Google ACE Deployment Practice Question
A company plans to deploy a containerized application on GKE Autopilot. They want to ensure high availability by running multiple replicas across different zones. They also need to expose the application via a load balancer with SSL termination. Which THREE resources should they create?
⚠ Common exam trap
The trap here is selecting StatefulSet instead of Deployment for stateless applications, or forgetting that Ingress is needed for SSL termination and external load balancing, while Service alone may not provide SSL termination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service
A Deployment (E) is the correct workload controller for a stateless containerized application, allowing the company to declare multiple replicas that GKE Autopilot spreads across zones for high availability. A Service (A) is required to provide a stable virtual IP and load-balance traffic to those pod replicas, and on GKE it also provisions the underlying Google Cloud load balancer. An Ingress (C) is needed to expose the application externally and to configure SSL/TLS termination using a managed certificate or a TLS secret, which is exactly the load-balancer-with-SSL requirement. A StatefulSet (B) is not appropriate because it is designed for stateful workloads needing stable network identities and persistent storage, which this stateless app does not require. A ConfigMap (D) only supplies non-sensitive configuration data and does not provide high availability, load balancing, or SSL termination.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Service
Why this is correct
A Service provides the stable virtual IP and load-balancing layer that distributes traffic across the application's pods, and it is the resource an Ingress or external load balancer targets for SSL termination, satisfying the exposure requirement in the stem.
- ✗
StatefulSet
Why it's wrong here
StatefulSet suits stateful workloads needing stable network identities and persistent per-pod storage, not stateless zone-spread replicas. It provides no load balancer or SSL termination. A Deployment with multiple replicas across zones, plus a Service and Ingress, meets the requirement.
- ✓
Ingress
Why this is correct
Ingress defines the HTTP(S) routing rules and provisions the Google Cloud external load balancer, with SSL termination configured via the associated managed certificate and TLS secret. It satisfies the requirement to expose the application through a load balancer performing SSL termination.
- ✗
ConfigMap
Why it's wrong here
A ConfigMap supplies non-confidential configuration data as key-value pairs to pods; it provides no replica scheduling, cross-zone distribution or load balancing with TLS termination. A Deployment, a Service of type LoadBalancer and a ManagedCertificate fulfil those requirements.
- ✓
Deployment
Why this is correct
A Deployment declares the desired replica count and pod template, and GKE Autopilot spreads those replicas across zones automatically, satisfying the high-availability constraint. It is the workload controller that manages the application's pods before a Service or Ingress exposes them.
Go deeper
Related to this question
Learn chapter
Packet Mirroring and Traffic Analysis
Key term
Ingress
Ingress is a Kubernetes API object that manages external access to services within a cluster, typically via HTTP or HTTPS routing rules.
Key term
Pod
A pod is the smallest deployable unit in Kubernetes, containing one or more containers that share storage, network, and a specification for how to run.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.