Google Associate Cloud Engineer (ACE) — Questions and Answers
Question 1: You need to ensure that all new VM instances in your organization use only approved OS images. Which policy should you configure?
- Organization policy constraint constraints/compute.trustedImageProjects (Correct answer)
- IAM deny policy on Compute Engine
- Firewall rule restricting image sources
- VPC Service Controls perimeter
Correct answer: Organization policy constraint constraints/compute.trustedImageProjects
The trustedImageProjects organization policy constraint restricts VM creation to images from specified approved projects.
Question 2: Which GCP feature provides DDoS protection and is automatically included with the global HTTP(S) Load Balancer?
- Identity-Aware Proxy
- Cloud IDS
- VPC Firewall Rules
- Cloud Armor (Correct answer)
Correct answer: Cloud Armor
Cloud Armor provides DDoS protection and WAF capabilities and integrates directly with the global HTTP(S) Load Balancer as its security policy engine.
Question 3: Which field in a Cloud Logging log entry indicates the source GCP resource that generated the log, such as a specific Compute Engine VM or Cloud Run revision?
- logName
- severity
- resource (Correct answer)
- insertId
Correct answer: resource
The 'resource' field in a log entry contains a MonitoredResource object that identifies the type and labels of the GCP resource that generated the log entry.
Question 4: Which Cloud DNS record type is used to map a hostname to an IPv6 address?
- PTR record
- CNAME record
- A record
- AAAA record (Correct answer)
Correct answer: AAAA record
AAAA records map a domain name to an IPv6 address, while A records map to IPv4 addresses.
Question 5: Your application stores session data in Cloud Memorystore for Redis. After a Redis instance restart, all session data is lost. What should you enable to persist data across restarts?
- VPC peering
- High availability (HA) mode only
- RDB snapshots or AOF persistence (Correct answer)
- Read replicas
Correct answer: RDB snapshots or AOF persistence
Enabling RDB persistence or AOF logging in Memorystore for Redis allows data to survive instance restarts.
Question 6: A Cloud Monitoring alerting policy is configured with a condition duration of 5 minutes. What does this mean?
- The alert policy is evaluated every 5 minutes
- Notifications are delayed by 5 minutes after the alert fires
- The alert fires immediately when the threshold is exceeded for any instant
- The alert fires only if the threshold is continuously exceeded for 5 minutes (Correct answer)
Correct answer: The alert fires only if the threshold is continuously exceeded for 5 minutes
The condition duration (also called the alignment period or 'for' window) requires the threshold to be continuously violated for the specified duration before the alerting policy fires.
Question 7: Which BigQuery feature eliminates the need to manage cluster sizing and charges only for data scanned?
- BigQuery Omni
- BigQuery on-demand pricing (Correct answer)
- BigQuery Reservations (flat-rate pricing)
- BigQuery BI Engine
Correct answer: BigQuery on-demand pricing
BigQuery on-demand pricing charges per TB of data scanned, with no infrastructure to manage, making it cost-efficient for variable or unpredictable query workloads.
Question 8: You are setting up a Cloud Armor security policy. Which rule action blocks requests that match a condition?
- redirect
- throttle
- deny(403) (Correct answer)
- allow
Correct answer: deny(403)
The deny(403) action in Cloud Armor returns an HTTP 403 Forbidden response to requests matching the security policy rule.
Question 9: Which Compute Engine pricing model offers the deepest discounts (up to 70% off on-demand) in exchange for a firm 1-year or 3-year commitment?
- Committed Use Discounts (CUD) (Correct answer)
- Spot VMs
- Preemptible VMs
- Sustained Use Discounts (SUD)
Correct answer: Committed Use Discounts (CUD)
Committed Use Discounts (CUDs) offer up to 70% off on-demand prices for a 1- or 3-year commitment to a specific machine type or resource, providing the highest discount tier.
Question 10: A Dataflow pipeline reading from Cloud Storage is running slowly. The job graph shows one stage with significantly more work than others. What is the likely cause?
- Data skew causing a hot key in one worker bundle (Correct answer)
- The Cloud Storage bucket is in a different region than the Dataflow job
- The pipeline uses the wrong runner (DirectRunner instead of DataflowRunner)
- Insufficient IAM permissions for the Dataflow worker
Correct answer: Data skew causing a hot key in one worker bundle
Data skew causes one worker to receive a disproportionate share of data, creating a bottleneck visible as an unbalanced stage in the job graph.
Question 11: When publishing an internal research report on a cloud cost optimization experiment, which element most strengthens the report's credibility and reusability?
- A methodology section detailing data sources, collection period, tools used, exclusions, and assumptions (Correct answer)
- Colorful charts and visualizations for executive presentations
- Comparison to a competitor's publicly reported cloud spend
- Executive summary endorsed by senior leadership
Correct answer: A methodology section detailing data sources, collection period, tools used, exclusions, and assumptions
A detailed methodology section allows others to critique the approach, reproduce the analysis, and understand the conditions under which the findings apply.
Question 12: What is the purpose of regular risk reviews in Cloud Engineer practice?
- To reduce workload
- To identify new risks, evaluate control effectiveness, and update mitigation strategies (Correct answer)
- To satisfy auditors only
- To generate reports
Correct answer: To identify new risks, evaluate control effectiveness, and update mitigation strategies
This is fundamental to Cloud Engineer practice. To identify new risks, evaluate control effectiveness, and update mitigation strategies represents the professional standard for risk management in the Cloud Engineer certification framework.
Question 13: What GCP feature lets you set maximum resource quotas per project to prevent runaway spend on services like Compute Engine or BigQuery?
- Org Policy constraints
- IAM deny policies
- Quotas and limits in the Cloud Console / API (Correct answer)
- Budget thresholds
Correct answer: Quotas and limits in the Cloud Console / API
GCP quotas (found in IAM & Admin > Quotas) cap the maximum number of resources a project can use, preventing runaway costs from misconfigured autoscaling or runaway queries.
Question 14: What is the purpose of Cloud NAT in Google Cloud?
- Encrypt traffic between on-premises and GCP
- Allow VMs without external IPs to access the internet for outbound traffic (Correct answer)
- Provide inbound internet access to VMs
- Route traffic between VPC networks
Correct answer: Allow VMs without external IPs to access the internet for outbound traffic
Cloud NAT enables VMs without external IP addresses to initiate outbound connections to the internet, keeping them private while still allowing updates and API calls.
Question 15: A GDPR Data Protection Impact Assessment (DPIA) is mandatory when processing activities are likely to result in which outcome?
- Cross-border data transfers to any non-EU country
- High risk to the rights and freedoms of natural persons (Correct answer)
- Processing data of more than 1,000 individuals
- Storage of data beyond 90 days
Correct answer: High risk to the rights and freedoms of natural persons
Under GDPR Article 35, a DPIA is required prior to processing that is likely to result in a high risk to individuals' rights and freedoms, such as large-scale profiling or systematic monitoring.
Question 16: You are designing a solution requiring global HTTP(S) load balancing with SSL termination and Cloud CDN. Which load balancer type should you use?
- Internal TCP/UDP Load Balancer
- Regional External Application Load Balancer
- Network Load Balancer
- External Application Load Balancer (Global) (Correct answer)
Correct answer: External Application Load Balancer (Global)
The External Application Load Balancer in global mode supports HTTPS, SSL termination, and integrates with Cloud CDN at Google's edge.
Question 17: A junior engineer on your team writes overly complex Terraform code with no comments. As a senior cloud engineer, the BEST professional response is:
- Rewrite the code silently without informing them
- Approve the code to avoid conflict since it technically works
- Provide constructive feedback, suggest simplification, and explain readability standards in a code review (Correct answer)
- Escalate immediately to management as a performance issue
Correct answer: Provide constructive feedback, suggest simplification, and explain readability standards in a code review
Constructive code review feedback builds team competency and establishes maintainable standards without undermining the junior engineer.
Question 18: What is the role of professional journals in Cloud Engineer practice?
- They are optional reading
- They only benefit academics
- They are outdated by publication time
- They disseminate current research, best practices, and professional developments (Correct answer)
Correct answer: They disseminate current research, best practices, and professional developments
This is fundamental to Cloud Engineer practice. They disseminate current research, best practices, and professional developments represents the professional standard for research in the Cloud Engineer certification framework.
Question 19: The corporate apps of your client are being moved to the Google Cloud Platform. The security team requests complete visibility into every project within the company. You create your account as the organization administrator and provide the Google Cloud Resource Manager. Which Cloud IAM (Google Cloud Identity and Access Management) roles ought the security team be assigned?
- Org viewer, project owner
- Org viewer, project viewer (Correct answer)
- Project owner, network admin
- Org admin, project browser
Correct answer: Org viewer, project viewer
The security team requires complete visibility into all projects and the organization structure without the ability to make changes. The `Org viewer` role grants read-only access to organization-level resources, while the `Project viewer` role provides read-only access to all resources within projects. Assigning both roles ensures the security team has comprehensive visibility for auditing purposes across the entire GCP organization without granting any modification permissions.
Question 20: A container image-packaged program has to be deployed in a new project. Not many requests are made daily to the application, which exposes an HTTP endpoint. You want to reduce spending. What ought you to do?
- Deploy the container on GKE with cluster autoscaling and horizontal pod autoscaling enabled
- Deploy the container on App Engine Flexible
- Deploy the container on Cloud Run
- Deploy the container on Cloud Run on GKE (Correct answer)
Correct answer: Deploy the container on Cloud Run on GKE
For a containerized application with low daily request volume, deploying it on Cloud Run on GKE is a highly cost-effective solution. Cloud Run on GKE allows the application to scale down to zero instances when idle, meaning you only pay for resources when requests are actively being processed. This minimizes infrastructure costs compared to maintaining a full GKE cluster with constantly running nodes or using App Engine Flexible for such low-traffic scenarios.
Question 21: What is the recommended method to grant a Compute Engine VM access to Google Cloud APIs without storing credentials in the code?
- Embed a service account key in the VM startup script
- Use environment variables with API keys
- Attach a service account to the VM instance (Correct answer)
- Store credentials in Cloud Storage
Correct answer: Attach a service account to the VM instance
Attaching a service account to a VM instance allows it to authenticate to Google Cloud APIs using Application Default Credentials without managing key files.
Question 22: How has digital technology transformed Cloud Engineer practice?
- It has had no impact
- It only affects large organizations
- It has replaced all traditional methods
- It has enhanced data collection, analysis, communication, and operational efficiency (Correct answer)
Correct answer: It has enhanced data collection, analysis, communication, and operational efficiency
This is fundamental to Cloud Engineer practice. It has enhanced data collection, analysis, communication, and operational efficiency represents the professional standard for technology in the Cloud Engineer certification framework.
Question 23: A cloud engineer must ensure that VPC Flow Logs are enabled for a subnet to analyze network traffic. Where is this setting configured?
- In Cloud Monitoring under network metrics
- On the subnet resource in the VPC network configuration (Correct answer)
- In the firewall rule policy for the network
- In the Cloud Logging log sink configuration
Correct answer: On the subnet resource in the VPC network configuration
VPC Flow Logs are enabled per-subnet in the VPC network configuration; when enabled, they capture a sample of network flows to and from VM instances in that subnet.
Question 24: What Cloud Armor policy type protects against common web attacks like SQL injection and cross-site scripting?
- Rate-based rules
- WAF (Web Application Firewall) preconfigured rules (Correct answer)
- Custom IP allow/deny rules
- Adaptive Protection policy
Correct answer: WAF (Web Application Firewall) preconfigured rules
Cloud Armor includes preconfigured WAF rules based on OWASP ModSecurity Core Rule Set to block common web exploits like SQLi and XSS.
Question 25: Which GCP service provides rightsizing recommendations by analyzing VM CPU and memory utilization data?
- Cost Management console
- Cloud Billing reports
- Cloud Monitoring alerting
- Google Cloud Recommender (Correct answer)
Correct answer: Google Cloud Recommender
Google Cloud Recommender analyzes resource usage patterns and suggests cost-saving actions like rightsizing oversized VMs or removing idle resources.
Question 26: A cloud team is conducting a risk assessment for a new AI/ML workload that processes PII. Which privacy regulation is most directly relevant for a US-based healthcare dataset?
- GDPR
- SOC 2
- PCI DSS
- HIPAA (Correct answer)
Correct answer: HIPAA
HIPAA governs Protected Health Information (PHI) in the US, making it the primary compliance framework for healthcare PII on cloud workloads.
Question 27: A GCP VM needs to communicate privately with a Google managed service (like Cloud Storage) without sending traffic over the internet. What feature enables this?
- Cloud CDN
- VPC Peering
- Private Google Access (Correct answer)
- Cloud NAT
Correct answer: Private Google Access
Private Google Access allows VMs with only internal IP addresses to reach Google APIs and services over Google's internal network without needing an external IP.
Question 28: A company runs a critical Azure SQL Database. During a DR test, they restore a geo-redundant backup to the secondary region and find data is 2 hours old. Their RPO requirement is 15 minutes. What change is needed?
- Enable zone-redundant backups in the primary region
- Enable Active Geo-Replication or Auto-Failover Groups, which provide near-real-time replication with RPO of ~5 seconds (Correct answer)
- Switch to Azure SQL Hyperscale tier for faster backups
- Increase backup frequency from daily to hourly
Correct answer: Enable Active Geo-Replication or Auto-Failover Groups, which provide near-real-time replication with RPO of ~5 seconds
Geo-redundant backups have an RPO of 1-2 hours; Active Geo-Replication continuously replicates transactions to a secondary database, achieving RPO of seconds to meet the 15-minute SLA.
Question 29: A team deployed several test VMs that are now idle. Which GCP tool will proactively identify these idle VMs and suggest deleting them?
- Cloud Billing cost table
- Google Cloud Recommender (idle VM recommendation) (Correct answer)
- Cloud Trace
- Cloud Monitoring uptime checks
Correct answer: Google Cloud Recommender (idle VM recommendation)
Google Cloud Recommender provides idle VM recommendations by identifying instances with low CPU utilization over a rolling 14-day window and suggesting they be stopped or deleted.
Question 30: You want to send all internet-bound traffic from a subnet through a centralized firewall VM. What GCP feature enables this custom routing?
- VPC firewall priority rules
- Cloud NAT outbound policy
- Cloud Armor policy attachment
- Custom static routes with a next-hop VM (Correct answer)
Correct answer: Custom static routes with a next-hop VM
Creating a custom static route with a next-hop pointing to a VM instance (firewall appliance) forces traffic matching the destination to traverse that VM.
Google Associate Cloud Engineer (ACE)
The Google Associate Cloud Engineer certification validates the ability to deploy applications, monitor operations, and manage enterprise solutions on Google Cloud Platform. It covers cloud infrastructure setup, solution planning and configuration, deployment, operations management, and access/security configuration.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds