  • Network Connectivity Center as a hub for connecting multiple on-prem sites and VPCs
  • Bandwidth, redundancy, and SLA trade-offs between connectivity options

Exam scenarios here typically describe a company's existing on-premises footprint and ask which interconnect method meets a stated latency, bandwidth, or redundancy requirement. Knowing the decision tree between VPN, Partner Interconnect, and Dedicated Interconnect is more valuable than memorizing every configuration flag.

Overlap alert: Domains 3 and 4 combined equal 32% of the exam - nearly as much as VPC design alone. Candidates who focus only on "core VPC" topics and treat managed services and hybrid connectivity as an afterthought consistently underperform on this section.

Domain 5: Managing, Monitoring, and Troubleshooting Network Operations (14%)

This domain shifts from building networks to operating and diagnosing them - the day-two responsibilities of a network engineer.

Operational Skills Tested

  • Using VPC Flow Logs and Firewall Rules Logging to diagnose connectivity issues
  • Interpreting Network Intelligence Center insights, including Connectivity Tests and Performance Dashboard
  • Reading Cloud Monitoring metrics and dashboards for network resources
  • Troubleshooting DNS resolution failures across peered or hybrid environments
  • Diagnosing asymmetric routing and firewall rule conflicts

Questions in this domain often provide symptoms - "traffic from Subnet A cannot reach Subnet B" - and ask which diagnostic tool or log source you'd check first. Familiarity with Connectivity Tests in particular shows up repeatedly, since it's Google's purpose-built tool for this exact scenario.

Domain 6: Configuring a Cloud Network Security Solution (13%)

The smallest domain by weight, but security concepts thread through nearly every other domain as well, since firewall rules and access controls appear in design, implementation, and troubleshooting questions too.

Security Topics to Cover

  • Hierarchical firewall policies vs. VPC firewall rules, and their evaluation order
  • Cloud Armor for DDoS and WAF-style protection on load balancers
  • Identity-Aware Proxy (IAP) for context-aware, zero-trust access to resources
  • Private Google Access, VPC Service Controls, and perimeter security for sensitive data
  • Certificate management for HTTPS load balancers, including managed vs. self-managed certs

Because this domain's concepts recur elsewhere on the exam, don't treat its 13% weight as a signal to deprioritize it. A firewall misconfiguration question could just as easily be scored under Domain 2 or Domain 5 depending on how it's framed.

Using Domain Weights to Plan Your Study Time

With official percentages in hand, you can allocate study time proportionally instead of guessing. A simple approach: spend roughly twice as much time on Domain 1 and Domain 2 combined as you do on Domain 6 alone, since together they represent about three times the question share.

Week 1

VPC Design (Domain 1)

  • Study Shared VPC, subnet planning, and routing mode decisions
  • Work through design-scenario practice questions
Week 2

VPC Implementation (Domain 2)

  • Build VPCs, firewall rules, and Cloud Routers hands-on in a sandbox project
  • Configure Shared VPC host/service project permissions
Week 3

Managed Services & Hybrid Connectivity (Domains 3-4)

  • Compare load balancer tiers, Cloud NAT, and Cloud DNS zone types
  • Map VPN vs. Interconnect decision criteria to scenario questions
Week 4

Operations & Security (Domains 5-6)

  • Practice Connectivity Tests and Flow Logs troubleshooting scenarios
  • Review Cloud Armor, IAP, and firewall policy evaluation order

This week-by-week split is only a starting skeleton - for a fuller methodology covering practice-question rotation and review cycles, see the PCNE Study Guide 2026. If you're unsure how difficult the exam feels in practice relative to this domain breakdown, our difficulty guide walks through that separately.

Question Style and Format on Exam Day

The PCNE exam consists of 50-60 multiple-choice and multiple-select questions, delivered over a 2-hour session in English or Japanese. Results are reported strictly as pass/fail - there's no scaled score breakdown by domain provided afterward, which is another reason to self-assess your domain strengths before test day rather than relying on post-exam feedback.

You can sit the exam at a Pearson VUE test center or remotely through OnVUE, both scheduled via Google's CM Connect (CertMetrics) portal. Remote candidates need to meet OnVUE's equipment and room requirements and cannot use notes or outside assistance during the session. The standard fee is $200 plus applicable tax, and there are no formal prerequisites - though Google recommends three or more years of industry experience, including at least one year designing and managing Google Cloud solutions, before attempting it.

For the full breakdown of fees, retake costs, and renewal discounts, see PCNE Certification Cost 2026. If you want specifics on eligibility and the recommended experience level, check PCNE Requirements 2026. And if scheduling logistics are your main concern right now, PCNE Exam Dates 2026 covers testing windows and booking mechanics in detail.

Certification validity: Once earned, the PCNE credential is valid for two years. It renews through the standard examination - the renewal window opens 60 days before your inactive date, and current policy allows renewal up to 30 days after that date, with a 50% discount code available in CM Connect.
DomainWeightPrimary Focus
1. VPC Network Design and Planning~21%Topology, IP planning, routing strategy
2. VPC Network Implementation~20%Building firewall rules, routes, Shared VPC
3. Managed Network Services~16%Load balancing, CDN, DNS, NAT
4. Hybrid and Multicloud Interconnectivity~16%VPN, Interconnect, Network Connectivity Center
5. Network Operations & Troubleshooting~14%Flow Logs, Network Intelligence Center, diagnostics
6. Cloud Network Security~13%Firewall policies, Cloud Armor, IAP

Once you've mapped these weights against your own strengths, running timed practice sets on our practice test platform is the fastest way to see which domains actually need more time versus which you've already mastered on paper. For a condensed, single-page review before test day, bookmark the PCNE Cheat Sheet 2026.

Frequently Asked Questions

Which PCNE domain should I study first?

Start with Domain 1 (VPC network design, ~21%) since its concepts - subnetting, routing modes, Shared VPC - underpin the implementation, managed services, and troubleshooting domains that follow.

Does the PCNE exam guide list sub-topics within each domain?

Yes. Google's official exam guide (file 042426) breaks each of the six domains into specific bullet points covering exact services and configuration scenarios, not just broad themes.

Are questions scored by domain on the results report?

No. The PCNE exam reports results as pass/fail only, with no domain-level score breakdown provided to candidates after the test.

Is security really the least important domain since it's only 13%?

Not exactly. Domain 6 has the lowest standalone weight, but firewall rules, IAP, and access control concepts also surface inside design, implementation, and troubleshooting questions from other domains.

How many questions come from hybrid connectivity topics?

Domain 4 (hybrid and multicloud interconnectivity) is weighted at approximately 16%, covering Cloud VPN, Cloud Interconnect, Cloud Router BGP, and Network Connectivity Center.

Ready to pass your PCNE exam?

Put this into practice with free PCNE questions across every exam domain.