Google Associate Cloud Engineer (ACE) — Questions and Answers
Question 1: You are designing a solution requiring global HTTP(S) load balancing with SSL termination and Cloud CDN. Which load balancer type should you use?
- Network Load Balancer
- Internal TCP/UDP Load Balancer
- External Application Load Balancer (Global) (Correct answer)
- Regional External Application Load Balancer
Correct answer: External Application Load Balancer (Global)
The External Application Load Balancer in global mode supports HTTPS, SSL termination, and integrates with Cloud CDN at Google's edge.
Question 2: What GCP feature allows you to export detailed billing data to BigQuery for advanced cost analysis?
- Cloud Logging sinks
- Cloud Monitoring metrics export
- Pub/Sub billing notifications
- Cloud Billing data export to BigQuery (Correct answer)
Correct answer: Cloud Billing data export to BigQuery
Cloud Billing export to BigQuery streams all billing data (usage, cost, credits) into a BigQuery dataset for custom queries, dashboards, and cost allocation reports.
Question 3: Your organization uses Shared VPC. Where must the Shared VPC host project's subnets be configured?
- In each service project separately
- In the host project, then shared to service projects (Correct answer)
- In a dedicated networking project outside the Shared VPC structure
- In the organization resource node
Correct answer: In the host project, then shared to service projects
In a Shared VPC setup, subnets are created and managed in the host project and then shared with one or more service projects, centralizing network administration.
Question 4: Which networking mode allows a GCP VM to receive packets destined for IP addresses other than its own (used for NAT VMs or VPN gateways)?
- Multi-NIC mode
- Alias IP ranges
- Promiscuous mode
- IP forwarding (Correct answer)
Correct answer: IP forwarding
Enabling IP forwarding on a VM instance allows it to route and forward packets whose destination IP does not match the VM's own IP address.
Question 5: Which Compute Engine pricing model offers the deepest discounts (up to 70% off on-demand) in exchange for a firm 1-year or 3-year commitment?
- Sustained Use Discounts (SUD)
- Committed Use Discounts (CUD) (Correct answer)
- Spot VMs
- Preemptible VMs
Correct answer: Committed Use Discounts (CUD)
Committed Use Discounts (CUDs) offer up to 70% off on-demand prices for a 1- or 3-year commitment to a specific machine type or resource, providing the highest discount tier.
Question 6: A risk owner has been assigned to a critical cloud database risk. What is the primary responsibility of a risk owner?
- Perform penetration tests on the database
- Ensure that treatment plans are implemented and the risk is monitored over time (Correct answer)
- Report the risk to regulators
- Write the database backup scripts
Correct answer: Ensure that treatment plans are implemented and the risk is monitored over time
The risk owner is accountable for ensuring that the agreed treatment plan is executed and that residual risk stays within acceptable bounds.
Question 7: What is the purpose of Alias IP ranges on a GCP VM instance?
- Enable IPv6 on the VM interface
- Assign multiple internal IP addresses or ranges to a single VM interface (Correct answer)
- Override the default gateway for the VM
- Assign multiple external IPs to a single VM
Correct answer: Assign multiple internal IP addresses or ranges to a single VM interface
Alias IP ranges allow a single VM network interface to have additional internal IP addresses or subnets, useful for containers or multiple services running on one VM.
Question 8: How do Cloud Engineer professionals establish measurable quality objectives?
- By comparing to competitors only
- Through subjective assessment
- By defining specific, measurable, achievable, relevant, and time-bound quality targets (Correct answer)
- Using vague goals
Correct answer: By defining specific, measurable, achievable, relevant, and time-bound quality targets
This is fundamental to Cloud Engineer practice. By defining specific, measurable, achievable, relevant, and time-bound quality targets represents the professional standard for quality in the Cloud Engineer certification framework.
Question 9: Which Google Cloud DNS feature allows you to resolve GCP internal DNS names from an on-premises network connected via Cloud Interconnect?
- DNS Forwarding with inbound server policies (Correct answer)
- Managed Private Zones with DNS Peering
- Cloud CDN
- Public DNS zones
Correct answer: DNS Forwarding with inbound server policies
Cloud DNS inbound server policies create forwarding addresses in a VPC so on-premises resolvers can forward GCP internal DNS queries to Cloud DNS over Interconnect or VPN.
Question 10: Which GCP resource hierarchy level should you use to apply spending budgets that cover multiple projects?
- Folder level
- Individual project level
- Billing account level (Correct answer)
- Organization level IAM
Correct answer: Billing account level
Budgets are attached to a billing account and can cover all projects linked to that account, or be scoped to specific projects, services, or labels.
Question 11: Which of the following BEST describes the principle of 'least privilege' as a professional engineering standard in cloud environments?
- Using a single shared service account across all applications to simplify management
- Granting all engineers administrator access for operational efficiency
- Assigning only the minimum permissions required for a role or service to perform its function (Correct answer)
- Restricting access to cloud resources only to the DevOps team
Correct answer: Assigning only the minimum permissions required for a role or service to perform its function
Least privilege limits the blast radius of compromised credentials or misconfigured services by ensuring identities have only the access they need.
Question 12: What is a GCP Commitment (CUD) applied to in terms of scope?
- A specific project
- A single VM instance
- A billing account across all projects
- A specific region and machine family (Correct answer)
Correct answer: A specific region and machine family
Committed Use Discounts are scoped to a specific region and machine family (e.g., N2 in us-central1), and the discount applies to any matching usage within that scope.
Question 13: For a latency-sensitive website, you wish to use GCP to run a single HTTP reverse proxy with caching. The CPU use for this specific reverse proxy is minimal. A 30-GB in-memory cache is desired, and an extra 2 GB of memory is required for the remaining processes. Cost savings are what you seek. How should this reverse proxy be used?
- Run it on Compute Engine, choose the instance type n1-standard-1, and add an SSD persistent disk of 32 GB
- Run it on Compute Engine, and choose a custom instance type with 6 vCPUs and 32 GB of memory (Correct answer)
- Package it in a container image, and run it on Kubernetes Engine, using n1-standard-32 instances as nodes
- Create a Cloud Memorystore for Redis instance with 32-GB capacity
Correct answer: Run it on Compute Engine, and choose a custom instance type with 6 vCPUs and 32 GB of memory
The application requires a 30 GB in-memory cache plus 2 GB for other processes, totaling 32 GB of memory, with minimal CPU usage. Running it on Compute Engine with a custom instance type allows for precise resource allocation, providing exactly 32 GB of memory and a minimal number of vCPUs (e.g., 6 vCPUs to ensure sufficient processing power for the proxy). This approach optimizes for cost savings by matching resources closely to the application's specific needs, avoiding the over-provisioning of predefined instance types.
Question 14: A healthcare cloud provider is assessed using HITRUST CSF. What is the primary advantage of HITRUST over using individual frameworks separately?
- It is mandated by the US federal government for all health IT
- It provides free annual audits for qualifying organizations
- It harmonizes multiple frameworks (HIPAA, NIST, ISO) into one unified control set (Correct answer)
- It replaces all other compliance requirements with a single audit
Correct answer: It harmonizes multiple frameworks (HIPAA, NIST, ISO) into one unified control set
HITRUST CSF consolidates requirements from HIPAA, NIST, ISO 27001, PCI DSS, and others into a single, mappable control framework, reducing audit duplication.
Question 15: A cloud engineer is presenting a disaster recovery plan to business stakeholders. Which element is most critical to include for business audiences?
- Recovery Time Objective (RTO) and Recovery Point Objective (RPO) in business terms (Correct answer)
- List of AWS services in the DR region
- Backup encryption algorithms used
- Detailed replication topology diagrams
Correct answer: Recovery Time Objective (RTO) and Recovery Point Objective (RPO) in business terms
RTO and RPO translate DR capability into business impact terms that executives can evaluate and approve.
Question 16: A GCP project contains a Cloud Run service that needs to read from a Firestore database. What is the most secure way to grant this access?
- Create a dedicated service account with only Firestore read permissions and assign it to the Cloud Run service (Correct answer)
- Grant the Cloud Run default service account the Project Owner role
- Store Firestore credentials in an environment variable
- Use a shared admin service account for all Cloud Run services
Correct answer: Create a dedicated service account with only Firestore read permissions and assign it to the Cloud Run service
Creating a dedicated, least-privilege service account for each service ensures that a compromise of one service does not expose permissions for others.
Question 17: Which VPC firewall rule component is used to apply the rule only to specific VM instances?
- Protocol and port
- Target tags or target service accounts (Correct answer)
- Priority value
- Source IP ranges
Correct answer: Target tags or target service accounts
Target tags (or target service accounts) on a firewall rule ensure it applies only to VM instances that carry the matching network tag or service account.
Question 18: What is the primary benefit of using custom machine types in Compute Engine?
- They allow you to specify exact vCPU and memory ratios to avoid paying for unused resources (Correct answer)
- They qualify for automatic Committed Use Discounts
- They provide faster network performance
- They support GPUs by default
Correct answer: They allow you to specify exact vCPU and memory ratios to avoid paying for unused resources
Custom machine types let you choose the exact number of vCPUs and amount of memory your workload needs, avoiding the waste of over-provisioning with fixed predefined machine types.
Question 19: A cloud engineer needs to process streaming IoT sensor data with sub-second latency. Which managed service is best suited for this use case on AWS?
- Amazon Kinesis Data Streams (Correct answer)
- AWS Batch
- Amazon SQS
- Amazon S3
Correct answer: Amazon Kinesis Data Streams
Amazon Kinesis Data Streams is purpose-built for real-time streaming data ingestion and processing with millisecond latency.
Question 20: What is the purpose of a quality audit in Cloud Engineer practice?
- To systematically evaluate processes against standards and identify improvement opportunities (Correct answer)
- To find fault with employees
- To reduce staffing
- To satisfy external requirements only
Correct answer: To systematically evaluate processes against standards and identify improvement opportunities
This is fundamental to Cloud Engineer practice. To systematically evaluate processes against standards and identify improvement opportunities represents the professional standard for quality in the Cloud Engineer certification framework.
Question 21: You are writing a custom metric in Cloud Monitoring. Which metric kind should you use if each data point represents an instantaneous measurement, such as current memory usage?
- DELTA
- CUMULATIVE
- DISTRIBUTION
- GAUGE (Correct answer)
Correct answer: GAUGE
A GAUGE metric kind represents an instantaneous value at a specific point in time, such as current CPU or memory usage.
Question 22: When should you use Workload Identity Federation instead of a service account key for external workloads?
- When the workload runs outside Google Cloud and you want keyless authentication (Correct answer)
- When you need to grant human users access
- When you want to disable multi-factor authentication
- When the workload runs inside Google Cloud
Correct answer: When the workload runs outside Google Cloud and you want keyless authentication
Workload Identity Federation allows external workloads (e.g., on AWS or on-premises) to authenticate to GCP without service account keys by exchanging short-lived credentials.
Question 23: What GCP feature lets you set maximum resource quotas per project to prevent runaway spend on services like Compute Engine or BigQuery?
- IAM deny policies
- Quotas and limits in the Cloud Console / API (Correct answer)
- Budget thresholds
- Org Policy constraints
Correct answer: Quotas and limits in the Cloud Console / API
GCP quotas (found in IAM & Admin > Quotas) cap the maximum number of resources a project can use, preventing runaway costs from misconfigured autoscaling or runaway queries.
Question 24: A video encoding pipeline on GCP uses Cloud Run to process uploads from Cloud Storage. During peak hours, unprocessed files accumulate for 2 hours. Cloud Run scales to max instances but CPU is only 40%. What is the bottleneck?
- Cloud Storage bucket is in a different region than Cloud Run
- Cloud Run max instances limit is reached
- The Cloud Storage trigger uses Pub/Sub, and the subscription's max outstanding messages limit is too low (Correct answer)
- The video codec library is single-threaded
Correct answer: The Cloud Storage trigger uses Pub/Sub, and the subscription's max outstanding messages limit is too low
Pub/Sub's max outstanding messages setting limits how many messages are delivered to subscribers concurrently; increasing it allows more Cloud Run instances to process files simultaneously.
Question 25: Which Google Cloud service provides a managed certificate authority for issuing private SSL/TLS certificates?
- Secret Manager
- Certificate Manager
- Cloud KMS
- Certificate Authority Service (CAS) (Correct answer)
Correct answer: Certificate Authority Service (CAS)
Certificate Authority Service (CAS) is a managed service that lets you create and manage private CAs for issuing internal TLS certificates.
Question 26: Which GCP tool provides budget alerts and can automatically cap spending by disabling billing on a project?
- Cloud Monitoring dashboards
- Cost table in the Billing console
- Cloud Billing budgets and alerts (Correct answer)
- Recommender API
Correct answer: Cloud Billing budgets and alerts
Cloud Billing budgets let you set a spending threshold and configure email alerts or Pub/Sub notifications; a billing account can also be programmatically disabled at threshold.
Question 27: Which GCP tool enables infrastructure provisioning using declarative configuration files, supporting version control and repeatable deployments?
- Cloud Scheduler
- Cloud Build
- Cloud Deployment Manager (Correct answer)
- Cloud Shell
Correct answer: Cloud Deployment Manager
Cloud Deployment Manager allows you to define GCP infrastructure in YAML or Python templates and manages the lifecycle of those resources declaratively.
Question 28: How do Cloud Engineer professionals transfer knowledge from training to practice?
- Training and practice are unrelated
- By passing the certification exam only
- Knowledge transfers automatically
- Through supervised practice, mentoring, gradual independence, and ongoing feedback (Correct answer)
Correct answer: Through supervised practice, mentoring, gradual independence, and ongoing feedback
This is fundamental to Cloud Engineer practice. Through supervised practice, mentoring, gradual independence, and ongoing feedback represents the professional standard for practical in the Cloud Engineer certification framework.
Question 29: A developer accidentally committed a service account key to a public GitHub repository. What is the FIRST action you should take?
- Delete the GitHub repository
- Notify the developer
- Revoke the service account's IAM roles
- Rotate the service account key immediately (Correct answer)
Correct answer: Rotate the service account key immediately
Rotating (or deleting) the exposed key immediately prevents unauthorized use, as the key may already be compromised the moment it was publicly accessible.
Question 30: Which Cloud Load Balancer type operates at Layer 7 and supports content-based routing (e.g., URL maps)?
- Internal TCP/UDP Load Balancer
- TCP Proxy Load Balancer
- External HTTP(S) Load Balancer (Correct answer)
- Network Passthrough Load Balancer
Correct answer: External HTTP(S) Load Balancer
The External HTTP(S) Load Balancer (Application Load Balancer) operates at Layer 7 and supports URL-based routing, host-based routing, and other HTTP-aware features.
Question 31: A company must comply with ITAR (International Traffic in Arms Regulations). What does this primarily restrict in cloud environments?
- Encryption strength of data at rest in government clouds
- Access to defense-related technical data by foreign nationals or non-US cloud regions (Correct answer)
- Transfer of financial data to countries with trade sanctions
- Use of open-source software in defense applications
Correct answer: Access to defense-related technical data by foreign nationals or non-US cloud regions
ITAR restricts the export of defense-related technical data, meaning it must only be accessible to US persons and stored in US-controlled cloud environments.
Question 32: What is the default maximum transmission unit (MTU) for a Google Cloud VPC network?
- 9000 bytes
- 1460 bytes (Correct answer)
- 1500 bytes
- 1400 bytes
Correct answer: 1460 bytes
Google Cloud VPC uses an MTU of 1460 bytes by default (not 1500) because of the 40-byte overhead used by GCP's encapsulation.
Question 33: Which control type is designed to detect risk events after they have occurred rather than prevent them?
- Deterrent control
- Preventive control
- Corrective control
- Detective control (Correct answer)
Correct answer: Detective control
Detective controls—such as CloudTrail logs and SIEM alerts—identify when a risk event has occurred so it can be investigated and remediated.
Question 34: Which label strategy is a best practice for enabling accurate cost allocation across teams in a large GCP organization?
- Use Cloud Monitoring tags instead of billing labels
- Rely on project names alone for cost tracking
- Use consistent resource labels (e.g., team, env, cost-center) on all billable resources (Correct answer)
- Apply labels only to VMs and Cloud Storage buckets
Correct answer: Use consistent resource labels (e.g., team, env, cost-center) on all billable resources
Consistent resource labels allow Cloud Billing reports to break down costs by dimensions like team, environment, or cost center, enabling granular showback and chargeback.
Question 35: Which technique uses probability distributions and thousands of simulated scenarios to model the range of possible financial outcomes from a cloud risk?
- Bowtie analysis
- Monte Carlo simulation (Correct answer)
- STRIDE modeling
- Delphi technique
Correct answer: Monte Carlo simulation
Monte Carlo simulation runs thousands of random iterations across probability distributions to produce a range of likely financial outcomes, supporting quantitative risk decisions.
Question 36: Which NIST document provides a risk management framework widely used for cloud environments in U.S. federal agencies?
- NIST CSF 2.0
- NIST SP 800-37 (RMF) (Correct answer)
- NIST SP 800-145
- NIST SP 800-53
Correct answer: NIST SP 800-37 (RMF)
NIST SP 800-37 defines the Risk Management Framework (RMF), a six-step process for selecting, implementing, and monitoring security controls.
Question 37: What is the main cost advantage of using Cloud Run over Compute Engine for stateless web workloads?
- Cloud Run VMs qualify for Sustained Use Discounts
- Cloud Run has lower network egress costs
- Cloud Run uses cheaper disk storage
- Cloud Run charges only for CPU and memory consumed during request processing, with no idle charges (Correct answer)
Correct answer: Cloud Run charges only for CPU and memory consumed during request processing, with no idle charges
Cloud Run scales to zero and charges only while actively handling requests, eliminating idle infrastructure costs that you'd pay for always-on Compute Engine VMs.
Question 38: A cloud team wants to reduce mean time to recovery (MTTR). Which evidence-based practice is most directly supported by incident post-mortem research?
- Mandating that all incidents be resolved within 30 minutes
- Implementing blameless post-mortems with documented action items and tracking their completion rate (Correct answer)
- Deploying more monitoring agents across all services
- Increasing the size of on-call rotations
Correct answer: Implementing blameless post-mortems with documented action items and tracking their completion rate
Research on high-performing engineering organizations consistently shows blameless post-mortems with tracked remediation items reduce MTTR over time.
Question 39: You need to expose a GKE service to the internet with a stable external IP address. Which Kubernetes service type should you use?
- ClusterIP
- NodePort
- LoadBalancer (Correct answer)
- ExternalName
Correct answer: LoadBalancer
A LoadBalancer service type provisions a Google Cloud external load balancer with a stable external IP for internet-facing traffic.
Question 40: Which Google Cloud networking product connects your on-premises network to GCP using a dedicated physical connection?
- Cloud VPN
- Direct Peering
- Cloud CDN
- Cloud Interconnect (Dedicated) (Correct answer)
Correct answer: Cloud Interconnect (Dedicated)
Dedicated Interconnect provides a direct physical connection between your on-premises network and Google's network, offering high bandwidth and low latency.
Question 41: What is the purpose of Cloud NAT in Google Cloud?
- Allow VMs without external IPs to access the internet for outbound traffic (Correct answer)
- Provide inbound internet access to VMs
- Route traffic between VPC networks
- Encrypt traffic between on-premises and GCP
Correct answer: Allow VMs without external IPs to access the internet for outbound traffic
Cloud NAT enables VMs without external IP addresses to initiate outbound connections to the internet, keeping them private while still allowing updates and API calls.
Question 42: A cloud engineer working in a regulated industry (e.g., healthcare) must ensure that all third-party cloud services used by their application have completed which assessment?
- A public code audit of the vendor's source code
- A performance benchmark comparing them to competitors
- A cost comparison validated by a financial auditor
- A vendor risk assessment and relevant compliance attestation (e.g., HIPAA BAA, SOC 2 Type II) (Correct answer)
Correct answer: A vendor risk assessment and relevant compliance attestation (e.g., HIPAA BAA, SOC 2 Type II)
Regulated industries require vendors to provide compliance attestations and signed agreements (like a HIPAA BAA) before processing protected data.
Question 43: A stakeholder escalates a complaint directly to the VP of Engineering about a cloud team's slow response. What is the appropriate first step for the team lead?
- Transfer the stakeholder to another team
- Acknowledge the escalation, investigate response time failures, and proactively close the feedback loop with the VP and stakeholder (Correct answer)
- Ignore the escalation and continue current work
- Blame the stakeholder for escalating
Correct answer: Acknowledge the escalation, investigate response time failures, and proactively close the feedback loop with the VP and stakeholder
Acknowledging escalations quickly and closing the loop with all parties restores trust and demonstrates accountability.
Question 44: In BigQuery, what is a partitioned table and what is its primary benefit?
- A table that streams data into separate shards automatically
- A table divided into segments based on a column value to reduce query cost and improve performance (Correct answer)
- A table split across multiple GCP regions for redundancy
- A table with row-level security applied per partition
Correct answer: A table divided into segments based on a column value to reduce query cost and improve performance
Partitioned tables divide data by a column (e.g., date) so queries that filter on that column scan only relevant partitions, reducing cost and latency.
Question 45: What Cloud Armor policy type protects against common web attacks like SQL injection and cross-site scripting?
- Rate-based rules
- WAF (Web Application Firewall) preconfigured rules (Correct answer)
- Adaptive Protection policy
- Custom IP allow/deny rules
Correct answer: WAF (Web Application Firewall) preconfigured rules
Cloud Armor includes preconfigured WAF rules based on OWASP ModSecurity Core Rule Set to block common web exploits like SQLi and XSS.
Question 46: A cloud engineer discovers that a critical security patch cannot be applied because it breaks a legacy application. The team documents the vulnerability and monitors it closely instead. This approach is an example of:
- Risk elimination
- Compensating control / risk acceptance with monitoring (Correct answer)
- Risk transference
- Risk avoidance
Correct answer: Compensating control / risk acceptance with monitoring
When patching isn't feasible, applying compensating controls and increasing monitoring is a structured form of informed risk acceptance.
Question 47: Which Cloud Monitoring feature allows you to verify that a publicly accessible URL returns a successful HTTP response at regular intervals?
- Synthetic monitor
- SLO alert
- Uptime check (Correct answer)
- Metric descriptor
Correct answer: Uptime check
Uptime checks periodically send requests to a specified URL or IP address and alert you when the endpoint is unreachable or returns an error.
Question 48: When publishing an internal research report on a cloud cost optimization experiment, which element most strengthens the report's credibility and reusability?
- Colorful charts and visualizations for executive presentations
- Executive summary endorsed by senior leadership
- Comparison to a competitor's publicly reported cloud spend
- A methodology section detailing data sources, collection period, tools used, exclusions, and assumptions (Correct answer)
Correct answer: A methodology section detailing data sources, collection period, tools used, exclusions, and assumptions
A detailed methodology section allows others to critique the approach, reproduce the analysis, and understand the conditions under which the findings apply.
Question 49: You need to schedule a lightweight script to run every 5 minutes without managing servers. Which service combination is most cost-effective?
- Cloud Scheduler triggering a Cloud Function (Correct answer)
- Compute Engine cron job
- Cloud Composer DAG
- GKE CronJob
Correct answer: Cloud Scheduler triggering a Cloud Function
Cloud Scheduler invoking a Cloud Function is serverless, scales to zero, and is cheapest for infrequent lightweight tasks.
Question 50: A cloud engineer notices that a service passes all unit tests but fails in production due to environment differences. What practice best addresses this?
- Increasing unit test count
- Disabling linting rules
- Using containerized test environments that mirror production (Correct answer)
- Running tests only on the main branch
Correct answer: Using containerized test environments that mirror production
Containerizing test environments with Docker ensures parity between test and production configurations.
Google Associate Cloud Engineer (ACE)
The Google Associate Cloud Engineer certification validates the ability to deploy applications, monitor operations, and manage enterprise solutions on Google Cloud Platform. It covers cloud infrastructure setup, solution planning and configuration, deployment, operations management, and access/security configuration.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds