Google Associate Cloud Engineer (ACE) — Questions and Answers
Question 1: Which Google Cloud DNS feature allows you to resolve GCP internal DNS names from an on-premises network connected via Cloud Interconnect?
- Managed Private Zones with DNS Peering
- Public DNS zones
- Cloud CDN
- DNS Forwarding with inbound server policies (Correct answer)
Correct answer: DNS Forwarding with inbound server policies
Cloud DNS inbound server policies create forwarding addresses in a VPC so on-premises resolvers can forward GCP internal DNS queries to Cloud DNS over Interconnect or VPN.
Question 2: What is the purpose of a quality audit in Cloud Engineer practice?
- To systematically evaluate processes against standards and identify improvement opportunities (Correct answer)
- To reduce staffing
- To find fault with employees
- To satisfy external requirements only
Correct answer: To systematically evaluate processes against standards and identify improvement opportunities
This is fundamental to Cloud Engineer practice. To systematically evaluate processes against standards and identify improvement opportunities represents the professional standard for quality in the Cloud Engineer certification framework.
Question 3: Which Cloud Monitoring workspace concept allows a single pane of glass for monitoring resources across multiple GCP projects?
- Scoping project (metrics scope) (Correct answer)
- Log bucket with multiple linked projects
- Shared VPC host project
- Monitored resource descriptor
Correct answer: Scoping project (metrics scope)
A scoping project (formerly called a Workspace) defines a metrics scope that can include metrics from multiple GCP projects, enabling centralized monitoring in a single Cloud Monitoring view.
Question 4: Which GCP tool provides budget alerts and can automatically cap spending by disabling billing on a project?
- Cloud Monitoring dashboards
- Cloud Billing budgets and alerts (Correct answer)
- Cost table in the Billing console
- Recommender API
Correct answer: Cloud Billing budgets and alerts
Cloud Billing budgets let you set a spending threshold and configure email alerts or Pub/Sub notifications; a billing account can also be programmatically disabled at threshold.
Question 5: Which AWS service provides a continuous risk and compliance assessment by checking resource configurations against security best practices?
- AWS Config with Conformance Packs (Correct answer)
- Amazon GuardDuty
- Amazon Inspector
- AWS CloudTrail
Correct answer: AWS Config with Conformance Packs
AWS Config with Conformance Packs evaluates resource configurations against compliance frameworks (CIS, PCI, NIST) on a continuous basis.
Question 6: What is the main difference between a regional and a global external HTTP(S) load balancer?
- Global LB uses Anycast IPs and routes to the nearest backend; regional LB is confined to one region (Correct answer)
- Regional LB uses Anycast; global LB uses unicast IPs
- There is no difference — they use the same infrastructure
- Global LB only supports HTTP; regional LB supports HTTPS
Correct answer: Global LB uses Anycast IPs and routes to the nearest backend; regional LB is confined to one region
The global HTTP(S) LB uses Anycast to route users to the closest healthy backend worldwide, while the regional version serves traffic within a single region.
Question 7: Which networking mode allows a GCP VM to receive packets destined for IP addresses other than its own (used for NAT VMs or VPN gateways)?
- Promiscuous mode
- Multi-NIC mode
- IP forwarding (Correct answer)
- Alias IP ranges
Correct answer: IP forwarding
Enabling IP forwarding on a VM instance allows it to route and forward packets whose destination IP does not match the VM's own IP address.
Question 8: When a cloud engineer is asked to provide a cost estimate to a client, professional standards require that the estimate:
- Match competitor quotes regardless of actual projected spend
- Be kept vague to avoid being held to a specific number
- Include assumptions, confidence intervals, and known unknowns clearly documented (Correct answer)
- Reflect the lowest possible number to win the contract
Correct answer: Include assumptions, confidence intervals, and known unknowns clearly documented
Professional estimates must be transparent about assumptions and uncertainty so clients can make informed decisions.
Question 9: What is the consequence of non-compliance for Cloud Engineer professionals?
- Only verbal warnings
- Just additional paperwork
- No significant consequences
- Potential fines, license revocation, legal liability, and reputational damage (Correct answer)
Correct answer: Potential fines, license revocation, legal liability, and reputational damage
This is fundamental to Cloud Engineer practice. Potential fines, license revocation, legal liability, and reputational damage represents the professional standard for regulatory in the Cloud Engineer certification framework.
Question 10: Which label strategy is a best practice for enabling accurate cost allocation across teams in a large GCP organization?
- Apply labels only to VMs and Cloud Storage buckets
- Use Cloud Monitoring tags instead of billing labels
- Use consistent resource labels (e.g., team, env, cost-center) on all billable resources (Correct answer)
- Rely on project names alone for cost tracking
Correct answer: Use consistent resource labels (e.g., team, env, cost-center) on all billable resources
Consistent resource labels allow Cloud Billing reports to break down costs by dimensions like team, environment, or cost center, enabling granular showback and chargeback.
Question 11: A multi-region AWS deployment uses Route 53 latency-based routing. Users in Europe report that they are sometimes routed to us-east-1 instead of eu-west-1. What is the most likely cause?
- The CloudFront distribution is overriding Route 53 decisions
- Latency-based routing does not support European regions
- The eu-west-1 health check is failing, causing Route 53 to failover to us-east-1 (Correct answer)
- Route 53 TTL is too low, causing frequent resolver changes
Correct answer: The eu-west-1 health check is failing, causing Route 53 to failover to us-east-1
Route 53 latency routing respects health checks; if the eu-west-1 endpoint health check fails, Route 53 routes users to the next healthy region regardless of latency.
Question 12: Which VPC firewall rule component is used to apply the rule only to specific VM instances?
- Protocol and port
- Priority value
- Source IP ranges
- Target tags or target service accounts (Correct answer)
Correct answer: Target tags or target service accounts
Target tags (or target service accounts) on a firewall rule ensure it applies only to VM instances that carry the matching network tag or service account.
Question 13: Which Google Cloud service should you enable to receive alerts when sensitive data is detected in Cloud Storage buckets?
- Cloud Logging
- Cloud DLP (Sensitive Data Protection) (Correct answer)
- Security Command Center Findings only
- Cloud Monitoring
Correct answer: Cloud DLP (Sensitive Data Protection)
Cloud DLP (now called Sensitive Data Protection) scans data in Cloud Storage, BigQuery, and Datastore for sensitive information like PII or credentials and can trigger notifications.
Question 14: A fintech startup experiences intermittent latency spikes in their payment processing API hosted on AWS. CloudWatch shows CPU and memory are normal, but RDS connection errors appear in logs. What is the most likely cause?
- Insufficient EC2 instance size
- RDS connection pool exhaustion under peak load (Correct answer)
- S3 bucket policy blocking API calls
- VPC peering misconfiguration
Correct answer: RDS connection pool exhaustion under peak load
Connection pool exhaustion occurs when concurrent requests exceed the max_connections limit on RDS, causing new connections to fail even though compute resources appear healthy.
Question 15: A cloud architect is designing a risk treatment plan for a DDoS threat against a public-facing API. Selecting AWS Shield Advanced transfers some financial risk because:
- It moves the workload to a private subnet
- It eliminates all network-layer threats
- Shield Advanced patches all API vulnerabilities automatically
- It includes Cost Protection that reimburses scaling costs incurred during a DDoS attack (Correct answer)
Correct answer: It includes Cost Protection that reimburses scaling costs incurred during a DDoS attack
AWS Shield Advanced Cost Protection reimburses EC2, CloudFront, and Route 53 scaling charges triggered by a DDoS event, financially transferring that risk to AWS.
Question 16: A data engineering team ingests 1TB of JSON logs daily into AWS S3, then queries them with Athena. Queries scan the full 1TB each time, costing $5/query. What single change reduces query cost most?
- Enable S3 Select on the bucket
- Increase Athena query concurrency
- Convert logs to Parquet format with Snappy compression and partition by date (Correct answer)
- Move logs from S3 Standard to S3 Intelligent-Tiering
Correct answer: Convert logs to Parquet format with Snappy compression and partition by date
Parquet's columnar format allows Athena to scan only required columns, and date partitioning prunes irrelevant partitions; together they can reduce data scanned by 95%+.
Question 17: How should an Cloud Engineer professional handle an outcome that differs from expectations?
- Ignore the discrepancy
- Blame external factors
- Repeat the same approach
- Analyze contributing factors, document findings, and adjust approach based on lessons learned (Correct answer)
Correct answer: Analyze contributing factors, document findings, and adjust approach based on lessons learned
This is fundamental to Cloud Engineer practice. Analyze contributing factors, document findings, and adjust approach based on lessons learned represents the professional standard for practical in the Cloud Engineer certification framework.
Question 18: A cloud engineer needs to explain a production outage to C-suite executives. Which communication approach is most appropriate?
- Wait until the incident is fully resolved before communicating
- Escalate to the engineering manager and let them handle communication
- Send a detailed technical root cause analysis immediately
- Provide a concise impact summary, current status, and next steps first (Correct answer)
Correct answer: Provide a concise impact summary, current status, and next steps first
Executives need impact, status, and mitigation steps — technical details come later in a post-mortem.
Question 19: Which Google Cloud networking product connects your on-premises network to GCP using a dedicated physical connection?
- Cloud VPN
- Cloud Interconnect (Dedicated) (Correct answer)
- Cloud CDN
- Direct Peering
Correct answer: Cloud Interconnect (Dedicated)
Dedicated Interconnect provides a direct physical connection between your on-premises network and Google's network, offering high bandwidth and low latency.
Question 20: You need to store logs from a Cloud Run service for 2 years to meet compliance requirements. What is the most cost-effective approach?
- Enable Data Access Audit Logs and keep them in Cloud Logging
- Create a log sink to export logs to a Cloud Storage bucket with a lifecycle policy (Correct answer)
- Increase the _Default log bucket retention to 730 days
- Use a Pub/Sub subscription to archive logs to an on-premises system
Correct answer: Create a log sink to export logs to a Cloud Storage bucket with a lifecycle policy
Exporting logs to Cloud Storage via a sink is the most cost-effective long-term archival solution; Cloud Storage costs less per GB than Cloud Logging for extended retention periods.
Question 21: What is the minimum number of Cloud VPN tunnels needed to achieve 99.99% availability for a VPN connection to on-premises?
- 2
- 8
- 4 (Correct answer)
- 1
Correct answer: 4
HA VPN with 99.99% SLA requires two HA VPN gateways each with two interfaces, creating 4 tunnels total across two on-premises peer gateways for full redundancy.
Question 22: Which BigQuery feature eliminates the need to manage cluster sizing and charges only for data scanned?
- BigQuery on-demand pricing (Correct answer)
- BigQuery Omni
- BigQuery Reservations (flat-rate pricing)
- BigQuery BI Engine
Correct answer: BigQuery on-demand pricing
BigQuery on-demand pricing charges per TB of data scanned, with no infrastructure to manage, making it cost-efficient for variable or unpredictable query workloads.
Question 23: How do Cloud Engineer professionals maintain digital competency?
- Through ongoing training, practice with new tools, and staying current with technological advances (Correct answer)
- Digital skills are not required
- Skills from initial training are sufficient
- By hiring IT support for all tasks
Correct answer: Through ongoing training, practice with new tools, and staying current with technological advances
This is fundamental to Cloud Engineer practice. Through ongoing training, practice with new tools, and staying current with technological advances represents the professional standard for technology in the Cloud Engineer certification framework.
Question 24: Which Google Cloud service provides a unified dashboard for metrics, logs, and traces across your cloud infrastructure?
- Cloud Profiler
- Error Reporting
- Cloud Monitoring (Correct answer)
- Cloud Trace
Correct answer: Cloud Monitoring
Cloud Monitoring (formerly Stackdriver Monitoring) provides a unified dashboard for metrics, uptime checks, alerting, and dashboards across Google Cloud and AWS resources.
Question 25: During risk prioritization, which scoring model uses five factors—Damage, Reproducibility, Exploitability, Affected users, and Discoverability—to rate vulnerabilities?
- DREAD (Correct answer)
- OWASP Risk Rating
- STRIDE
- CVSS
Correct answer: DREAD
DREAD is a Microsoft-originated vulnerability scoring model using five factors to produce a numeric risk score for prioritization.
Question 26: How does a Cloud Engineer professional communicate risks to stakeholders?
- Through annual reports only
- By presenting risks clearly with context, potential impacts, and recommended actions (Correct answer)
- By minimizing all risks
- Using technical jargon only
Correct answer: By presenting risks clearly with context, potential impacts, and recommended actions
This is fundamental to Cloud Engineer practice. By presenting risks clearly with context, potential impacts, and recommended actions represents the professional standard for risk management in the Cloud Engineer certification framework.
Question 27: What is a GCP Commitment (CUD) applied to in terms of scope?
- A single VM instance
- A billing account across all projects
- A specific project
- A specific region and machine family (Correct answer)
Correct answer: A specific region and machine family
Committed Use Discounts are scoped to a specific region and machine family (e.g., N2 in us-central1), and the discount applies to any matching usage within that scope.
Question 28: You want to reduce Cloud Logging ingestion costs by dropping noisy DEBUG-level log entries from a specific service before they are stored. What should you configure?
- Log bucket with reduced retention
- Cloud Monitoring alert suppression
- Log exclusion filter (Correct answer)
- Log sink to /dev/null
Correct answer: Log exclusion filter
Log exclusion filters in Cloud Logging drop matching log entries before they are ingested and stored, reducing ingestion volume and costs.
Question 29: What does Identity-Aware Proxy (IAP) protect in Google Cloud?
- Encrypts data at rest in Cloud Storage
- Manages SSL certificates for load balancers
- Controls access to applications and VMs based on user identity and context (Correct answer)
- Scans container images for vulnerabilities
Correct answer: Controls access to applications and VMs based on user identity and context
IAP enforces access control for web applications and VM SSH/RDP by verifying user identity and device context before granting access.
Question 30: What is the recommended method to grant a Compute Engine VM access to Google Cloud APIs without storing credentials in the code?
- Store credentials in Cloud Storage
- Embed a service account key in the VM startup script
- Attach a service account to the VM instance (Correct answer)
- Use environment variables with API keys
Correct answer: Attach a service account to the VM instance
Attaching a service account to a VM instance allows it to authenticate to Google Cloud APIs using Application Default Credentials without managing key files.
Question 31: A VPC network has a firewall rule allowing SSH from 0.0.0.0/0. You want to restrict SSH access to only your corporate IP range (203.0.113.0/24). What is the correct action?
- Change the existing rule's source range to 203.0.113.0/24 (Correct answer)
- Add 203.0.113.0/24 as a target tag on the existing rule
- Create a higher-priority deny rule for 0.0.0.0/0 and an allow rule for 203.0.113.0/24
- Delete the existing allow rule and create a new allow rule for 203.0.113.0/24
Correct answer: Change the existing rule's source range to 203.0.113.0/24
Editing the source IP range of the existing firewall rule directly restricts SSH to the specified corporate range.
Question 32: A GCP VM needs to communicate privately with a Google managed service (like Cloud Storage) without sending traffic over the internet. What feature enables this?
- VPC Peering
- Private Google Access (Correct answer)
- Cloud NAT
- Cloud CDN
Correct answer: Private Google Access
Private Google Access allows VMs with only internal IP addresses to reach Google APIs and services over Google's internal network without needing an external IP.
Question 33: What is a risk mitigation strategy in Cloud Engineer practice?
- Only addressing risks after they occur
- Transferring all responsibility
- Ignoring low-probability risks
- Implementing controls that reduce the likelihood or impact of identified risks (Correct answer)
Correct answer: Implementing controls that reduce the likelihood or impact of identified risks
This is fundamental to Cloud Engineer practice. Implementing controls that reduce the likelihood or impact of identified risks represents the professional standard for risk management in the Cloud Engineer certification framework.
Question 34: A team deployed several test VMs that are now idle. Which GCP tool will proactively identify these idle VMs and suggest deleting them?
- Cloud Billing cost table
- Cloud Monitoring uptime checks
- Cloud Trace
- Google Cloud Recommender (idle VM recommendation) (Correct answer)
Correct answer: Google Cloud Recommender (idle VM recommendation)
Google Cloud Recommender provides idle VM recommendations by identifying instances with low CPU utilization over a rolling 14-day window and suggesting they be stopped or deleted.
Question 35: Which Cloud DNS record type is used to map a hostname to an IPv6 address?
- A record
- AAAA record (Correct answer)
- PTR record
- CNAME record
Correct answer: AAAA record
AAAA records map a domain name to an IPv6 address, while A records map to IPv4 addresses.
Question 36: What happens to a Spot VM when Compute Engine needs the capacity back?
- It continues running but at a higher price
- It is stopped or preempted with a 30-second warning (Correct answer)
- It is converted to a standard VM at on-demand pricing
- It is migrated to another zone automatically
Correct answer: It is stopped or preempted with a 30-second warning
Spot VMs (formerly Preemptible VMs) can be preempted by Google at any time with a 30-second shutdown notice when Compute Engine needs the capacity for other workloads.
Question 37: What is the default retention period for logs stored in the _Default log bucket in Cloud Logging?
- 30 days (Correct answer)
- 365 days
- 7 days
- 90 days
Correct answer: 30 days
The _Default log bucket retains logs for 30 days by default; you can extend retention up to 3,650 days for an additional cost.
Question 38: A team uses contract testing between microservices. What does this approach verify?
- That all services share the same database schema
- That each service honors the API contract expected by its consumers (Correct answer)
- That legal SLAs are documented correctly
- That network latency stays below a defined threshold
Correct answer: That each service honors the API contract expected by its consumers
Contract testing ensures that a provider service's API response matches what its consumer services actually expect.
Question 39: Which PCI DSS requirement specifically addresses the protection of stored cardholder data?
- Requirement 6
- Requirement 1
- Requirement 3 (Correct answer)
- Requirement 10
Correct answer: Requirement 3
PCI DSS Requirement 3 covers protection of stored cardholder data, including encryption and data retention policies.
Question 40: A cloud engineer is implementing SLOs for a service. What does an 'error budget' represent?
- The number of failed deployments permitted per sprint
- The maximum number of open bug tickets at any time
- The allowed amount of downtime or errors before the SLO is breached (Correct answer)
- The allocated cloud spend before alerts trigger
Correct answer: The allowed amount of downtime or errors before the SLO is breached
An error budget is the acceptable margin of failure derived from the SLO, giving teams flexibility to ship while maintaining reliability.
Question 41: Which Cloud Load Balancer type operates at Layer 7 and supports content-based routing (e.g., URL maps)?
- Internal TCP/UDP Load Balancer
- Network Passthrough Load Balancer
- TCP Proxy Load Balancer
- External HTTP(S) Load Balancer (Correct answer)
Correct answer: External HTTP(S) Load Balancer
The External HTTP(S) Load Balancer (Application Load Balancer) operates at Layer 7 and supports URL-based routing, host-based routing, and other HTTP-aware features.
Question 42: What GCP feature lets you set maximum resource quotas per project to prevent runaway spend on services like Compute Engine or BigQuery?
- Quotas and limits in the Cloud Console / API (Correct answer)
- Budget thresholds
- IAM deny policies
- Org Policy constraints
Correct answer: Quotas and limits in the Cloud Console / API
GCP quotas (found in IAM & Admin > Quotas) cap the maximum number of resources a project can use, preventing runaway costs from misconfigured autoscaling or runaway queries.
Question 43: A cloud engineer's employer asks them to configure infrastructure in a way that clearly violates a customer's contractual data residency requirement. The engineer should:
- Implement it but alert the customer after the fact
- Seek a third-party cloud consultant to share responsibility
- Implement it and note the deviation in a comment
- Refuse and document the conflict in writing to management (Correct answer)
Correct answer: Refuse and document the conflict in writing to management
Violating a contractual data residency requirement exposes the company to legal liability; the engineer should refuse and escalate in writing.
Question 44: A Compute Engine VM runs continuously for a full month. What automatic discount is applied without any commitment required?
- Free tier credit
- Committed Use Discount
- Spot VM discount
- Sustained Use Discount (SUD) (Correct answer)
Correct answer: Sustained Use Discount (SUD)
Sustained Use Discounts are automatic discounts of up to 30% applied to VMs that run for a significant portion of the billing month (no commitment required).
Question 45: What GCP feature allows you to export detailed billing data to BigQuery for advanced cost analysis?
- Pub/Sub billing notifications
- Cloud Monitoring metrics export
- Cloud Logging sinks
- Cloud Billing data export to BigQuery (Correct answer)
Correct answer: Cloud Billing data export to BigQuery
Cloud Billing export to BigQuery streams all billing data (usage, cost, credits) into a BigQuery dataset for custom queries, dashboards, and cost allocation reports.
Question 46: What is 'survivorship bias' and how can it distort cloud architecture research?
- Overweighting architectures that are still running while ignoring failed designs that were abandoned (Correct answer)
- The tendency to favor cloud services that have survived multiple outages
- Selecting the vendor that has been in business the longest
- Bias toward architectures that survived a security audit
Correct answer: Overweighting architectures that are still running while ignoring failed designs that were abandoned
Survivorship bias leads teams to study only successful architectures, missing lessons from failures that were quietly discarded.
Question 47: What is the significance of a code of conduct for Cloud Engineer professionals?
- It limits professional freedom
- It establishes expected behaviors and ethical standards that protect the public and profession (Correct answer)
- It applies only to new practitioners
- It is merely symbolic
Correct answer: It establishes expected behaviors and ethical standards that protect the public and profession
This is fundamental to Cloud Engineer practice. It establishes expected behaviors and ethical standards that protect the public and profession represents the professional standard for professional standards in the Cloud Engineer certification framework.
Question 48: Which control from the CIS Controls framework specifically addresses the management of cloud-based assets?
- CIS Control 1: Inventory and Control of Enterprise Assets (Correct answer)
- CIS Control 16: Application Software Security
- CIS Control 4: Secure Configuration of Enterprise Assets
- CIS Control 17: Incident Response Management
Correct answer: CIS Control 1: Inventory and Control of Enterprise Assets
CIS Control 1 focuses on maintaining an accurate inventory of all enterprise assets, including cloud-based resources, as the foundation of security.
Question 49: What is the main cost advantage of using Cloud Run over Compute Engine for stateless web workloads?
- Cloud Run charges only for CPU and memory consumed during request processing, with no idle charges (Correct answer)
- Cloud Run uses cheaper disk storage
- Cloud Run VMs qualify for Sustained Use Discounts
- Cloud Run has lower network egress costs
Correct answer: Cloud Run charges only for CPU and memory consumed during request processing, with no idle charges
Cloud Run scales to zero and charges only while actively handling requests, eliminating idle infrastructure costs that you'd pay for always-on Compute Engine VMs.
Question 50: You want to send all internet-bound traffic from a subnet through a centralized firewall VM. What GCP feature enables this custom routing?
- VPC firewall priority rules
- Cloud NAT outbound policy
- Custom static routes with a next-hop VM (Correct answer)
- Cloud Armor policy attachment
Correct answer: Custom static routes with a next-hop VM
Creating a custom static route with a next-hop pointing to a VM instance (firewall appliance) forces traffic matching the destination to traverse that VM.
Google Associate Cloud Engineer (ACE)
The Google Associate Cloud Engineer certification validates the ability to deploy applications, monitor operations, and manage enterprise solutions on Google Cloud Platform. It covers cloud infrastructure setup, solution planning and configuration, deployment, operations management, and access/security configuration.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds