Reinforce ACE concepts with active-recall study cards covering all 5 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For ACE preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the ACE question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your ACE flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real ACE exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass ACE.
Sample cards from the ACE flashcard bank. Read the question, think of the answer, then read the explanation below.
You have a managed instance group (MIG) with instances that need to run a startup script to configure monitoring agents. You created the instance template without a startup script. Which action should you take to add the startup script?
Create a new instance template with the startup script, then update the MIG to use the new template via a rolling update.
Instance templates are immutable; you cannot modify them. You must create a new instance template with the startup script and update the MIG to use it via rolling update or by setting the template.
You deployed a Cloud Run service with gcloud run deploy --image gcr.io/my-project/my-image --platform managed --region us-central1 --allow-unauthenticated. Users report intermittent 503 errors. What is the most likely cause?
The service is hitting the maximum number of concurrent requests per container instance (default 80) and needs more instances.
Cloud Run scales based on concurrent requests per container instance, with a default concurrency limit of 80. When a container instance reaches this limit, additional requests are queued or rejected; if the service cannot scale out fast enough (e.g., due to cold starts or instance limits), users experience intermittent 503 errors. The most likely cause is that the service is hitting this concurrency limit and needs more instances or a higher concurrency setting.
A new engineer needs to set up the gcloud CLI on their local machine and authenticate with a user account. Which command should they run after installing the SDK?
gcloud init
The 'gcloud init' command is the standard way to initialize the gcloud CLI, authenticate with a user account, set the default project, and configure other initial settings. It walks the user through the authentication flow and sets up the local configuration for subsequent gcloud commands.
A startup wants to create a new GCP project for development. They've already created a billing account. Which command can they use to create the project?
gcloud projects create PROJECT_ID
The 'gcloud projects create' command creates a new project. The billing association is separate, but the project can be created without billing immediately.
An organization wants to enforce a policy that disables the creation of VMs with external IPs across all projects. Which resource hierarchy level should the policy be attached to for maximum coverage?
Organization
To enforce a policy across all projects, the policy must be attached at the highest level in the resource hierarchy: the organization. Organization policies are inherited by all descendant resources (folders, projects, and VMs), ensuring uniform enforcement. Attaching at lower levels would not cover all projects unless applied individually, which is inefficient and error-prone.
A company is migrating a legacy monolithic application to Google Cloud. The application has unpredictable traffic patterns and long-running connections. The team wants to minimize operational overhead and only pay for resources when the application is processing requests. Which compute option should they choose?
Cloud Run
Cloud Run is a fully managed serverless container platform that scales to zero when idle and bills only for actual request processing time (down to 100ms granularity). It handles unpredictable traffic and long-running HTTP/gRPC connections natively, with no cluster or node management. This matches the requirements of minimal operational overhead and pay-per-use.
An engineer needs to create a Cloud Storage bucket for storing archival data that will be accessed less than once a year. The data must be stored durably and cost-effectively. Which storage class should the engineer use?
Archive
Archive is the correct choice because it is Google Cloud's lowest-cost storage class, designed for data accessed less than once per year. It offers the same 99.999999999% (11 nines) durability as other Cloud Storage classes, so the archival data remains highly durable. Its retrieval costs and minimum storage duration (365 days) align with the infrequent access pattern, making it the most cost-effective option for this use case.
You need to monitor the uptime of an external HTTPS endpoint that is critical to your application. Which Google Cloud service should you use to create an uptime check?
Cloud Monitoring
Cloud Monitoring provides uptime checks that can monitor HTTP, HTTPS, and TCP endpoints from multiple locations.
You have a Compute Engine VM instance that is currently running. You need to resize it to a different machine type. What must you do first?
Stop the instance, then use gcloud compute instances set-machine-type, then start the instance.
Changing the machine type requires the VM to be in a stopped state. You must stop the instance, change the machine type, then start it.
Your GKE cluster is running a deployment with a container image my-app:v1. You need to update it to my-app:v2 and monitor the rollout progress. Which commands should you use?
kubectl set image deployment/my-app my-app=my-app:v2 followed by kubectl rollout status deployment/my-app
The correct approach uses `kubectl set image` to declaratively update the container image in the deployment, which triggers a rolling update, followed by `kubectl rollout status` to watch the rollout progress until completion. This is the standard Kubernetes-native workflow for image updates and monitoring.
You need to export logs from Cloud Logging to a BigQuery dataset for long-term analysis. What should you create?
A log sink with BigQuery as the destination
To export logs from Cloud Logging to BigQuery, you create a log sink with BigQuery as the destination. Log sinks are the mechanism in Google Cloud for routing log entries to supported destinations, including BigQuery, Cloud Storage, and Pub/Sub. This allows for long-term storage and analysis.
You are using Cloud Run and want to split traffic so that 10% of requests go to revision v2 and 90% go to revision v1. Which command should you use?
gcloud run services update-traffic --to-revisions v1=90,v2=10
The correct command to split traffic between Cloud Run revisions is `gcloud run services update-traffic` with the `--to-revisions` flag, specifying the revision names and percentages. This command updates the traffic allocation for a service. The syntax `--to-revisions v1=90,v2=10` correctly assigns 90% to v1 and 10% to v2.
A security team wants to ensure that all Compute Engine instances in a project automatically use a custom service account with minimal permissions. What must the engineer do when creating new instances?
Use gcloud compute instances create with the --service-account flag pointing to the custom service account.
The --service-account flag on gcloud compute instances create explicitly attaches the specified custom service account to the new instance at creation time, ensuring the VM uses minimal-permission credentials instead of the default Compute Engine service account. This is the correct declarative way to enforce per-instance identity in GCP.
An engineer needs to view the current IAM policy for a project in JSON format. Which gcloud command should they use?
gcloud projects get-iam-policy PROJECT_ID --format json
The `gcloud projects get-iam-policy` command retrieves the IAM policy attached to a project and returns it in the requested format. Adding `--format json` outputs the policy as a JSON document, which is exactly what the engineer needs. This is the standard read-only command for inspecting project-level IAM bindings.
A developer created a service account with the roles/storage.admin role and wants to use it from a Compute Engine instance without downloading a key file. What is the best practice?
Attach the service account to the instance using the --service-account flag when creating the instance.
The best practice is to attach the service account to the Compute Engine instance at creation time using the --service-account flag. This allows the instance to automatically obtain credentials via the metadata server, avoiding the need to download and manage a service account key file. Downloading keys should be avoided due to security risks.
The ACE flashcard bank covers all 5 official blueprint domains published by Google Cloud. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Deploying and Implementing a Cloud Solution
Setting Up a Cloud Solution Environment
Planning and Configuring a Cloud Solution
Ensuring Successful Operation of a Cloud Solution
Configuring Access and Security
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that ACE questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.ACE questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective ACE study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free ACE flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 775+ original ACE flashcards across all 5 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official Google Cloud exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official ACE exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included