Courseiva

Google ACE Deploying and Implementing a Cloud Solution Practice Question

A developer needs to SSH into a Compute Engine instance that has OS Login enabled. The developer's Google account is already granted the roles/compute.osLogin role. Which command should the developer use to connect?

⚠ Common exam trap

ACE often tests the misconception that OS Login still requires a manual SSH key file — candidates pick the ssh -i option because it looks like the 'standard' SSH command, but OS Login specifically replaces that workflow with identity-based gcloud authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

gcloud compute ssh instance-name --zone=us-central1-a

With OS Login enabled and the roles/compute.osLogin role granted, the developer should connect using gcloud compute ssh, which automatically handles OS Login authentication and key management. The gcloud compute ssh command integrates with OS Login to generate short-lived SSH certificates and manage the developer's Google identity, so no manual key file is needed. Specifying the zone ensures the command targets the correct instance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ssh -i ~/.ssh/google_key user@instance-ip

    Why it's wrong here

    While possible, the recommended method with OS Login is gcloud compute ssh.

  • ✓

    gcloud compute ssh instance-name --zone=us-central1-a

    Why this is correct

    With OS Login enabled and roles/compute.osLogin granted, gcloud compute ssh authenticates using the Google account and manages SSH keys through OS Login, so no manual key setup is needed. This satisfies the scenario by connecting the developer to the instance in the specified zone.

  • ✗

    gcloud compute instances get-serial-port-output instance-name --zone=us-central1-a

    Why it's wrong here

    This command retrieves serial console output, which is diagnostic logging, not an interactive shell. With OS Login and roles/compute.osLogin granted, the developer should run gcloud compute ssh, which maps the Google identity to a POSIX account. Serial-port output suits boot troubleshooting.

  • ✗

    gcloud compute connect-to-serial-port instance-name --zone=us-central1-a

    Why it's wrong here

    Serial console access bypasses SSH entirely, providing out-of-band console login rather than the SSH session OS Login governs; it is tempting as the recovery route when SSH or networking fails, but here the developer holds roles/compute.osLogin and needs gcloud compute ssh, which authenticates via OS Login.

About these practice questions

This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.