Courseiva

Google Associate Cloud Engineer (ACE) — Questions 751–775

775 questions total · 11pages · All types, answers revealed

Page 10

Page 11 of 11

751
MCQmedium

Refer to the exhibit. A team has this IAM policy on a Cloud Storage bucket. The bucket contains sensitive data. Which action should the team take immediately?

A.Add a condition to the objectViewer binding to restrict access.
B.Remove allUsers from the objectViewer binding.
C.Remove the entire objectViewer binding.
D.Change the objectViewer role to objectAdmin for allUsers.
AnswerB

Removing allUsers from the objectViewer binding is the precise and correct fix because it eliminates the special principal that grants anonymous public read access while leaving the binding intact for any other IAM members. After this change, only authenticated users or principals explicitly added to the bucket policy can access the objects. This directly aligns with the principle of least privilege and avoids affecting other legitimate permissions in the same binding.

Why this answer

The IAM policy grants `allUsers` (anyone on the internet) the `objectViewer` role on the bucket, which allows unauthenticated read access to all objects. Since the bucket contains sensitive data, this is a critical security exposure that must be removed immediately by deleting the `allUsers` principal from the binding.

Exam trap

Google Cloud often tests the misconception that adding conditions or changing roles can mitigate a public access exposure, when the correct immediate action is to remove the `allUsers` or `allAuthenticatedUsers` principal entirely.

How to eliminate wrong answers

Option A is wrong because adding a condition to the `objectViewer` binding does not address the core issue: `allUsers` still has public access. Conditions restrict access based on attributes (e.g., IP address), but they do not remove the fact that unauthenticated users can attempt to read objects. Option C is wrong because removing the entire `objectViewer` binding would also remove legitimate, authenticated users who need read access, which is overly destructive and not the immediate required action.

Option D is wrong because changing the role to `objectAdmin` for `allUsers` would escalate privileges, granting public users write and delete permissions on objects, making the security risk even worse.

752
MCQhard

A company has two on-premises data centers connected via a redundant network. They want to extend their Google Cloud VPC to on-premises using Cloud VPN with dynamic routing (BGP). They need to ensure traffic from on-premises to Google Cloud can fail over to the secondary tunnel if the primary tunnel fails. The VPC has a single region. What should they configure?

A.Use a single Cloud VPN gateway and create two tunnels to separate on-prem VPN devices, each with BGP.
B.Use Cloud Interconnect as the primary and Cloud VPN as the backup.
C.Use a Cloud Router in global dynamic routing mode and set up a single VPN tunnel with BGP.
D.Create two Cloud VPN gateways in the VPC, each with a BGP session to its own on-prem VPN device, both using the same Cloud Router with separate BGP sessions.
AnswerD

This is the correct high-availability Cloud VPN design. Two Cloud VPN gateways, each with its own BGP session to a distinct on-premises VPN device, and both sessions terminating on the same Cloud Router, provide automatic failover. When one gateway or tunnel fails, its BGP session is lost and the Cloud Router withdraws the advertised routes, while the other BGP session continues to propagate the same on-premises prefixes, so traffic switches to the healthy tunnel. Using a single Cloud Router with separate BGP sessions also lets you control traffic selection through BGP attributes like MED.

Why this answer

It provides true active/passive failover for on-premises to Google Cloud traffic. By creating two Cloud VPN gateways, each with a BGP session to its own on-premises VPN device, and attaching both sessions to the same Cloud Router, you enable BGP to advertise the same VPC prefixes over both tunnels. The Cloud Router uses BGP path selection (e.g., MED or AS path prepending) to prefer one tunnel as primary; if that tunnel fails, BGP withdraws the route and traffic automatically switches to the secondary tunnel.

This satisfies the requirement for failover without relying on a single gateway or tunnel.

Exam trap

The trap here is that candidates assume a single Cloud VPN gateway with multiple tunnels provides redundancy, but they overlook that the gateway itself is a single point of failure, which is why two separate gateways are required for true failover.

How to eliminate wrong answers

Option A is wrong because using a single Cloud VPN gateway creates a single point of failure; if the gateway itself fails, both tunnels become unavailable, preventing failover. Option B is wrong because Cloud Interconnect is a dedicated, high-bandwidth connection that does not support dynamic failover to Cloud VPN as a backup in the same way; the question specifically requires Cloud VPN with dynamic routing, not a hybrid interconnect/VPN design. Option C is wrong because a single VPN tunnel with BGP provides no redundancy; if the tunnel or its underlying network path fails, all traffic is lost, and global dynamic routing mode does not add failover capability.

753
MCQhard

You are planning a GCP network for a company with offices in three regions: `us-central1`, `europe-west1`, and `asia-east1`. All three regions must communicate with each other, and traffic must NOT traverse the public internet. Each region has its own subnet. Which network design achieves this with the least management overhead?

A.Create three separate VPCs (one per region) and connect them with VPC Network Peering.
B.Use a single global VPC with subnets in each region; traffic between subnets stays on Google's private network.
C.Set up Cloud VPN tunnels between each pair of regions.
D.Use Cloud Interconnect dedicated connections in each region and configure BGP routing between them.
AnswerB

A VPC network is a global resource; its subnets can be placed in any region. Instances in different regional subnets communicate using their internal IPv4 addresses, with traffic forwarding handled automatically by the VPC's dynamic routes. Because the underlying links between regions traverse Google's private backbone, this requires no VPNs, peering, or Interconnect attachments, giving low latency and no additional configuration.

Why this answer

A single global VPC allows you to create subnets in multiple regions, and traffic between those subnets stays on Google's private backbone network without traversing the public internet. This design requires no additional connectivity configuration, peering, or VPN tunnels, making it the simplest to manage while meeting all requirements.

Exam trap

The trap here is that candidates often overcomplicate the solution by thinking they need separate VPCs or VPNs for each region, not realizing that a single global VPC inherently supports multi-region subnets with private, Google-managed routing.

How to eliminate wrong answers

Option A is wrong because VPC Network Peering connects separate VPCs but requires explicit peering setup between each pair (three VPCs need three peering connections), and traffic still stays on Google's network, but the management overhead is higher than a single VPC. Option C is wrong because Cloud VPN tunnels require configuring and maintaining VPN gateways and tunnels between each region pair, adding complexity and potential latency, and traffic would traverse the public internet unless using HA VPN with Cloud Router, which still adds overhead. Option D is wrong because Cloud Interconnect is a dedicated physical connection to Google's network, which is overkill for this scenario—it requires on-premises infrastructure, BGP configuration, and is designed for hybrid cloud connectivity, not for inter-region communication within a single cloud environment.

754
MCQmedium

A security team wants to restrict access to a Google Cloud project such that only virtual machines with a specific tag 'web' can connect to a Compute Engine instance on port 443. Which configuration is required?

A.Create a firewall rule allowing egress from instances with tag 'web' to the target instance on port 443.
B.Create a firewall rule allowing ingress from instances with tag 'web' to the target instance on port 443.
C.Set an IAM condition on the instance to only allow calls from instances with tag 'web'.
D.Use Cloud Armor to filter traffic based on tags.
AnswerB

An ingress firewall rule applied to the target's VPC network can use source tags to restrict incoming traffic to only those instances bearing the 'web' tag. Since the rule's direction is ingress, it operates on traffic destined for the target instance on the specified port. This is the standard, supported method for tag-based network access control on Google Cloud.

Why this answer

Firewall rules in Google Cloud are stateful and control ingress traffic at the network level. To allow only VMs with tag 'web' to connect to the target instance on port 443, you must create an ingress firewall rule that specifies the source tag 'web', the target instance (or its network tag), and the protocol/port tcp:443. This rule permits incoming HTTPS traffic from any VM that has the 'web' tag, regardless of its IP address.

Exam trap

Google Cloud often tests the distinction between ingress and egress firewall rules, and the trap here is that candidates mistakenly choose an egress rule (Option A) because they think of restricting traffic 'from' the source, but the correct direction for controlling incoming connections to a target is ingress.

How to eliminate wrong answers

Option A is wrong because an egress firewall rule controls outbound traffic from the source, not inbound traffic to the target; the question requires restricting incoming connections to the target instance on port 443, which is an ingress direction. Option C is wrong because IAM conditions control identity-based access (who can perform actions on the instance), not network-level traffic filtering based on VM tags; tags are not evaluated in IAM policies for network access. Option D is wrong because Cloud Armor is a web application firewall (WAF) that protects against application-layer attacks and filters based on IP addresses, geographic regions, or custom rules, but it does not filter traffic based on Compute Engine instance tags.

755
MCQmedium

An application uses the S3-compatible API to interact with Cloud Storage. The team needs credentials compatible with HMAC-based S3 authentication. Which credential type does Cloud Storage support for this?

A.Service account JSON key file — it's compatible with the S3 HMAC authentication format
B.HMAC keys created for a service account in Cloud Storage settings
C.Cloud KMS symmetric keys configured for Cloud Storage access
D.An API key generated in the GCP Console for Cloud Storage
AnswerB

HMAC keys created for a service account in Cloud Storage settings are the correct mechanism for enabling S3-compatible API access to Cloud Storage. Each key gives an access key ID and a secret access key, which S3 SDKs and tools such as AWS CLI use to sign requests with HMAC-SHA1 or HMAC-SHA256. These keys are separate from OAuth 2.0 credentials, are scoped to the associated service account's permissions, and are explicitly designed for Google Cloud's XML API and S3 interoperability.

Why this answer

Cloud Storage supports HMAC keys for service accounts to provide S3-compatible authentication. These keys consist of an access key and a secret key, which are used to sign requests using the HMAC-SHA256 algorithm, matching the AWS S3 signature process. This allows applications using the S3 API to authenticate directly against Cloud Storage without needing a JSON key file or OAuth 2.0 tokens.

Exam trap

Google Cloud often tests the distinction between authentication methods (HMAC vs. OAuth 2.0) and encryption keys (KMS vs. HMAC), leading candidates to confuse a JSON key file or an API key with HMAC credentials.

How to eliminate wrong answers

Option A is wrong because a service account JSON key file is used for OAuth 2.0-based authentication, not for HMAC-based S3 authentication; it contains a private key for signing JWT tokens, not an HMAC access/secret key pair. Option C is wrong because Cloud KMS symmetric keys are used for encryption and decryption of data at rest, not for authentication or signing S3 API requests. Option D is wrong because an API key is a simple identifier used for quota and access control in GCP APIs, but it does not support the HMAC signing mechanism required for S3-compatible authentication.

756
MCQmedium

An engineer deployed a new version of their application on GKE using a Deployment. Users report that the new version has a bug. The engineer wants to quickly revert to the previous version. How can they achieve this?

A.Scale the deployment to zero and then scale back up
B.Run kubectl delete deployment and re-apply the old manifest
C.Run kubectl rollout undo deployment/<deployment-name>
D.Run kubectl rollout history deployment/<deployment-name>
AnswerC

`kubectl rollout undo deployment/<deployment-name>` instructs the Deployment controller to revert to the previous revision by restoring the prior Pod template and rolling it out with the same gradual scaling strategy—creating a new ReplicaSet while terminating the current one in a controlled fashion. This preserves availability because the controller scales up the new/old ReplicaSet before scaling down the current one. The command is the canonical, declarative way to undo a bad deployment with minimal downtime.

Why this answer

The `kubectl rollout undo` command is specifically designed to revert a Deployment to a previous revision. When you run `kubectl rollout undo deployment/<deployment-name>`, Kubernetes updates the Deployment's pod template to match the previous ReplicaSet, triggering a new rollout that restores the old version. This is the fastest and most reliable way to roll back a bad deployment.

Exam trap

ACE often tests the difference between `kubectl rollout undo` (which performs a rollback) and `kubectl rollout history` (which only shows revisions), causing candidates to confuse viewing history with reverting.

How to eliminate wrong answers

Option A is wrong because scaling to zero then back up does not change the pod template; it simply restarts the same (buggy) version, and scaling to zero causes downtime. Option B is wrong because deleting the Deployment removes its history and ReplicaSets, and re-applying the old manifest is manual, error-prone, and loses the rollout history. Option D is wrong because `kubectl rollout history` only displays the revision history; it does not perform any rollback action.

757
Multi-Selecthard

A company wants to organize their GCP resources into a hierarchy to separate development, staging, and production environments. Which THREE resources can be used to create this separation?

Select 3 answers
A.Folders
B.Organization node
C.Billing accounts
D.Projects
E.Labels
AnswersA, B, D

Folders are hierarchical containers that sit between the organization node and projects, allowing you to group projects based on business units, teams, or deployment stages (e.g., development, staging, production). As nodes in the resource hierarchy, folders inherit policies from the organization node and propagate their own IAM policies and resource constraints to all projects and folders underneath them, making them a correct and essential component for organizing GCP resources.

Why this answer

GCP resource hierarchy includes Organization, Folders, Projects, and Resources. Folders can be used to group projects (e.g., dev folder, prod folder). Projects are the containers for resources.

Labels are metadata tags but not part of the hierarchy. Billing accounts are separate from the hierarchy. IAM policy is not a resource for separation.

758
MCQeasy

A small team is setting up a new Google Cloud project for a web application. They need to ensure that they can manage costs and receive alerts when spending exceeds a threshold. What is the simplest way to achieve this?

A.Export billing data to BigQuery and create custom dashboards.
B.Use the Google Cloud Pricing Calculator to estimate costs and set manual alerts.
C.Create a billing account for each team member and link it to the project.
D.Set up a budget alert in the Google Cloud Console for the project.
AnswerD

Budget alerts in the Google Cloud Console monitor actual and forecast spend against a defined threshold and notify via Pub/Sub or email. This requires no custom tooling, satisfying the small team's need for the simplest cost-management and alerting mechanism.

Why this answer

Google Cloud budget alerts are configured directly in the Billing section of the Console, where you set a budget amount and threshold percentages (e.g., 50%, 90%, 100%) and attach email or Pub/Sub notifications. This requires no data export, no external tooling, and no per-user billing accounts, making it the simplest path to cost visibility and alerting. It satisfies the requirement with a few clicks and is the native, recommended approach.

Exam trap

ACE often tests the confusion between cost estimation tools (Pricing Calculator) and cost monitoring tools (budgets and alerts) — candidates pick the calculator thinking it enforces or alerts on spend, when it only forecasts.

How to eliminate wrong answers

Option A is wrong because exporting billing data to BigQuery and building dashboards is a heavyweight analytics solution that requires a dataset, scheduled exports, and BI tooling — it provides reporting, not the simplest alerting mechanism. Option B is wrong because the Pricing Calculator only estimates future costs; it has no runtime connection to actual spend and cannot generate alerts when real spending crosses a threshold. Option C is wrong because creating a billing account per team member fragments billing, complicates cost attribution, and does not by itself produce threshold alerts; a project links to one billing account, not many.

759
MCQeasy

You need to be notified when the CPU utilization of any Compute Engine instance in your project exceeds 80% for 5 minutes. Which Cloud Monitoring feature should you use?

A.Uptime check
B.Log-based alert
C.Metric threshold alerting policy
D.Dashboard
AnswerC

A metric threshold alerting policy is the native Cloud Monitoring mechanism for checking a numeric metric stream against a condition, such as compute.googleapis.com/instance/cpu/utilization being above 80% for 5 minutes. You configure an alignment period, aggregator, window, and threshold, then route the incident to notification channels like email, Pub/Sub, or mobile. This directly consumes the CPU utilization metric and triggers a notification only when the threshold condition is met.

Why this answer

Metric threshold alerting policies in Cloud Monitoring evaluate time-series data (such as compute.googleapis.com/instance/cpu/utilization) against a threshold condition over a defined duration. To alert when CPU exceeds 80% for 5 minutes, you create an alerting policy with a threshold condition on the CPU utilization metric and set the duration window to 5 minutes. This is the native mechanism for firing notifications based on metric values crossing thresholds.

Exam trap

The trap here is confusing monitoring features that sound similar — candidates often pick uptime checks or log-based alerts because they think 'notification' implies any alerting mechanism, missing that CPU utilization is a metric and requires a metric threshold policy.

How to eliminate wrong answers

Option A is wrong because uptime checks only verify endpoint availability (HTTP/TCP response) from multiple global locations and cannot evaluate CPU utilization metrics. Option B is wrong because log-based alerts fire on log entry patterns, not on numeric metric thresholds like CPU percentage. Option D is wrong because dashboards are visualization-only; they display charts but do not evaluate conditions or send notifications.

760
MCQhard

A security team wants to prevent every project in the organization from creating VM instances with external IP addresses — without requiring configuration in each individual project. What is the most scalable solution?

A.Create a firewall rule in every project blocking outbound traffic on port 80 and 443
B.Set the organization policy constraint compute.vmExternalIpAccess to Deny All at the organization level
C.Remove the Compute Engine Admin role from all project owners
D.Use Cloud Armor to block all traffic destined for public IPs in the organization
AnswerB

The compute.vmExternalIpAccess organization policy is a list constraint that governs whether VMs can be assigned external IP addresses. Setting it to 'Deny All' at the organization level means the policy inherits down to every project and future project, so no VM can ever get an ephemeral or static external IP. This is the correct, centralized, and scalable preventive control because it directly blocks the resource assignment at the API level, rather than reacting to traffic or permissions.

Why this answer

The organization policy constraint `compute.vmExternalIpAccess` can be applied at the organization level to deny all VM instances from having external IP addresses, enforcing this rule across all projects without per-project configuration. This is the most scalable approach as it uses Google Cloud's hierarchical policy engine to centrally control resource creation, overriding any project-level settings.

Exam trap

The trap here is that candidates confuse network-level controls (firewall rules, Cloud Armor) with resource-level policies (organization constraints), mistakenly thinking blocking traffic is equivalent to preventing IP assignment, when in fact the constraint operates at the IAM/resource creation layer.

How to eliminate wrong answers

Option A is wrong because firewall rules only control network traffic after a VM is created, not the assignment of external IP addresses during VM creation; blocking ports 80 and 443 does not prevent a VM from having an external IP, and traffic on other ports (e.g., SSH on port 22) would still be allowed. Option C is wrong because removing the Compute Engine Admin role from project owners does not prevent VMs from being created with external IPs by other users or service accounts, and it breaks legitimate administrative workflows without addressing the IP assignment policy. Option D is wrong because Cloud Armor is a web application firewall that protects against DDoS and application-layer attacks, not a tool to control whether VMs are assigned external IPs; it cannot block the creation of VMs with public IPs.

761
MCQeasy

A Cloud Shell user wants to persist Terraform state files across sessions. What is the best approach?

A.Store them in /tmp
B.Store them in a Cloud Storage bucket and mount via gcsfuse
C.Store them on the instance's local SSD
D.Store them in the home directory ($HOME)
AnswerD

The home directory ($HOME) in Cloud Shell is the designated persistent storage area, backed by a 5GB disk that survives across sessions and idle timeouts. Files saved there, including Terraform state files, are retained for later use and are protected from session cleanup. This makes $HOME the simplest and correct choice for persisting state in a personal Cloud Shell environment.

Why this answer

In Google Cloud Shell, the home directory ($HOME) is persistent across sessions, while other locations like /tmp are ephemeral and cleared when the session ends. Storing Terraform state files in $HOME ensures they persist and are available in subsequent Cloud Shell sessions without additional setup.

Exam trap

ACE often tests the difference between persistent and ephemeral storage in Cloud Shell, and candidates may choose Cloud Storage with gcsfuse thinking it's the 'cloud-native' answer, but the question asks for the best approach for a single user's persistence, which is $HOME.

How to eliminate wrong answers

Option A is wrong because /tmp is a temporary filesystem that is wiped when the Cloud Shell session terminates, so state files would be lost. Option B is wrong because while storing state in a Cloud Storage bucket is a best practice for team collaboration, mounting it via gcsfuse is not the recommended or simplest approach for persistence in Cloud Shell; gcsfuse has performance and consistency limitations. Option C is wrong because the instance's local SSD is ephemeral and not persistent across Cloud Shell sessions, which are themselves ephemeral VMs.

762
MCQmedium

An engineer is setting up Cloud Identity for a new domain. What is a prerequisite for creating a Cloud Identity account?

A.A G Suite account
B.A billing account
C.Domain verification
D.An existing Google Cloud project
AnswerC

Cloud Identity requires proof that you own the custom domain (e.g., @yourdomain.com) before it can create user accounts and manage access for that domain. You must add a unique verification code as a DNS TXT record, or follow the alternate HTML file method, to prove control of the domain. Without this step, Google cannot legally or technically assign identity administration to your domain.

Why this answer

Cloud Identity requires domain verification to prove ownership. This is done via DNS TXT record or other methods.

763
MCQhard

An e-commerce platform sees a 20x traffic spike every Black Friday. The rest of the year traffic is low and stable. The team wants to minimize costs during normal periods while handling the annual peak without manual intervention. Which architecture achieves this?

A.Pre-provision 20x capacity year-round to guarantee Black Friday performance
B.Managed instance group with autoscaling + scheduled scaling pre-warming before Black Friday
C.Deploy on Cloud SQL — it scales compute automatically for traffic spikes
D.Add 20 manual VMs on Black Friday and delete them afterward each year
AnswerB

A managed instance group (MIG) with autoscaling can scale out based on real-time load metrics such as CPU utilization or requests per second, automatically adding instances as demand rises. Adding a scheduled scaling policy that pre-warms capacity a few hours before Black Friday ensures the additional instances are fully initialized, warmed up, and ready to accept traffic before the spike hits, avoiding the latency and slow startup that could occur if scaling were purely reactive. Together these provide both proactive capacity for the expected surge and reactive scaling for any unexpected above-forecast demand, making this the correct solution.

Why this answer

It combines managed instance group autoscaling for normal low-cost operation with scheduled scaling to pre-warm capacity before the Black Friday spike, ensuring seamless handling of the 20x traffic surge without manual intervention. This approach uses the 'autoscaler' and 'scheduled scaling' features in Google Cloud to dynamically adjust resources based on load, while pre-warming prevents cold-start latency during the peak.

Exam trap

Google Cloud often tests the misconception that database services like Cloud SQL can automatically scale compute for traffic spikes, but in reality, Cloud SQL requires manual vertical scaling or read replicas and does not handle web-tier traffic spikes natively.

How to eliminate wrong answers

Option A is wrong because pre-provisioning 20x capacity year-round incurs massive unnecessary costs, violating the requirement to minimize costs during normal periods. Option C is wrong because Cloud SQL does not automatically scale compute resources for traffic spikes; it supports read replicas and vertical scaling but requires manual intervention or configuration changes, and it is a database service, not a compute solution for handling web traffic. Option D is wrong because manually adding and deleting 20 VMs each year introduces manual intervention and operational overhead, contradicting the requirement for no manual intervention, and does not provide automated scaling for the spike.

764
Multi-Selectmedium

Which TWO actions should a DevOps engineer take to reduce egress costs when transferring large amounts of data from Compute Engine to Cloud Storage in the same region?

Select 2 answers
A.Use internal IP addresses for the Compute Engine instances.
B.Use a regional Cloud Storage bucket in the same region as the instances.
C.Set up a VPN between the instances and Cloud Storage.
D.Use a multi-regional Cloud Storage bucket.
E.Configure a Cloud NAT gateway.
AnswersA, B

Assigning internal IP addresses to Compute Engine instances ensures that instance-to-instance traffic stays within Google's private VPC network, which is never billed as egress. Traffic between instances using external IPs, even in the same zone, incurs standard egress charges because it leaves the internal network. Internal IPs also eliminate the need for public IP addresses, reducing both cost and potential security exposure.

Why this answer

Using internal IP addresses for Compute Engine instances ensures that traffic to Cloud Storage stays within Google's internal network, avoiding internet egress charges. When instances communicate with Cloud Storage using external IPs, the traffic is routed over the public internet, incurring egress costs. Internal IPs keep the data transfer on Google's backbone, which is free for same-region transfers.

Exam trap

Google Cloud often tests the misconception that using a multi-regional bucket in the same region reduces costs, but the trap here is that multi-regional buckets incur higher egress charges due to replication across zones, and candidates may overlook that internal IPs are the key to avoiding internet egress fees.

765
MCQeasy

A developer wants to verify which IAM roles they currently have on a specific GCP project before requesting additional access. Which gcloud command lists the IAM policy for a project?

A.gcloud iam roles list --project=[PROJECT_ID]
B.gcloud projects get-iam-policy [PROJECT_ID]
C.gcloud auth list --project=[PROJECT_ID]
D.gcloud iam service-accounts get-iam-policy [PROJECT_ID]
AnswerB

`gcloud projects get-iam-policy [PROJECT_ID]` fetches the complete IAM policy object for the specified project, which is structured as a list of bindings where each binding maps one role to a set of members. The output includes the policy version, etag, and bindings, so you can see exactly which members are assigned each role (e.g., serviceAccount:..., user:...). This is the direct, correct way to query current member-role bindings on a project.

Why this answer

The correct command to retrieve the IAM policy for a GCP project is `gcloud projects get-iam-policy [PROJECT_ID]`. This command returns the complete IAM policy bindings (roles and members) for the specified project, allowing the developer to see which roles they currently have. It directly queries the Cloud Resource Manager API to fetch the project-level IAM policy.

Exam trap

Google Cloud often tests the distinction between listing roles (available role definitions) and getting the IAM policy (actual role bindings), so candidates mistakenly choose `gcloud iam roles list` thinking it shows their assigned roles.

How to eliminate wrong answers

Option A is wrong because `gcloud iam roles list` lists predefined or custom roles available in the organization or project, not the bindings of those roles to principals. Option C is wrong because `gcloud auth list` displays the currently active authenticated accounts and their status, not the IAM policy for a project. Option D is wrong because `gcloud iam service-accounts get-iam-policy` retrieves the IAM policy for a specific service account, not for the project itself.

766
MCQmedium

A team's CI/CD pipeline authenticates to GCP using Application Default Credentials (ADC). The pipeline runs on a GCE VM with a service account attached. Which credential source does the ADC use when running on a GCE VM?

A.The GOOGLE_APPLICATION_CREDENTIALS environment variable pointing to a JSON key file
B.The VM's attached service account credentials via the instance metadata server
C.The developer's personal Google account used during `gcloud auth login`
D.A randomly selected service account from the project's service accounts list
AnswerB

On a Compute Engine VM, Application Default Credentials automatically uses the service account that was attached to the instance at creation time by querying the instance metadata server at metadata.google.internal/computeMetadata/v1/instance/service-accounts/. The metadata server returns a short-lived OAuth 2.0 access token with scopes defined on the instance, eliminating the need for any downloaded key file on disk. The client libraries cache and refresh these tokens automatically, making this the default and most secure credential source in a GCE environment.

Why this answer

On a GCE VM, Application Default Credentials (ADC) automatically uses the credentials from the VM's attached service account by querying the instance metadata server at the link-local address 169.254.169.254. This is the default behavior when no environment variable or other credential source is explicitly configured, making option B correct.

Exam trap

Google Cloud often tests the misconception that ADC always requires an explicit credential file or that it uses the gcloud user login, when in fact on GCE VMs it transparently uses the attached service account via the metadata server.

How to eliminate wrong answers

Option A is wrong because the GOOGLE_APPLICATION_CREDENTIALS environment variable is a manual override that ADC checks first, but it is not the default source on a GCE VM; the question describes a pipeline running on a GCE VM with a service account attached, and ADC will use the metadata server unless that variable is set. Option C is wrong because a developer's personal Google account from `gcloud auth login` is used for user-level authentication in gcloud CLI, not for ADC on a VM; ADC on a GCE VM does not consult user credentials from gcloud. Option D is wrong because ADC does not randomly select a service account; it uses the specific service account attached to the VM instance, which is obtained from the instance metadata server, not from a project-wide list.

767
MCQhard

A team has a streaming pipeline built with Apache Beam that reads from Cloud Pub/Sub and writes transformed data to BigQuery. Which GCP service executes this pipeline with managed autoscaling?

A.Cloud Composer
B.Cloud Dataflow
C.Cloud Dataproc
D.Cloud Data Fusion
AnswerB

Cloud Dataflow is the correct choice because it is the fully managed, native execution engine for Apache Beam pipelines on Google Cloud. When you run a Beam pipeline with the Dataflow runner, the service automatically provisions and autoscales workers for both streaming and batch modes, providing unified semantics. It handles resource management, checkpointing, and exactly-once processing without requiring you to manage clusters.

Why this answer

Cloud Dataflow is the correct service because it is a fully managed, autoscaling service specifically designed to execute Apache Beam pipelines. It handles the reading from Cloud Pub/Sub and writing to BigQuery, automatically scaling worker resources based on the pipeline's processing demands.

Exam trap

The trap here is that candidates often confuse Cloud Dataproc (which runs Spark) with Cloud Dataflow (which runs Beam), not realizing that Beam pipelines require Dataflow for managed autoscaling, while Dataproc requires manual cluster sizing or separate autoscaling policies.

How to eliminate wrong answers

Option A is wrong because Cloud Composer is a managed workflow orchestration service based on Apache Airflow, not a stream processing engine; it can trigger Dataflow jobs but does not execute Beam pipelines directly. Option C is wrong because Cloud Dataproc is a managed Spark and Hadoop service that can run batch or stream processing but does not natively execute Apache Beam pipelines with managed autoscaling; it requires manual cluster management or separate autoscaling configuration. Option D is wrong because Cloud Data Fusion is a fully managed data integration service for building ETL/ELT pipelines using a visual interface, but it does not execute Apache Beam pipelines and does not provide managed autoscaling for Beam-based streaming jobs.

768
MCQmedium

An engineer wants to ensure that no one in their organization can create VMs with public IP addresses. Which Google Cloud tool should they use to enforce this restriction?

A.Organization policies
B.Labels
C.IAM roles
D.Quotas
AnswerA

Organization policies are the correct tool because they directly enforce restrictions on resource configurations across the entire hierarchy (folders and projects). For example, the compute.vmExternalIpAccess constraint can be set to only allow certain VMs to have external IPs, or require a dedicated VPC peering. They act as guardian rules that cannot be overridden by users without the necessary admin permissions.

Why this answer

Organization policies in Google Cloud are hierarchical constraints applied at the organization, folder, or project level that restrict what resources can be created or configured. The predefined constraint constraints/compute.vmExternalIpAccess can be set to deny, preventing any VM in the scope from receiving an external IP. This is enforced by the resource manager before the VM is created, making it the correct tool for a hard organizational restriction.

Exam trap

The trap is assuming IAM roles can enforce resource configuration restrictions — IAM controls who can act, not what configuration is allowed; that is the job of organization policies.

How to eliminate wrong answers

Option B is wrong because labels are metadata key-value pairs used for organization, billing, and filtering — they have no enforcement capability. Option C is wrong because IAM roles grant or deny permissions to identities, but they cannot express resource-level constraints like 'no external IPs'; a user with compute.instances.create could still create a VM with a public IP. Option D is wrong because quotas limit the quantity of resources (e.g., number of CPUs per region), not the configuration attributes of those resources.

769
MCQeasy

A new engineer needs to enable the Compute Engine API for a project using the gcloud command-line tool. Which command should they run?

A.gcloud compute enable-api
B.gcloud projects enable compute.googleapis.com
C.gcloud api enable compute
D.gcloud services enable compute.googleapis.com
AnswerD

The correct command is `gcloud services enable compute.googleapis.com`. The `gcloud services` group is the standard interface for enabling and disabling Google Cloud APIs, and `compute.googleapis.com` is the unique service name for Compute Engine. This command works asynchronously, so you can verify the operation with `gcloud services list --enabled` or the console. It requires the `serviceusage.services.enable` IAM permission on the project.

Why this answer

The correct command is 'gcloud services enable compute.googleapis.com' because the gcloud CLI uses the 'services' command group to manage API enablement, and the Compute Engine API is identified by its service name 'compute.googleapis.com'. This is the standard, documented syntax for enabling any Google Cloud API via gcloud.

Exam trap

ACE often tests the exact gcloud command syntax — candidates confuse the 'services' command group with 'compute' or 'api', or forget that the service name must be the full domain (compute.googleapis.com).

How to eliminate wrong answers

Option A is wrong because 'gcloud compute enable-api' is not a valid gcloud command — 'compute' is a command group for managing Compute Engine resources, not APIs. Option B is wrong because 'gcloud projects enable' is not a valid subcommand; project management uses 'gcloud projects' for create/delete/describe, not API enablement. Option C is wrong because 'gcloud api enable' is not a valid command group — the correct group is 'services'.

770
MCQmedium

A company wants to set up a cost-effective disaster recovery solution for a critical application running on Compute Engine. The primary region is us-east1. The recovery point objective (RPO) is 1 hour, and recovery time objective (RTO) is 4 hours. Which strategy is most cost-effective?

A.Regular backups to Cloud Storage with automated scripts to restore in a different region
B.Use managed instance groups in two regions with autoscaling
C.Cross-region replica of persistent disks using snapshot schedules every hour
D.Active-active multi-region deployment with HTTP load balancer
AnswerC

Snapshot schedules automatically take incremental persistent disk snapshots at defined intervals, providing a predictable hourly RPO while minimizing storage costs because only changed blocks are captured. These snapshots are a native Compute Engine feature and can be used to create new disks in a target region during failover, streamlining replication and restoration without custom code. This balance of cost, integration, and recoverability makes it the most practical, cost-effective DR choice.

Why this answer

The most cost-effective because it uses snapshot schedules to create cross-region replicas of persistent disks every hour, meeting the 1-hour RPO without requiring always-on compute resources. This approach minimizes costs by only storing incremental snapshots in Cloud Storage, while automated restore procedures can spin up instances in the secondary region within the 4-hour RTO.

Exam trap

Google Cloud often tests the misconception that active-active or multi-region instance groups are always the best for disaster recovery, but the trap here is that for cost-effectiveness with moderate RPO/RTO, a snapshot-based replication strategy is more appropriate than maintaining always-on infrastructure.

How to eliminate wrong answers

Option A is wrong because regular backups to Cloud Storage with automated scripts require manual or custom automation for restore, which can introduce delays and complexity, and the RTO of 4 hours may be exceeded if scripts fail or need debugging; also, backups are not inherently cross-region replicas, so additional configuration is needed to meet the RPO. Option B is wrong because managed instance groups in two regions with autoscaling keep compute resources running in both regions, incurring continuous costs for idle instances in the secondary region, which is not cost-effective for a disaster recovery solution that only needs to activate during failover. Option D is wrong because active-active multi-region deployment with HTTP load balancer requires always-on compute and networking resources in both regions, leading to higher operational costs than a standby or backup-based approach, and it is overkill for the given RPO and RTO requirements.

771
MCQhard

A regulated company requires a log of all actions taken by Google support engineers when they access customer GCP environments during support cases. Which Cloud Audit Log type captures this?

A.Admin Activity audit logs
B.Data Access audit logs with Google-initiated access filter
C.Access Transparency logs
D.System event audit logs with personnel filter
AnswerC

Access Transparency logs are a specialized Cloud Logging feature specifically designed to record metadata about actions performed by Google personnel when they access customer data and GCP environments. These logs capture the who, when, and why for Google support or engineering access, giving customers visibility and accountability for Google-side activities. Unlike other audit logs, Access Transparency is the only option that directly documents Google employee actions, and it is available in enabled organizations, often in conjunction with Assured Workloads.

Why this answer

Access Transparency logs are the correct choice because they specifically capture actions taken by Google support engineers when accessing customer data or configurations in GCP. These logs provide near real-time records of Google-initiated access, which is required for regulated companies to audit support personnel activities. Admin Activity logs only record administrative actions by customers, not Google personnel, while Data Access logs with Google-initiated access filter are not a valid log type in Cloud Audit Logs.

Exam trap

The trap here is that candidates confuse 'Data Access logs' with 'Access Transparency logs,' assuming a filter can isolate Google-initiated actions, but Access Transparency is a separate, dedicated log type specifically for Google personnel access, not a subset of Data Access logs.

How to eliminate wrong answers

Option A is wrong because Admin Activity audit logs record actions performed by customers or authorized users within a GCP project (e.g., creating resources), not actions taken by Google support engineers. Option B is wrong because Data Access logs capture API calls that read or modify customer data, but there is no 'Google-initiated access filter' as a distinct log type; Access Transparency logs are the dedicated mechanism for Google-initiated access. Option D is wrong because System event audit logs record GCP system events (e.g., VM live migrations), not personnel actions, and there is no 'personnel filter' in Cloud Audit Logs.

772
MCQmedium

You are deploying a new version of an application to a Google Kubernetes Engine (GKE) cluster. You want to ensure that the new version is rolled out gradually, and if any issues are detected, the rollout is automatically paused. You also want to be able to easily roll back to the previous version. Which GKE feature should you use?

A.Use a StatefulSet with pod management policy set to Parallel.
B.Configure a Kubernetes Deployment with a rolling update strategy and set maxSurge and maxUnavailable parameters.
C.Create a DaemonSet to ensure the new version runs on all nodes.
D.Use a ReplicaSet with a custom controller to manage the rollout.
AnswerB

A Kubernetes Deployment with a rolling update strategy allows you to gradually replace pods with the new version. By setting maxSurge and maxUnavailable, you control the pace and availability. If issues arise, you can pause the rollout and roll back using kubectl rollout undo. This meets all requirements: gradual rollout, automatic pause on issues (via readiness probes), and easy rollback.

Why this answer

A Kubernetes Deployment with a rolling update strategy is designed for gradual rollouts, supports pausing and resuming, and allows easy rollback to previous versions. It uses ReplicaSets under the hood and provides declarative updates. The other options are either for different use cases (StatefulSet, DaemonSet) or lack native rollout control (ReplicaSet).

Exam trap

The trap here is confusing a ReplicaSet with a Deployment; while a ReplicaSet maintains pod count, only a Deployment provides rolling update and rollback orchestration.

773
MCQmedium

A company wants to run a stateless HTTP web application that experiences highly variable traffic, including periods of zero traffic. The application is packaged as a Docker container. The team wants to minimize operational overhead and pay only for resources consumed during request processing. Which Google Cloud compute service is the best fit?

A.Cloud Functions
B.Cloud Run
C.GKE Standard
D.Compute Engine with managed instance group
AnswerB

Cloud Run is Google Cloud's fully managed serverless container platform that executes stateless containers on a Knative-based infrastructure, making it ideal for an HTTP web application. It automatically scales to zero when there is no traffic, so you pay nothing during idle periods, and it scales up to thousands of concurrent instances based on incoming requests, with per-request billing that only charges from the moment a request starts to when it finishes. Cloud Run supports any OCI-container image, meaning you can package a web server (e.g., Nginx, Express, Django) and it will handle TLS certificates, domain mapping, and load balancing natively. For variable traffic patterns of a stateless HTTP app, Cloud Run offers the perfect balance of elasticity, cost-efficiency, and operational simplicity.

Why this answer

Cloud Run is serverless, scales to zero, charges per request, and runs containers from container images. Cloud Functions is for event-driven functions, not full web apps. GKE Standard and Compute Engine require managing servers and do not scale to zero.

774
Drag & Dropmedium

Arrange the steps to create a Cloud Pub/Sub topic, subscription, and publish a message.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence ensures the topic and subscription exist before any messages are published, and messages are retrieved only after they have been published. This order prevents errors and message loss in Google Cloud Pub/Sub.

775
MCQhard

A team is designing a data pipeline: Cloud Storage → Pub/Sub → Dataflow → BigQuery. They expect 50 GB of data per hour. Dataflow jobs must automatically scale workers based on pipeline backlog. Which Dataflow feature provides automatic horizontal scaling of worker VMs?

A.Vertical scaling — Dataflow automatically increases worker machine types under load
B.Dataflow Horizontal Autoscaling — automatically adds/removes workers based on pipeline lag
C.GKE cluster autoscaler — Dataflow runs on GKE and inherits its autoscaling
D.Cloud Monitoring alerting policy that triggers worker additions via gcloud
AnswerB

Horizontal autoscaling dynamically adds or removes worker VMs by evaluating pipeline lag, so throughput tracks the 50 GB per hour backlog without manual intervention. This satisfies the stated requirement that Dataflow jobs scale workers automatically based on backlog.

Why this answer

Dataflow Horizontal Autoscaling is the correct feature because it automatically adds or removes worker VMs based on the pipeline's backlog (lag), which directly matches the requirement for automatic horizontal scaling. This feature uses the Cloud Monitoring service to track the number of unprocessed elements and adjusts worker count accordingly, ensuring efficient resource usage without manual intervention.

Exam trap

Google Cloud often tests the distinction between horizontal and vertical scaling, and candidates may confuse Dataflow's autoscaling with GKE cluster autoscaler, not realizing Dataflow manages its own worker fleet independently of GKE.

How to eliminate wrong answers

Option A is wrong because vertical scaling increases the machine type (e.g., more vCPUs or memory) of existing workers, not the number of workers, and Dataflow does not automatically change machine types under load; it relies on horizontal scaling. Option C is wrong because Dataflow does not run on GKE by default; it uses its own managed service for worker VMs, and the GKE cluster autoscaler is irrelevant unless the pipeline is explicitly configured to run on a GKE cluster, which is not the standard deployment. Option D is wrong because while Cloud Monitoring can trigger alerts, it does not directly add workers; Dataflow Horizontal Autoscaling is the built-in mechanism that handles scaling automatically, and using a custom alerting policy to invoke gcloud commands would be an external, non-native approach that contradicts the requirement for automatic scaling.

Page 10

Page 11 of 11

All pages