Associate Cloud Engineer v1.0 Flashcards
7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Associate Cloud Engineer v1.0 flashcards as text
Your team needs to grant a developer read-only access to all Cloud Storage buckets in a project without affecting other resources. Which IAM role should you assign at the project level?
Answer: roles/storage.objectViewer
roles/storage.objectViewer grants read access to objects in all buckets within the project without broader project-level permissions.
A GKE cluster needs to pull private container images from Artifact Registry in the same project. What is the recommended approach?
Answer: Grant the node pool's service account roles/artifactregistry.reader
Assigning roles/artifactregistry.reader to the node pool's service account follows least-privilege and is the GCP-recommended method.
You want to deploy a containerized batch job that runs to completion and does not need to serve HTTP traffic. Which Google Cloud service is most appropriate?
Answer: Cloud Run Jobs
Cloud Run Jobs are designed for containerized workloads that run to completion rather than serving ongoing requests.
A Cloud SQL instance is running out of storage. Which setting should you enable to avoid downtime from a full disk?
Answer: Automatic storage increase
Enabling automatic storage increase allows Cloud SQL to expand disk capacity automatically when it reaches a threshold.
Which gcloud command lists all VM instances across every zone in a project?
Answer: gcloud compute instances list
gcloud compute instances list without zone flags returns instances from all zones in the current project by default.
You need to schedule a lightweight script to run every 5 minutes without managing servers. Which service combination is most cost-effective?
Answer: Cloud Scheduler triggering a Cloud Function
Cloud Scheduler invoking a Cloud Function is serverless, scales to zero, and is cheapest for infrequent lightweight tasks.
A VPC network has a firewall rule allowing SSH from 0.0.0.0/0. You want to restrict SSH access to only your corporate IP range (203.0.113.0/24). What is the correct action?
Answer: Change the existing rule's source range to 203.0.113.0/24
Editing the source IP range of the existing firewall rule directly restricts SSH to the specified corporate range.