Courseiva

Google Associate Cloud Engineer (ACE) — Questions 376–450

775 questions total · 11pages · All types, answers revealed

Page 5

Page 6 of 11

Page 7
376
MCQmedium

An engineer wants to view the current IAM policy for a project in JSON format. Which command should they use?

A.gcloud resource-manager folders get-iam-policy my-project --format json
B.gcloud projects describe my-project --format json
C.gcloud projects get-iam-policy my-project --format json
D.gcloud iam policies get my-project --format json
AnswerC

This is the exact, valid CLI command for retrieving a project's IAM policy. The subcommand get-iam-policy reads the IAM policy bound to the specified project resource, and --format json renders it as a JSON array of bindings, including roles, members, and conditions. It is the correct tool for this task.

Why this answer

The command 'gcloud projects get-iam-policy my-project --format json' retrieves the IAM policy bound to a project and outputs it in JSON. This is the correct gcloud command for viewing a project's IAM policy, which lists bindings between members and roles. The --format json flag ensures machine-readable JSON output.

Exam trap

The trap is confusing project metadata retrieval (describe) with IAM policy retrieval (get-iam-policy), or assuming a generic 'iam policies get' command exists — ACE tests precise command syntax and resource scope.

How to eliminate wrong answers

Option A is wrong because 'gcloud resource-manager folders get-iam-policy' operates on folders, not projects, and 'my-project' is a project ID — the command would fail or target the wrong resource hierarchy level. Option B is wrong because 'gcloud projects describe' returns project metadata (name, ID, number, lifecycle state), not the IAM policy. Option D is wrong because 'gcloud iam policies get' is not a valid gcloud command — IAM policies are retrieved via resource-specific get-iam-policy commands, not a generic iam policies get.

377
MCQmedium

An engineer needs to grant an external auditor read-only access to view IAM policies on a GCP project. The auditor should not have access to any other resources. Which IAM role should be assigned?

A.roles/iam.roleAdmin
B.roles/iam.serviceAccountAdmin
C.roles/viewer
D.roles/iam.securityReviewer
AnswerD

roles/iam.securityReviewer is the correct choice because it grants permission to view IAM policies (for example, 'getIamPolicy') across all resources without allowing any modifications. It also includes permissions to list and get roles, which is exactly what an external auditor needs to review access configuration. This role aligns with least privilege for a read-only audit.

Why this answer

The `roles/iam.securityReviewer` role grants permission to view IAM policies without granting access to other resources. It is specifically designed for security auditors.

378
MCQmedium

You need to export all Cloud Logging logs from your project to BigQuery for long-term analysis. What should you create?

A.A Cloud Monitoring dashboard
B.A VPC flow log
C.A log-based alert
D.A log sink with destination BigQuery
AnswerD

A log sink in Cloud Logging's Router exports matching log entries to a destination such as BigQuery, Cloud Storage, or Pub/Sub. By configuring a sink with BigQuery as the destination and a filter that matches all logs (or empty filter), you continuously export your project's logs to a BigQuery dataset for analysis and long-term retention. This is the standard and only fully supported mechanism for exporting Cloud Logging logs to external services.

Why this answer

Log sinks route logs to supported destinations including BigQuery.

379
MCQeasy

A company wants to migrate a monolithic application to Google Cloud with minimal changes to the application code. Which compute option is most suitable?

A.Google Kubernetes Engine
B.App Engine (Flexible Environment)
C.Compute Engine
D.Cloud Functions
AnswerC

Compute Engine offers Infrastructure-as-a-Service virtual machines in which you select the OS, disk, and networking settings, allowing you to upload a disk image or reinstall the application directly. This 'lift-and-shift' approach preserves the existing architecture, libraries, and configuration with minimal or no code changes, making it the fastest and lowest-effort migration path for a monolithic application. It also provides full administrative control over the environment, letting you manage updates, security, and scaling in a familiar way.

Why this answer

Compute Engine (C) is the most suitable option because it provides Infrastructure as a Service (IaaS) virtual machines that can run the monolithic application with minimal code changes. The application can be migrated by simply lifting and shifting the existing VM or container image to a Compute Engine instance, preserving the OS, runtime, and dependencies without refactoring.

Exam trap

Google Cloud often tests the misconception that 'containerization always means minimal changes,' but the trap here is that GKE and App Engine Flexible Environment still require containerization and potential code adjustments, while Compute Engine allows a true lift-and-shift with zero code changes.

How to eliminate wrong answers

Option A is wrong because Google Kubernetes Engine (GKE) requires containerizing the application and often involves refactoring to fit a microservices architecture, which contradicts the 'minimal changes' requirement. Option B is wrong because App Engine Flexible Environment requires the application to be packaged as a container and adhere to specific runtime constraints, such as handling scaling and health checks, which may necessitate code modifications. Option D is wrong because Cloud Functions is a serverless, event-driven compute service that enforces a stateless, short-lived execution model, which is incompatible with a monolithic application's long-running processes and stateful behavior.

380
MCQmedium

Your company runs a data processing pipeline on Cloud Dataproc. The pipeline reads data from Cloud Storage, processes it with Spark, and writes results to BigQuery. Recently, the pipeline has been failing with errors indicating insufficient disk space on the worker nodes. The cluster is configured with standard worker nodes with 100 GB of standard persistent disk. The data size being processed has grown from 50 GB to 150 GB. What is the most cost-effective way to resolve the disk space issue?

A.Increase the size of the persistent disks on the worker nodes to 200 GB.
B.Use local SSDs instead of persistent disks for temporary storage.
C.Enable automatic disk resizing for the cluster.
D.Increase the number of worker nodes in the cluster.
AnswerC

Enabling automatic disk resizing on the node pool lets GKE monitor persistent-disk usage and grow the disk capacity in real time when utilization crosses a threshold, up to a configurable maximum. This keeps worker nodes operational during data spikes without human intervention, and because the disk only grows when needed, you avoid paying for unused space. It is the correct balance of resilience and cost management for a pipeline with variable data volume.

Why this answer

Cloud Dataproc's automatic disk resizing feature dynamically increases the size of persistent disks on worker nodes when disk usage exceeds a threshold (default 90%). This resolves the insufficient disk space issue without manual intervention or additional cost for unused capacity, making it the most cost-effective solution for handling the increased data volume from 50 GB to 150 GB.

Exam trap

Google Cloud often tests the misconception that adding more nodes (scaling out) is the default solution for storage issues, but the trap here is that the problem is disk space per node, not cluster capacity, making automatic disk resizing the most cost-effective and operationally efficient fix.

How to eliminate wrong answers

Option A is wrong because increasing persistent disks to 200 GB incurs ongoing costs for the full provisioned size, even if only a portion is used, and is less cost-effective than automatic resizing which only grows disks as needed. Option B is wrong because local SSDs provide temporary, non-persistent storage that is lost on VM termination and cannot be used for the pipeline's intermediate data if it must survive restarts or failures; additionally, local SSDs are more expensive per GB than persistent disks and require manual configuration. Option D is wrong because adding more worker nodes increases the total disk capacity but also increases compute costs unnecessarily; the issue is disk space per node, not insufficient nodes, and scaling out does not address the root cause of insufficient local storage on existing nodes.

381
MCQmedium

You are investigating high latency in your application deployed on Compute Engine. You suspect a specific API call is taking longer than expected. Which Google Cloud tool should you use to analyze the latency of individual requests?

A.Cloud Debugger
B.Cloud Trace
C.Cloud Monitoring dashboards
D.Cloud Logging log explorer
AnswerB

Cloud Trace is a distributed tracing service designed to collect latency data from Google Cloud and measure time spent in each service and API call during a request. It provides detailed per-request traces with spans that show the timing of each operation, making it the correct tool to investigate high application latency. By analyzing the waterfall view of spans, you can identify the exact component responsible for the delay across distributed services.

Why this answer

Cloud Trace provides distributed tracing, allowing you to see the latency of individual requests and identify bottlenecks. It captures trace spans from supported frameworks and services.

382
MCQmedium

An organization wants to deploy a containerized web application on GKE. They need the application to be accessible from the internet via a stable IP address. Which service type should they use when exposing the deployment?

A.ClusterIP
B.LoadBalancer
C.NodePort
D.ExternalName
AnswerB

A LoadBalancer Service is the appropriate choice for a containerized web application that needs a stable external IP. When you create this Service on Google Kubernetes Engine, the cloud-controller-manager automatically provisions a Google Cloud (TCP/UDP) load balancer and assigns a regional static external IP address. This gives clients a stable, publicly reachable endpoint, which precisely matches the requirement for an internet-facing web application.

Why this answer

A LoadBalancer service type provisions a Google Cloud TCP/UDP Load Balancer and assigns a stable external IP address. NodePort exposes on a high port but requires manual setup; ClusterIP is internal only.

383
MCQhard

A security team discovers that a service account key was accidentally committed to a public GitHub repository 48 hours ago. What should be the immediate steps to remediate this incident?

A.Rotate the service account key to generate a new one, keeping the old key active briefly for transition
B.Delete the leaked key immediately, audit Cloud Audit Logs for unauthorized activity using the key, then create a new key or switch to keyless authentication
C.Change the service account's display name and email to invalidate the leaked key
D.Remove all IAM roles from the service account to deny all actions until the investigation completes
AnswerB

Deleting the compromised service account key immediately revokes the attacker's primary authentication credential, effectively cutting off their direct API access through that key. After deletion, audit Cloud Audit Logs—specifically the Data Access and Admin Activity logs—to determine whether the key was used to call any GCP APIs, identify the scope of exposure, and check for unusual patterns such as token creation or IAM changes. Then issue a new key if the workload still requires a long-lived credential, or better, eliminate static keys entirely by adopting keyless authentication such as Workload Identity Federation, which binds short-lived credentials to the workload's identity.

Why this answer

The immediate priority is to revoke the compromised key's access by deleting it, which invalidates it instantly. Auditing Cloud Audit Logs is essential to detect any unauthorized usage that occurred during the 48-hour exposure window. Finally, creating a new key or switching to keyless authentication (e.g., workload identity federation) restores secure access without relying on long-lived static credentials.

Exam trap

Google Cloud often tests the misconception that rotating a key (generating a new one while keeping the old active) is sufficient, but the trap is that the old key remains valid and must be explicitly deleted to fully remediate a public leak.

How to eliminate wrong answers

Option A is wrong because rotating the key while keeping the old key active briefly violates the principle of least privilege and leaves a window for attackers to continue using the leaked credential. Option C is wrong because changing the service account's display name or email does not invalidate the existing key; keys are tied to the service account's unique ID and remain valid until explicitly deleted or disabled. Option D is wrong because removing all IAM roles from the service account is an overly broad action that could break legitimate services, and it does not immediately revoke the leaked key's ability to authenticate; the key itself remains valid until deleted.

384
MCQeasy

A company has a Compute Engine instance that needs to read files from a Cloud Storage bucket. The instance is running a custom application. What is the recommended way to grant the instance access to the bucket?

A.Generate a signed URL for the bucket and embed it in the application.
B.Create a service account with Storage Object Viewer role and associate it with the instance.
C.Use the default Compute Engine service account with Storage Admin role.
D.Store the bucket credentials in the instance metadata.
AnswerB

Associating a purpose-built service account with the instance is the Google-recommended pattern for granting cloud resources to a VM. Granting the Storage Object Viewer role (roles/storage.objectViewer) provides read-only access to objects without allowing writes or deletions, aligning with least privilege. The Compute Engine metadata server automatically supplies short-lived OAuth tokens for the service account, so no credentials are ever hard-coded or stored on disk. This integration works with the instance's default credentials and is fully auditable in Cloud Audit Logs.

Why this answer

Associating a service account with a Compute Engine instance and granting it the Storage Object Viewer role is the recommended IAM-based approach for granting least-privilege access to Cloud Storage. The instance retrieves short-lived OAuth 2.0 access tokens from the metadata server, which the application can use to authenticate API calls without embedding long-lived credentials.

Exam trap

Google Cloud often tests the misconception that the default Compute Engine service account is appropriate for custom applications, when in fact it should be replaced with a dedicated service account with minimal roles to avoid over-permissioning and cross-instance credential sharing.

How to eliminate wrong answers

Option A is wrong because signed URLs provide time-limited access to specific objects, not ongoing read access to a bucket, and embedding them in an application requires manual rotation and exposes the URL in code. Option C is wrong because the default Compute Engine service account with Storage Admin role grants excessive permissions (including delete and update) and violates the principle of least privilege; the default account is also shared across instances in the project. Option D is wrong because storing bucket credentials in instance metadata is insecure—metadata is accessible to any process on the instance and can be exposed via the metadata server without authentication.

385
MCQeasy

A company wants to deploy a new version of their application with zero downtime. They are using a managed instance group (MIG) behind a load balancer. Which deployment method should they use?

A.Create a new MIG, then update the load balancer's backend service
B.Delete the current MIG and create a new one with the updated template
C.Update the instance template and restart all instances
D.Perform a rolling update using a new instance template, with a health check
AnswerD

A rolling update with a new instance template and a health check is the correct way to deploy a new application version without downtime: the MIG progressively creates new instances from the updated template, waits for each to pass the configured health check, and then terminates the old instances. You can control the rollout speed with parameters like maxSurge and maxUnavailable, which ensure that a certain number of old instances remain serving at all times. The health check acts as the gate — if the new version fails health checks, the rollout pauses and old instances stay in service, allowing you to roll back without a full outage. This method directly targets the application version on existing instances, unlike a full MIG replacement, because it updates the instance group in place through the MIG's native update mechanism.

Why this answer

A rolling update using a new instance template allows the managed instance group (MIG) to gradually replace instances with the new version while health checks ensure each new instance is healthy before proceeding. This maintains the desired capacity and avoids downtime, as the load balancer automatically directs traffic only to healthy instances throughout the process.

Exam trap

Google Cloud often tests the misconception that updating the instance template and restarting all instances (Option C) is acceptable for zero downtime, but this ignores the fact that simultaneous restarts cause a full outage unless the MIG is configured for a rolling update with health checks.

How to eliminate wrong answers

Option A is wrong because creating a new MIG and updating the load balancer's backend service introduces a manual cutover step that risks traffic disruption or misconfiguration, and does not leverage the MIG's built-in rolling update mechanism for zero downtime. Option B is wrong because deleting the current MIG before creating a new one causes a period with zero instances, resulting in downtime until the new MIG is fully operational. Option C is wrong because updating the instance template and restarting all instances simultaneously would cause all instances to be unavailable at once, leading to downtime; a rolling update is required to replace instances incrementally.

386
MCQmedium

An administrator wants to set up a budget alert that triggers at 50%, 90%, and 100% of the monthly spending limit. What is the correct way to configure this?

A.Create a budget with a single threshold of 100% and rely on Cloud Monitoring
B.Use Cloud Billing reports to manually track
C.Create three separate budgets, each with a single threshold
D.Create one budget with three threshold rules: 50%, 90%, 100%
AnswerD

Creating one budget with three threshold rules is the recommended and most efficient approach because Cloud Billing budgets natively support multiple thresholds—each can be a percentage of the budget amount and trigger an alert independently. For example, you can set actual-cost thresholds at 50%, 90%, and 100%, and optionally add forecasted-cost thresholds as well. This gives you the desired notification at each stage without duplicating budget resources.

Why this answer

Budget alerts can have multiple threshold rules with different percentages. You can create a single budget with three threshold rules.

387
MCQmedium

A managed instance group (MIG) is running 4 VMs with a CPU autoscaling target of 60%. A traffic spike drives average CPU to 90%. How does the autoscaler respond?

A.The MIG terminates the 2 least-used VMs to trigger a restart with higher performance settings
B.The autoscaler adds VMs until average CPU across the group drops to approximately 60%
C.The MIG live-migrates instances to larger machine types automatically
D.The MIG restarts all existing VMs to clear cached load
AnswerB

The autoscaler uses the target CPU utilization (e.g., 60%) to compute desired capacity: if the group's average CPU is above target, it calculates how many VMs are needed so that average utilization drops back to that level and provisions additional instances. For example, if 5 VMs run at 80%, it targets 7 VMs (5*0.8/0.6 ≈ 6.67) to bring average CPU to ~57%. This scale-out distributes load across new instances, reducing per-VM CPU demand. The autoscaler keeps adding until the measured average falls to approximately the target.

Why this answer

The autoscaler for a managed instance group (MIG) uses a target utilization metric—here, CPU at 60%. When average CPU exceeds that target (90%), the autoscaler calculates the desired number of VMs to bring utilization back to 60% (e.g., 4 VMs * 90% / 60% = 6 VMs) and adds instances accordingly. It does not terminate, migrate, or restart VMs; it scales out horizontally.

Exam trap

Google Cloud often tests the misconception that autoscaling involves modifying existing instances (e.g., restarting, migrating, or resizing) rather than simply adding or removing instances based on a target metric.

How to eliminate wrong answers

Option A is wrong because the autoscaler does not terminate VMs to trigger restarts; it adds VMs to reduce load, and termination would increase load on remaining instances. Option C is wrong because MIGs do not support live migration to larger machine types; autoscaling only adds or removes instances of the same template, and changing machine type requires a new instance template or a different MIG. Option D is wrong because restarting VMs does not reduce CPU utilization; it temporarily disrupts service and does not address sustained high load.

388
MCQmedium

A developer has deployed a Cloud Run service but receives a 503 error when accessing it. The service logs show 'The request was aborted because there was no available instance.' What is the most likely cause?

A.The minimum number of instances is set too high.
B.The container health checks are failing.
C.The service is experiencing a spike in traffic and the max instances are too low.
D.The service's memory limit is set too low.
AnswerC

The error 'no available instance' occurs when a request arrives and all existing Cloud Run instances are processing requests, and the service has already reached its configured maximum number of instances. Cloud Run can only scale out to the max-instances setting; if that cap is too low relative to a spike in traffic, new requests are rejected with HTTP 503 and this log message. Increasing max instances or using instance-based concurrency tuning can mitigate this.

Why this answer

The 503 error with the message 'The request was aborted because there was no available instance' indicates that all current instances are saturated and Cloud Run cannot scale up quickly enough to handle the incoming requests. This occurs when traffic spikes exceed the configured maximum number of instances, causing new requests to be rejected until an instance becomes free. Option C correctly identifies that the max instances setting is too low for the traffic spike.

Exam trap

Google Cloud often tests the distinction between scaling limits (max instances) and resource constraints (memory/CPU), where candidates mistakenly attribute 503 errors to resource limits rather than the explicit scaling cap.

How to eliminate wrong answers

Option A is wrong because setting the minimum number of instances too high would keep idle instances running, which would reduce cold starts and help handle traffic, not cause a 503 due to no available instances. Option B is wrong because failing container health checks would cause the instance to be marked unhealthy and removed from serving, but the error message specifically states 'no available instance' rather than 'unhealthy instance' or 'health check failure'. Option D is wrong because a memory limit set too low would cause the container to be killed (OOMKilled) or return 502/504 errors, not a 503 with the specific 'no available instance' message.

389
MCQhard

Your team uses Cloud Build to build and push Docker images to Artifact Registry. A new security requirement mandates that only images signed by Cloud Build (using Binary Authorization with attestors) can be deployed to your GKE cluster. Which sequence of steps correctly implements this?

A.Enable BinAuthz on the GKE cluster; Cloud Build automatically signs images when BinAuthz is enabled.
B.Create a Cloud KMS key and attestor, configure Cloud Build to create attestations post-build, then set a BinAuthz policy requiring the attestation on the GKE cluster.
C.Use Artifact Registry vulnerability scanning; images that pass scanning are automatically trusted by GKE.
D.Add a Cloud Build step that runs `gcloud container binauthz attestations sign-and-create` without additional configuration.
AnswerB

The correct workflow is to provision a Cloud KMS asymmetric signing key, create a Container Analysis note, and define a Binary Authorization attestor that references both the note and the KMS key. After that, add a Cloud Build step (for example, using the `gcloud container binauthz attestations sign-and-create` command or the official attestation helper) to sign the image digest and create an attestation in Container Analysis. Finally, set the BinAuthz admission policy on the GKE cluster to require attestations from that attestor; the cluster then permits only images bearing a valid signature. This sequence maps the cryptographic trust chain to the actual enforcement point.

Why this answer

It follows the required workflow: you must first create a Cloud KMS key and an attestor in Binary Authorization, then configure Cloud Build to generate an attestation (signed by the attestor) after each successful build. Finally, you set a Binary Authorization policy on the GKE cluster that enforces the attestation, ensuring only signed images are deployed. Cloud Build does not automatically sign images when BinAuthz is enabled; the attestation must be explicitly created.

Exam trap

Google Cloud often tests the misconception that enabling Binary Authorization on a cluster automatically integrates with Cloud Build to sign images, when in fact you must manually create the attestor, key, and attestation step.

How to eliminate wrong answers

Option A is wrong because enabling Binary Authorization on the GKE cluster does not cause Cloud Build to automatically sign images; Cloud Build requires explicit configuration to create attestations using an attestor and signing key. Option C is wrong because Artifact Registry vulnerability scanning only identifies vulnerabilities and does not create cryptographic attestations; GKE does not automatically trust scanned images without a Binary Authorization policy requiring attestations. Option D is wrong because the `gcloud container binauthz attestations sign-and-create` command requires a properly configured attestor and signing key (e.g., Cloud KMS) to be in place; simply adding the command as a build step without prior setup of the attestor and key will fail.

390
MCQmedium

A Compute Engine VM with only a private IP address needs to download software updates from the internet (apt-get update). What must be configured in the VPC to enable outbound internet access for private VMs?

A.Enable Private Google Access on the subnet
B.Configure Cloud NAT on the VPC's Cloud Router for the subnet
C.Add an external IP address to the VM temporarily for the update, then remove it
D.Create a VPC firewall rule allowing egress to 0.0.0.0/0 on port 80 and 443
AnswerB

Configuring Cloud NAT on the VPC's Cloud Router for the subnet is correct because it provides source network address translation for instances with private IPs. The NAT gateway maps the private source addresses to a shared public IP, allowing outbound internet connections while keeping the instances themselves unreachable from the outside. This makes apt-get, pip, and similar package managers work without assigning per-VM external IPs.

Why this answer

Cloud NAT (Network Address Translation) allows private VMs without external IP addresses to initiate outbound connections to the internet. It translates the VM's private IP to a public IP managed by Cloud NAT, enabling apt-get update to reach external repositories. This is the correct and scalable solution for outbound-only internet access from private instances.

Exam trap

Google Cloud often tests the distinction between Private Google Access (for Google APIs only) and Cloud NAT (for general internet access), leading candidates to mistakenly choose Private Google Access when the requirement is for outbound internet access to non-Google endpoints.

How to eliminate wrong answers

Option A is wrong because Private Google Access only enables VMs with private IPs to reach Google APIs and services (e.g., Cloud Storage, BigQuery) via Google's internal network, not general internet destinations like apt repositories. Option C is wrong because temporarily adding an external IP is a manual, non-scalable workaround that violates the requirement for a persistent configuration and exposes the VM to inbound traffic. Option D is wrong because a firewall rule allowing egress to 0.0.0.0/0 on ports 80 and 443 only permits the traffic to leave the VPC; without Cloud NAT or an external IP, the packets have no routable source address and will be dropped by the internet gateway.

391
MCQmedium

A team deploys a new version of their application using a blue-green strategy on GKE. The 'green' deployment is running but still in testing. When ready, traffic should instantly switch from 'blue' to 'green' with rollback possible in seconds. How is the instant switch implemented?

A.Delete the blue Deployment and create the green Deployment as the replacement
B.Update the Service's label selector from 'version: blue' to 'version: green'
C.Update the Deployment's container image tag — GKE automatically performs a blue-green rollout
D.Use kubectl patch to update the Service's ClusterIP to point to the green Deployment
AnswerB

Changing the Service's label selector from version: blue to version: green repoints the Service's Endpoints to the green Pods immediately, because Kubernetes Services route traffic by matching Pod labels, not by any explicit backend list. Since the blue Deployment remains untouched, it stays running with its Pods intact, making a rollback as simple as reverting the selector back to blue. No downtime occurs because the green Pods are already healthy and registered as ready before the switch, and the Service's ClusterIP and DNS name remain unchanged.

Why this answer

In a blue-green deployment on GKE, the Service acts as a stable network endpoint abstracting the underlying Pods. By changing the Service's label selector from 'version: blue' to 'version: green', traffic is instantly routed to the green Pods without any downtime or need to recreate resources. This allows immediate rollback by simply reverting the selector back to 'version: blue'.

Exam trap

Google Cloud often tests the misconception that updating a Deployment's image tag or using kubectl patch on ClusterIP is the correct way to switch traffic, when in fact the Service's label selector is the precise mechanism for instant traffic redirection in blue-green deployments.

How to eliminate wrong answers

Option A is wrong because deleting the blue Deployment and creating the green Deployment as a replacement would cause downtime during the deletion and creation process, and does not provide an instant switch or easy rollback. Option C is wrong because updating a Deployment's container image tag triggers a rolling update, not a blue-green switch; GKE does not automatically perform a blue-green rollout based on image tag changes. Option D is wrong because a Service's ClusterIP is a virtual IP assigned by Kubernetes and cannot be patched to point to a different Deployment; the correct way to redirect traffic is by updating the label selector, not the ClusterIP.

392
MCQmedium

A team is migrating a stateful application with local disk writes to GKE. The application requires a dedicated persistent disk that follows the Pod if it's rescheduled to a different node. Which Kubernetes resource provides this?

A.A HostPath volume pointing to a directory on the node
B.A ConfigMap mounted as a volume
C.A PersistentVolumeClaim backed by a GCE persistent disk StorageClass
D.An emptyDir volume scoped to the Pod
AnswerC

A PersistentVolumeClaim (PVC) backed by a GCE persistent disk StorageClass provides durable, network-attached block storage that is provisioned independently of any specific node. When a Pod using this PVC is rescheduled, the underlying PersistentVolume (a GCE PD) is detached from the old node and attached to the new node, preserving all application-written data. This makes it the correct choice for stateful workloads that must survive Pod restarts or node failures. Note that the PD is zonal, so the new node must be in the same zone as the disk.

Why this answer

A PersistentVolumeClaim (PVC) backed by a GCE persistent disk StorageClass is the correct choice because it provides a durable, network-attached block storage volume that persists independently of the Pod's lifecycle. When the Pod is rescheduled to a different node, the PVC ensures the GCE persistent disk is detached from the old node and reattached to the new node, preserving the application's state. This meets the requirement for a dedicated persistent disk that follows the Pod across rescheduling events.

Exam trap

Google Cloud often tests the distinction between ephemeral (emptyDir, HostPath) and persistent (PVC-backed) storage, trapping candidates who confuse node-local storage with cluster-wide persistent volumes that follow Pods across nodes.

How to eliminate wrong answers

Option A is wrong because a HostPath volume mounts a directory from the host node's filesystem, which is node-specific and does not follow the Pod if it is rescheduled to a different node; it also lacks the durability and portability required for stateful applications. Option B is wrong because a ConfigMap is designed for injecting non-sensitive configuration data (e.g., key-value pairs or small files) and is not a persistent storage volume; it cannot handle disk writes or maintain state across Pod reschedules. Option D is wrong because an emptyDir volume is ephemeral and scoped to the Pod's lifecycle—it is created when the Pod starts and deleted when the Pod is removed, so it does not persist data if the Pod is rescheduled to a different node.

393
MCQmedium

A GKE team is comparing Autopilot and Standard cluster modes for a new project. They want to minimize infrastructure management overhead, automatically right-size node resources, and be billed only for Pod resource requests. Which mode matches these requirements?

A.GKE Standard — it provides more control over node configuration
B.GKE Autopilot — managed nodes, automatic right-sizing, and per-Pod billing
C.GKE Standard with cluster autoscaler and node auto-provisioning enabled
D.Both modes are equivalent in management overhead — Autopilot is just a pricing model
AnswerB

GKE Autopilot is the correct choice because it fully abstracts node management: Google provisions, scales, and optimizes the underlying nodes, and you only pay for Pod resource requests. There are no node pools or machine types to configure, and the cluster automatically right-sizes workloads, delivering truly minimal operational overhead.

Why this answer

GKE Autopilot is the correct choice because it fully manages the underlying node infrastructure, automatically right-sizes node resources based on Pod resource requests, and bills only for the requested CPU and memory of Pods, not the underlying nodes. This aligns directly with the team's goals of minimizing management overhead, automatic right-sizing, and per-Pod billing.

Exam trap

Google Cloud often tests the misconception that GKE Standard with autoscaling features provides the same per-Pod billing and zero node management as Autopilot, but the key difference is that Standard always bills for the underlying nodes, not the Pods.

How to eliminate wrong answers

Option A is wrong because GKE Standard requires manual node management and does not automatically right-size node resources; it bills for the underlying nodes, not per Pod. Option C is wrong because even with cluster autoscaler and node auto-provisioning, GKE Standard still bills for the provisioned nodes, not per Pod, and does not provide the same level of automatic right-sizing as Autopilot. Option D is wrong because Autopilot and Standard are fundamentally different in management overhead and billing model; Autopilot is not just a pricing model but a fully managed mode with distinct operational characteristics.

394
MCQhard

A team runs a critical production project and wants to prevent anyone — including project owners and organization admins — from accidentally deleting it. Which mechanism provides this protection?

A.Remove the Owner role from all users in the project
B.Set an organization policy denying the resourcemanager.projects.delete permission
C.Create a project lien using the Cloud Resource Manager API or gcloud
D.Enable deletion protection in the project's IAM settings in the Console
AnswerC

Creating a project lien is the correct way to prevent accidental or even intentional deletion of a project. A lien blocks the resourcemanager.projects.delete operation on the project, and any deletion attempt will fail until the lien is removed via the Cloud Resource Manager API or using the 'gcloud resource-manager liens' commands, even for users who have the delete permission. This is the only option that directly and reliably protects the project from deletion.

Why this answer

A project lien is the correct mechanism because it explicitly prevents the deletion of a Google Cloud project by blocking the `resourcemanager.projects.delete` operation until the lien is removed. This protection works regardless of the user's role, including project owners and organization admins, and is managed via the Cloud Resource Manager API or `gcloud` command. It is designed specifically for accidental deletion prevention, not for access control.

Exam trap

The trap here is that candidates confuse IAM permissions (like denying `resourcemanager.projects.delete`) with project-level operational locks (liens), or assume a UI toggle exists for deletion protection when it does not in Google Cloud.

How to eliminate wrong answers

Option A is wrong because removing the Owner role from all users does not prevent organization admins or other privileged users from deleting the project, and it breaks project management functionality. Option B is wrong because setting an organization policy denying `resourcemanager.projects.delete` would block all project deletions across the organization, which is too broad and not a targeted protection for a single project. Option D is wrong because there is no 'deletion protection' toggle in IAM settings in the Google Cloud Console; IAM manages permissions, not project-level deletion locks.

395
MCQeasy

A developer needs to create a zonal GKE cluster with 3 nodes of type e2-standard-4 in zone us-central1-a. Which command should they use?

A.gcloud compute instances create my-cluster --zone=us-central1-a --machine-type=e2-standard-4 --num-nodes=3
B.gcloud container clusters create my-cluster --zone=us-central1-a --num-nodes=3 --machine-type=e2-standard-4
C.gcloud container clusters create my-cluster --zone=us-central1-a --num-nodes=1 --machine-type=e2-standard-4
D.gcloud container clusters create my-cluster --region=us-central1 --num-nodes=3 --machine-type=e2-standard-4
AnswerB

This correct command creates a zonal GKE cluster because --zone targets a single zone, us-central1-a, and the cluster's control plane and nodes are both provisioned there. The --num-nodes=3 flag defines the initial size of the default node pool, and --machine-type=e2-standard-4 sets each node's VM shape. This exactly meets the requirement for a 3-node zonal cluster.

Why this answer

The correct command creates a zonal cluster (single zone) with specified node count and machine type. The --region flag creates a regional cluster, which is not required.

396
MCQhard

You need to audit all IAM policy changes in your project. You want to ensure that every change is logged with the identity of the user who made the change. Which type of audit log should you enable?

A.Data Access audit logs
B.Admin Activity audit logs
C.Policy Denied audit logs
D.System Event audit logs
AnswerB

Admin Activity audit logs capture all changes to configurations and metadata, including every IAM role binding, service account creation or deletion, and project-level policy modification. These logs are enabled by default for all projects and cannot be disabled, making them the authoritative source for answering 'who changed an IAM policy and when.' Each entry includes the actor, the action, the affected resource, and the request metadata, so this is the correct log type to audit IAM policy changes.

Why this answer

Admin Activity audit logs (also known as Cloud Audit Logs) record all API calls that modify the configuration or metadata of resources, including IAM policy changes. These logs capture the identity of the user who made the change, the time of the change, and the specific modification, ensuring full accountability for administrative actions.

Exam trap

Google Cloud often tests the distinction between Admin Activity and Data Access logs, where candidates mistakenly choose Data Access logs because they think 'all changes' include data modifications, but IAM policy changes are administrative, not data-level, operations.

How to eliminate wrong answers

Option A is wrong because Data Access audit logs record API calls that read or modify user-provided data (e.g., reading a Cloud Storage object), not configuration changes like IAM policies. Option C is wrong because Policy Denied audit logs only log access attempts that are denied by IAM policies, not the changes to the policies themselves. Option D is wrong because System Event audit logs capture non-user-initiated events such as system maintenance or resource lifecycle events, not user-driven IAM policy modifications.

397
MCQmedium

You manage a Google Kubernetes Engine (GKE) cluster and need to update the deployment 'web-app' to use a new container image tag 'v2'. You also want to ensure the update proceeds and, if it fails, roll back to the previous revision. Which set of commands should you use?

A.gcloud container clusters upgrade; kubectl rollout status; kubectl rollout undo
B.kubectl set image deployment/web-app web-app=gcr.io/myproject/web-app:v2; kubectl rollout status; kubectl rollout undo
C.kubectl edit deployment web-app; kubectl rollout status; kubectl delete deployment web-app
D.kubectl apply -f web-app.yaml; kubectl rollout status; kubectl rollout undo
AnswerB

kubectl set image directly updates the Deployment's pod template to reference the v2 image, which triggers a rolling update orchestrated by the Deployment controller. kubectl rollout status then watches that update to completion, returning a non-zero exit code if the rollout fails (e.g., due to crash-loops or insufficient readiness), which is the correct signal for conditional rollback. kubectl rollout undo reverts to the previous revision, but note it should be gated on that failure in practice; even so, this is the only option that uses the proper Kubernetes-native commands for image update, rollout monitoring, and rollback.

Why this answer

The correct command to update a deployment's container image is 'kubectl set image deployment/web-app web-app=gcr.io/myproject/web-app:v2', which directly updates the image tag for the specified container in the deployment. Following that, 'kubectl rollout status' monitors the update progress, and 'kubectl rollout undo' reverts to the previous revision if the update fails. This sequence ensures a controlled update with rollback capability.

Exam trap

The trap here is confusing cluster-level upgrades (gcloud container clusters upgrade) with application-level updates, or thinking that editing the deployment manually is equivalent to a controlled image update with rollback.

How to eliminate wrong answers

Option A is wrong because 'gcloud container clusters upgrade' upgrades the GKE cluster's Kubernetes version, not the application deployment image. Option C is wrong because 'kubectl edit deployment web-app' opens an editor for manual changes, which is error-prone and not scriptable, and 'kubectl delete deployment web-app' deletes the deployment entirely rather than rolling back. Option D is wrong because 'kubectl apply -f web-app.yaml' requires an updated manifest file and does not specifically target an image tag change; it could apply other unintended changes.

398
MCQmedium

You have a GKE cluster with a node pool that needs to scale automatically based on load. The cluster was created with autoscaling disabled. Which command enables autoscaling on an existing node pool?

A.gcloud container node-pools create my-pool --enable-autoscaling
B.kubectl autoscale node-pool my-pool --min=1 --max=10
C.gcloud container node-pools update my-pool --cluster=my-cluster --enable-autoscaling --min-nodes=1 --max-nodes=10
D.gcloud container clusters update my-cluster --enable-autoscaling
AnswerC

This is the correct command because it targets an existing node pool (`my-pool`) within the specified cluster and toggles the GKE cluster autoscaler on for that pool. The `--min-nodes=1` and `--max-nodes=10` flags define the scaling boundaries, allowing the pool to resize within those limits based on resource demand. The `--cluster` flag scopes the operation to the right cluster, and the update command modifies the live pool without recreating it.

Why this answer

The correct command is `gcloud container node-pools update` with `--enable-autoscaling` and min/max node flags, because autoscaling is a property of the node pool, not the cluster, and it must be enabled on an existing pool via the update verb. The `--cluster` flag identifies the parent cluster, and `--min-nodes`/`--max-nodes` define the scaling bounds. This is the only option that both targets an existing node pool and uses the correct gcloud subcommand.

Exam trap

The trap here is confusing cluster-level and node-pool-level operations — candidates often pick the cluster update command or the create command, forgetting that autoscaling is configured per node pool and requires the `node-pools update` verb.

How to eliminate wrong answers

Option A is wrong because `gcloud container node-pools create` creates a brand-new node pool rather than enabling autoscaling on the existing one, which would leave the original pool unchanged and add unnecessary resources. Option B is wrong because `kubectl autoscale` operates on Kubernetes workload resources (Deployments, ReplicaSets, StatefulSets) via HorizontalPodAutoscaler, not on GKE node pools; there is no `node-pool` resource type for kubectl autoscale. Option D is wrong because `gcloud container clusters update --enable-autoscaling` is not a valid way to enable node pool autoscaling — cluster-level update commands do not carry the node pool's min/max node configuration, and the flag belongs to node-pool operations.

399
Multi-Selectmedium

A company wants to migrate an on-premises MySQL database to Cloud SQL with minimal downtime. The database is 500 GB. Which TWO steps should be taken? (Choose 2 correct answers.)

Select 2 answers
A.Create a Cloud SQL instance to serve as the target for the migration.
B.Export the database using gcloud sql export sql, then import to Cloud SQL.
C.Create a Cloud SQL instance and configure it as an external replica of the on-premises database.
D.Use mysqldump to backup the database and restore into Cloud SQL.
E.Use Database Migration Service to create a continuous migration job.
AnswersA, E

The Database Migration Service requires a pre-provisioned Cloud SQL instance as the destination, so creating one first defines the target tier, storage, and network configuration before any migration job is started. Without an existing instance, DMS has nowhere to replicate the initial snapshot or stream incoming changes. This is the necessary first step in a low-downtime migration, even though the actual data movement happens later via a DMS job.

Why this answer

To minimize downtime, you can perform a Database Migration Service (DMS) continuous migration or export/import with a consistent snapshot. DMS supports MySQL and provides continuous sync. Alternatively, you can export the database using mysqldump, then import, but this requires downtime.

However, for minimal downtime, DMS is best. Another approach is to create a read replica then promote, but Cloud SQL does not support external read replicas directly. The correct two are: use DMS for continuous migration, and optionally create a clone for testing, but the question asks for migration steps.

The best two from the options: use DMS migration job and create a Cloud SQL instance.

400
MCQhard

An organization has a folder hierarchy with multiple projects. They want to grant a support team the ability to view all IAM policies across the entire folder. What is the most efficient way?

A.Grant roles/iam.securityReviewer at the folder level.
B.Grant roles/iam.securityReviewer on each project individually.
C.Grant roles/owner at the folder level.
D.Grant roles/viewer at the folder level.
AnswerA

Granting roles/iam.securityReviewer at the folder level is correct because IAM permissions propagate through the resource hierarchy. This predefined role includes resourcemanager.folders.getIamPolicy and resourcemanager.projects.getIamPolicy, allowing the user to read IAM policies on the folder and every project, folder, and resource beneath it. Because the audit scope is the entire folder hierarchy, one grant at the folder root covers all child projects without per-project assignments, satisfying the requirement efficiently and with least privilege.

Why this answer

Granting roles/iam.securityReviewer at the folder level is the most efficient approach because IAM policies in Google Cloud are hierarchical and inherited. A single binding at the folder level automatically applies to every project and resource beneath it, so the support team gains visibility into all IAM policies across all projects without per-project configuration. This follows the principle of least privilege while minimizing administrative overhead.

Exam trap

ACE often tests the misconception that roles/viewer or roles/owner are sufficient for auditing IAM — candidates forget that viewer lacks IAM read permissions and owner is over-privileged, and they overlook that folder-level inheritance is the efficient answer.

How to eliminate wrong answers

Option B is wrong because granting the role on each project individually is operationally inefficient and error-prone — new projects added later would not be covered, and it requires N separate bindings instead of one. Option C is wrong because roles/owner grants full control over all resources (including billing, IAM modification, and deletion), which is far more privilege than needed to merely view IAM policies and violates least privilege. Option D is wrong because roles/viewer grants read access to most resources but does not include the specific iam.policies.get and related permissions needed to review IAM policies; securityReviewer is the purpose-built role for auditing IAM.

401
MCQmedium

A developer needs to use Application Default Credentials (ADC) in a local development environment to call the Cloud Translation API. They have already run `gcloud auth login`. What additional step is required to make ADC work correctly?

A.Run `gcloud auth application-default login` to generate ADC credentials.
B.Set the `GOOGLE_CLOUD_PROJECT` environment variable to the project ID.
C.Download a service account JSON key and set `GOOGLE_APPLICATION_CREDENTIALS`.
D.Run `gcloud config set account` to switch to the correct account.
AnswerA

`gcloud auth application-default login` is the canonical command for locally developing with Google Cloud client libraries because it downloads OAuth2 user credentials and stores them in `application_default_credentials.json` in the well-known gcloud config directory. This file is one of the primary sources in the ADC lookup chain, so client libraries automatically discover these credentials without any further configuration. Unlike `gcloud auth login`, which only authenticates the gcloud CLI, this command specifically populates the credentials that your application code will find when it calls the ADC helper.

Why this answer

`gcloud auth application-default login` creates a special credential file (typically at `~/.config/gcloud/application_default_credentials.json`) that Application Default Credentials (ADC) uses to authenticate API calls. While `gcloud auth login` sets up user credentials for gcloud CLI commands, ADC does not use those credentials directly; it requires its own separate credential file. Running this command ensures that the local development environment can authenticate to the Cloud Translation API via ADC without additional configuration.

Exam trap

Google Cloud often tests the distinction between `gcloud auth login` (for CLI authentication) and `gcloud auth application-default login` (for ADC), leading candidates to mistakenly think the former is sufficient for ADC-based API calls.

How to eliminate wrong answers

Option B is wrong because setting the `GOOGLE_CLOUD_PROJECT` environment variable only specifies the project ID for quota and billing purposes; it does not provide authentication credentials, so ADC would still fail without valid credentials. Option C is wrong because downloading a service account JSON key and setting `GOOGLE_APPLICATION_CREDENTIALS` is a valid method for ADC, but it is not required after `gcloud auth login`; the question asks for the additional step to make ADC work correctly, and the simpler, recommended step for local development is to use `gcloud auth application-default login` rather than managing service account keys. Option D is wrong because `gcloud config set account` switches the active account for gcloud CLI commands but does not create or configure the ADC credential file, so ADC would still not have credentials to use.

402
Multi-Selecthard

An engineer needs to choose a location for a new GCP project's resources to maximize availability and minimize latency for users in Europe and Asia. Which three actions should they take? (Choose THREE)

Select 3 answers
A.Use a global load balancer to distribute traffic
B.Set the project default region to us-central1
C.Deploy resources in europe-west1 and asia-east1
D.Use a single zone in europe-west1 for simplicity
E.Enable Cloud CDN to cache content at edge locations
AnswersA, C, E

Global external HTTPS load balancing leverages a single anycast IP address and Google's global backbone to forward each user request to the optimal backend based on latency and health. It performs traffic distribution at L7 to the nearest available region, allowing active/active serving across multiple regions without DNS round-robin. This is the standard control plane that unifies multi-region deployments into one global endpoint.

Why this answer

Option A is correct because a global external Application Load Balancer (or global external proxy Network Load Balancer) uses Google's global anycast edge network to route users to the closest healthy backend, reducing latency and improving availability across Europe and Asia. Option C is correct because deploying resources in multiple regions such as europe-west1 and asia-east1 places compute and data physically near European and Asian users, and multi-region deployment protects against regional failures. Option E is correct because Cloud CDN caches content at Google edge points of presence (over 100+ locations), serving cached responses from the nearest edge to further cut latency for static and cacheable content.

Option B is not appropriate because setting the default region to us-central1 would place resources in North America, far from the target European and Asian users, increasing latency. Option D is not appropriate because a single zone in europe-west1 creates a single point of failure and does not serve Asian users with low latency, contradicting the availability and latency goals.

Exam trap

The trap is choosing a single region or single zone for 'simplicity' — the exam rewards multi-region design for global user bases, and single-zone answers are almost always wrong when availability is a stated goal.

403
Multi-Selectmedium

You need to set up log-based alerting in Cloud Logging to send notifications when a specific error pattern appears in your application logs. Which TWO components are required to accomplish this?

Select 2 answers
A.An alerting policy
B.A log sink
C.A Cloud Pub/Sub topic
D.An uptime check
E.A log-based metric
AnswersA, E

The alerting policy is the actual alerting mechanism in Cloud Logging. It defines the conditions that trigger an incident, such as a threshold on a metric (e.g., a log-based metric exceeding a value) and specifies the notification channels (email, Slack, etc.) to receive alerts. Without an alerting policy, a log-based metric only counts or samples log entries; it does not perform any active monitoring or notify anyone.

Why this answer

Option A, an alerting policy, is required because it is the Cloud Monitoring resource that defines the condition to watch and the notification channels to fire when that condition is met, which is what actually sends the notifications. Option E, a log-based metric, is required because log-based alerting in Cloud Logging works by defining a metric that counts or extracts values from log entries matching the specified error pattern, and the alerting policy then evaluates that metric. Together, the log-based metric translates the log filter into a time series and the alerting policy triggers notifications when that series crosses the threshold.

Option B, a log sink, is not required because sinks route or export log entries to destinations such as Cloud Storage or BigQuery and are not part of the alerting evaluation path. Option C, a Cloud Pub/Sub topic, is not required because Pub/Sub is only needed for log routing/export or for notification delivery if explicitly chosen as a channel, not for creating the log-based alert itself. Option D, an uptime check, is not required because uptime checks probe endpoint availability over HTTP/TCP and are unrelated to matching error patterns in log entries.

Exam trap

ACE often tests the confusion between log routing (sinks) and log alerting — candidates who think a log sink or Pub/Sub topic is required for alerting miss that the essential pair is a log-based metric plus an alerting policy.

404
Multi-Selecteasy

A company wants to ensure that only users from a specific domain (@example.com) can access Cloud Storage buckets in a project. Which two steps should be taken? (Choose two.)

Select 2 answers
A.Use VPC Service Controls to restrict access.
B.Enable domain restricted sharing in Cloud Storage settings.
C.Set an organization policy to restrict allowed domains for IAM.
D.Add an IAM condition to the bucket policy to require that the user's domain is @example.com.
E.Grant access to the bucket to a Cloud Identity group that only includes @example.com users.
AnswersC, E

The organization policy constraint iam.allowedPolicyMemberDomains is the canonical mechanism to restrict which domains can be granted IAM roles. When this constraint lists example.com, any attempt to add a principal outside that domain to a bucket policy, project, or folder is rejected. Because it is inherited from the organization, it protects all resources under that hierarchy without per-resource configuration.

Why this answer

The organization policy constraint `iam.allowedPolicyMemberDomains` restricts which domains can be used as members in IAM policies across the entire project. This ensures that only principals from @example.com can be granted access to any resource, including Cloud Storage buckets. Option E is correct because a Cloud Identity group containing only @example.com users can be granted IAM roles on the bucket, and membership in the group is controlled by the domain, effectively limiting access to that domain.

Exam trap

Google Cloud often tests the distinction between organization policies (which enforce constraints globally at the resource hierarchy level) and IAM conditions (which are per-binding and evaluated at access time), leading candidates to incorrectly choose IAM conditions as a domain restriction mechanism.

405
MCQmedium

A company has multiple VPC networks in their project. They want Compute Engine instances in one VPC to communicate with instances in another VPC using internal IP addresses. Which feature should they use?

A.Cloud NAT
B.VPC Network Peering
C.Cloud VPN
D.Firewall rules
AnswerB

VPC Network Peering directly connects two VPC networks over Google's private backbone, allowing instances in each network to communicate using internal RFC 1918 addresses without needing public IPs or a VPN. It is the recommended method for inter-VPC connectivity because it offers low latency, no bandwidth restrictions, and no single point of failure. Peering works across projects and organizations, and it automatically exchanges routes for all subnets in the peered networks, so it fully satisfies the requirement to connect multiple VPC networks.

Why this answer

VPC Peering allows connectivity between two VPC networks using internal IPs. VPN is for on-premises connectivity. Cloud NAT is for outbound internet access.

Firewall rules control traffic but do not enable routing between VPCs.

406
Drag & Dropmedium

Arrange the steps to create a Compute Engine instance with a custom service account in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The service account must exist before attaching to an instance; instance creation is the final step.

407
MCQhard

A company has a Google Cloud organization with multiple folders and projects. The security team wants to audit all actions that create or modify IAM policies across the entire organization. Which type of audit log should they examine?

A.System Event audit logs
B.Data Access audit logs
C.VPC Flow Logs
D.Admin Activity audit logs
AnswerD

Admin Activity audit logs are enabled by default and capture all API calls that modify the configuration or metadata of resources, including IAM policy updates. For an organization with multiple folders, these logs at the org level record IAM binding changes on any resource in the hierarchy, such as 'setIamPolicy' from projects or folders. They provide an audit trail of who changed what, when, from where, and for which resource, making them the correct log type for investigating IAM policy modifications.

Why this answer

Admin Activity audit logs in Google Cloud record all API calls that modify resource configurations, including IAM policy changes (e.g., setIamPolicy). They are enabled by default, cannot be disabled, and are the correct log type for auditing who created or modified IAM policies across the organization.

Exam trap

ACE often tests the distinction between Admin Activity (config changes) and Data Access (data reads/writes), causing candidates to pick Data Access when the question is about IAM policy modifications.

How to eliminate wrong answers

Option A is wrong because System Event audit logs record Google-initiated system actions (e.g., live migration, automatic restarts), not user-driven IAM changes. Option B is wrong because Data Access audit logs record reads and writes of user data (e.g., reading a GCS object), not administrative configuration changes like IAM policy modifications. Option C is wrong because VPC Flow Logs capture network traffic metadata (IP, port, protocol) for VPC subnets, not IAM or API activity.

408
MCQmedium

A DevOps engineer needs to deploy a new GKE Pod that mounts a ConfigMap named 'app-config' as environment variables. The ConfigMap already exists in the cluster. Which YAML snippet correctly references it?

A.envFrom: - configMapRef: name: app-config
B.volumes: - name: config / configMap: name: app-config
C.env: - name: CONFIG / valueFrom: secretKeyRef: name: app-config
D.envFrom: - secretRef: name: app-config
AnswerA

The `envFrom` field with a `configMapRef` entry creates environment variables for every key in the `app-config` ConfigMap, with the key name becoming the variable name. This is the correct, declarative way to inject an entire ConfigMap's data as environment variables without listing each key individually. Note that the variables are snapshotted at pod creation; later ConfigMap updates do not update the already-running container's environment.

Why this answer

The `envFrom` field with a `configMapRef` allows a Pod to load all key-value pairs from a ConfigMap as environment variables. This is the standard Kubernetes syntax for injecting ConfigMap data into a container's environment without specifying individual keys.

Exam trap

Google Cloud often tests the distinction between `configMapRef` and `secretRef` in `envFrom` blocks, and the trap here is that candidates confuse ConfigMaps with Secrets or incorrectly use volume syntax for environment variables.

How to eliminate wrong answers

Option B is wrong because it defines a volume mount for a ConfigMap, not environment variables; the correct syntax for a ConfigMap volume uses `configMap` (not `config`) and requires a `volumes` block plus a `volumeMounts` entry. Option C is wrong because it uses `secretKeyRef` to reference a ConfigMap, which is only valid for Secrets, not ConfigMaps; also, the `valueFrom` field is used for individual key references, not for loading the entire ConfigMap. Option D is wrong because it uses `secretRef` instead of `configMapRef`; `secretRef` is used to load Secrets as environment variables, not ConfigMaps.

409
Multi-Selectmedium

You are troubleshooting a Pub/Sub subscription that is not delivering messages promptly. Which THREE factors should you investigate? (Choose THREE.)

Select 3 answers
A.The subscription's backlog size
B.The topic's retention duration
C.The subscriber's processing latency
D.The message ordering key
E.The acknowledgment deadline
AnswersA, C, E

The subscription's backlog size is the primary indicator of delivery problems: it counts messages that have been published but not yet acknowledged. When troubleshooting a subscription that is not delivering, an ever-growing backlog means messages are arriving faster than the subscriber can process them, or the subscriber has stopped pulling entirely. Large backlog also correlates with slow processing and can help you decide whether to scale out subscribers or inspect subscriber logs.

Why this answer

Common causes include backlog, subscriber latency, and ack deadlines.

410
Multi-Selecteasy

A company is deploying a web application on Compute Engine and wants to distribute traffic across multiple instances in different zones for high availability. They also need to terminate SSL/TLS at the load balancer. Which TWO services should they use together?

Select 2 answers
A.Managed instance group
B.External HTTP(S) load balancer
C.Cloud CDN
D.Internal TCP/UDP load balancer
E.Cloud NAT
AnswersA, B

A managed instance group (MIG) is the correct backend infrastructure because it maintains a pool of identical VM instances across multiple zones, enabling the HTTP(S) load balancer to distribute traffic and automatically heal failed instances. MIGs support autoscaling based on load, which is essential for a scalable web application, and they provide the instance-level health checking that the load balancer relies on to route requests only to healthy VMs.

Why this answer

Option A, a managed instance group, is correct because it provides the pool of identical Compute Engine instances spread across multiple zones that the load balancer distributes traffic to, and it also enables autohealing and autoscaling for high availability. Option B, an external HTTP(S) load balancer, is correct because it is a global, layer 7 load balancer that spreads client traffic across instances in multiple zones/regions and supports SSL/TLS termination at the load balancer via its target HTTPS proxy and SSL certificates. Option C, Cloud CDN, is not required here because it is a content-caching layer that integrates with the HTTP(S) load balancer but does not itself distribute traffic across instances or terminate SSL/TLS.

Option D, an internal TCP/UDP load balancer, is wrong because it is a regional, layer 4 load balancer for internal traffic and does not terminate SSL/TLS or serve public web traffic. Option E, Cloud NAT, is wrong because it provides outbound internet access for instances without external IPs and has nothing to do with inbound traffic distribution or SSL/TLS termination.

Exam trap

ACE often tests the combination of a managed instance group with an external load balancer for HA and SSL termination, while candidates may incorrectly choose Cloud CDN or internal load balancer for external SSL termination.

411
MCQeasy

An organization wants to separate its development and production environments using Google Cloud resource hierarchy. What is the recommended approach?

A.Create a single project and use separate VPC networks for dev and prod.
B.Create two separate organizations, one for dev and one for prod.
C.Create two projects under the same folder and use labels to differentiate dev and prod.
D.Create two folders under the organization node, one for dev and one for prod.
AnswerD

Folders beneath the organisation node let you apply separate IAM policies, quotas and billing controls to dev and prod, with projects nested inside each. This isolates environments while retaining centralised organisation-level governance, which is Google's recommended hierarchy for environment separation.

Why this answer

Google Cloud resource hierarchy is Organization > Folders > Projects > Resources. Creating two folders under the organization node — one for dev and one for prod — is the recommended way to separate environments because IAM policies and organization policies applied at the folder level are inherited by all projects beneath them. This provides clean isolation and centralized governance without duplicating the organization.

Exam trap

ACE often tests whether candidates know that folders — not projects, VPCs, or labels — are the recommended resource-hierarchy boundary for separating environments.

How to eliminate wrong answers

Option A is wrong because a single project with separate VPCs does not provide billing, IAM, or policy isolation between environments and is not a recommended separation boundary. Option B is wrong because an organization maps to a single identity domain (Cloud Identity/Workspace), so creating two organizations is impractical and breaks centralized administration. Option C is wrong because two projects under the same folder share inherited policies and using labels for environment separation is a tagging convention, not a security boundary.

412
MCQhard

A team manages multiple Kubernetes Engine clusters across different projects. They need to enforce that all clusters have the same security policies, including private cluster settings and workload identity. Which approach is most scalable?

A.Use Cloud Asset Inventory to compare configurations and alert on differences.
B.Retrieve cluster configuration for each cluster using gcloud container clusters describe and apply changes manually.
C.Use Config Connector with deployment scripts to manage cluster resources as Kubernetes custom resources.
D.Use Terraform with a module that defines the standard cluster configuration, and apply it to each project.
AnswerD

Terraform with a reusable module is the correct approach because it implements infrastructure-as-code, allowing the cluster configuration to be defined declaratively, versioned in source control, and parameterized for different projects. Applying the same module to each project guarantees identical clusters while handling dependency ordering, state tracking, and incremental changes. This is the standard, scalable pattern for cross-project consistency in Google Cloud, and it also provides drift detection through Terraform plans and state management.

Why this answer

Terraform, combined with a reusable module, provides an Infrastructure as Code (IaC) approach that enforces consistent cluster configurations across multiple projects declaratively. This method is scalable as it allows you to define the standard security policies (private cluster settings, Workload Identity) once in a module and apply it to any number of clusters, ensuring drift is prevented and changes are auditable.

Exam trap

Candidates may confuse monitoring tools (Cloud Asset Inventory) with enforcement, but Terraform is the most scalable because it provides a module-driven IaC workflow without the operational overhead of a management Kubernetes cluster.

How to eliminate wrong answers

Option A is wrong because Cloud Asset Inventory is a monitoring and alerting tool, not a configuration enforcement mechanism; it can detect differences but cannot automatically apply or remediate policies, making it reactive rather than proactive and less scalable for enforcement. Option B is wrong because manually retrieving and applying configurations with gcloud commands is error-prone, time-consuming, and does not scale across multiple clusters and projects, as it lacks automation and version control. Option C is wrong because Config Connector manages Google Cloud resources as Kubernetes custom resources, but it requires a Kubernetes cluster to run and is primarily designed for managing resources within a single project or from a central cluster, not for enforcing identical policies across multiple independent clusters in different projects.

413
MCQmedium

Your application exposes a REST API that external partners consume. You need rate limiting per partner (API key), usage analytics, and developer portal for onboarding. Traffic is currently 1,000 requests/day but expected to grow to 10M/day within a year. Which GCP service best fits these requirements?

A.Cloud Endpoints with Extensible Service Proxy
B.Apigee API Management
C.Cloud Armor with rate limiting rules
D.API Gateway with a backend Cloud Run service
AnswerB

Apigee provides per-API-key rate limiting, built-in analytics dashboards and a developer portal for partner onboarding, and its infrastructure scales to the projected 10M daily requests. Cloud Endpoints and API Gateway lack the full portal and quota-management feature set required here.

Why this answer

Apigee API Management is correct because it provides built-in rate limiting per API key (via quota policies), detailed analytics dashboards for usage tracking, and a developer portal for partner onboarding and key management. Unlike simpler API gateways, Apigee is designed for enterprise-grade API management at scale, handling growth from 1,000 to 10M requests/day with features like monetization, traffic management, and security policies.

Exam trap

Google Cloud often tests the distinction between a simple API gateway (like Cloud Endpoints or API Gateway) and a full API management platform (Apigee), where the presence of a developer portal and per-partner analytics is the key differentiator, not just rate limiting or traffic growth.

How to eliminate wrong answers

Option A is wrong because Cloud Endpoints with Extensible Service Proxy (ESP) is a lightweight API gateway that lacks a built-in developer portal and advanced analytics; it relies on Google Cloud's operations suite for basic metrics and does not offer per-partner rate limiting via API keys without custom code. Option C is wrong because Cloud Armor is a web application firewall (WAF) and DDoS protection service that can rate-limit by IP address, not by API key or partner, and it provides no developer portal or usage analytics per partner. Option D is wrong because API Gateway with a backend Cloud Run service is a managed gateway that supports rate limiting and basic analytics but lacks a developer portal for partner onboarding and is designed for simpler use cases, not the enterprise-grade API management and analytics required for 10M requests/day.

414
MCQmedium

A team is deploying a Cloud Function that requires a private environment variable containing an API key. They want the key stored securely and automatically injected at runtime. Which approach follows GCP best practices?

A.Hardcode the API key in the function source code
B.Pass the API key as a plain-text environment variable in the function configuration
C.Store the key in Secret Manager and reference it as a secret environment variable in the function deployment
D.Store the API key in a Cloud Storage bucket and download it at function startup
AnswerC

Storing the key in Secret Manager and referencing it as a secret environment variable is the correct approach because Cloud Functions integrates natively with Secret Manager through the --set-secrets flag. At runtime, the function's service account fetches the secret value using the IAM role roles/secretmanager.secretAccessor, and the secret is injected into the function environment without ever being stored in the function configuration or visible in the console, gcloud, or Cloud Monitoring metadata.

Why this answer

Secret Manager is the GCP-native service designed to securely store API keys and other sensitive data. By referencing a secret as an environment variable in the Cloud Function deployment configuration, the key is automatically decrypted and injected at runtime without exposing it in source code or configuration files. This follows the principle of least privilege and ensures the secret is encrypted at rest and in transit.

Exam trap

Google Cloud often tests the misconception that storing secrets in Cloud Storage with fine-grained ACLs is sufficient, but the trap here is that Secret Manager is the only service that provides automatic encryption, versioning, and audit logging for secrets without requiring custom code.

How to eliminate wrong answers

Option A is wrong because hardcoding the API key in source code exposes it in version control systems, logs, and build artifacts, violating security best practices. Option B is wrong because passing the API key as a plain-text environment variable in the function configuration stores it unencrypted in the deployment metadata and can be viewed in the Cloud Console or API responses. Option D is wrong because storing the key in a Cloud Storage bucket requires additional code to download and parse the file at startup, introduces latency, and risks exposing the key if bucket permissions are misconfigured or if the bucket is publicly accessible.

415
MCQeasy

A team's GKE application is running out of memory due to a memory leak. Pods are restarting with OOMKilled status. As an immediate measure before a code fix is available, what kubectl action provides the most insight into which container is leaking?

A.kubectl get events --field-selector=reason=OOMKilling
B.kubectl top pods --containers -n [NAMESPACE]
C.kubectl delete pod [POD_NAME] -- force=true to clear the memory leak
D.gcloud container clusters describe [CLUSTER] --memory-usage
AnswerB

`kubectl top pods --containers -n [NAMESPACE]` is the correct command because it queries the metrics-server API to show real-time CPU and memory utilization per individual container inside each Pod. This granularity is essential in GKE because a Pod often runs sidecars alongside the main application, and aggregating metrics at the Pod level can hide which container is consuming excessive memory. By comparing each container's usage to its requests and limits, you can pinpoint the leaking container and confirm the diagnosis before taking any remediation action.

Why this answer

`kubectl top pods --containers` shows per-container CPU and memory usage for each pod in the namespace. This allows you to identify which specific container within a pod is consuming excessive memory and triggering the OOMKilled status, even before a code fix is deployed. It provides immediate, real-time insight into resource consumption at the container level, which is essential for diagnosing a memory leak in a multi-container pod.

Exam trap

Google Cloud often tests the misconception that cluster-level or event-based commands (like `kubectl get events` or `gcloud container clusters describe`) provide container-level resource diagnostics, when in fact only `kubectl top` with the `--containers` flag gives per-container memory usage in real time.

How to eliminate wrong answers

Option A is wrong because `kubectl get events --field-selector=reason=OOMKilling` only shows that an OOMKill event occurred, but does not reveal which specific container within the pod leaked memory; it lacks the granularity needed to pinpoint the leaking container. Option C is wrong because `kubectl delete pod --force=true` merely terminates the pod, which does not provide any diagnostic insight into which container caused the memory leak; it is a destructive action that removes the evidence without analysis. Option D is wrong because `gcloud container clusters describe` does not support a `--memory-usage` flag; cluster-level description commands provide static configuration metadata, not real-time per-container memory metrics.

416
MCQhard

Your organization uses VPC Service Controls to protect BigQuery and Cloud Storage. A data pipeline service account needs to read from a protected Cloud Storage bucket and write results to a protected BigQuery dataset. Both resources are in the same perimeter. The service account is outside the perimeter (it runs in a Cloud Run service in a different project). How do you grant the pipeline access?

A.Add the Cloud Run project to the VPC Service Controls perimeter.
B.Create an Ingress Rule in the VPC-SC perimeter that allows the service account from the external project to access the specific BigQuery and Storage resources.
C.Grant the service account `roles/bigquery.admin` and `roles/storage.admin` to bypass the perimeter restrictions.
D.Move the Cloud Run service into a VPC and set up VPC peering to the perimeter VPC.
AnswerB

An ingress rule in VPC Service Controls is the precise mechanism for allowing an external identity, such as the Cloud Run service account, to access protected resources inside the perimeter. The rule specifies the source identity (the service account), the source project (the Cloud Run project), and the exact target resources (particular BigQuery datasets and Storage buckets), limiting exposure to only what the service genuinely needs. This is the least-privileged and context-aware approach, and it is the only option that correctly addresses the boundary enforcement.

Why this answer

VPC Service Controls (VPC-SC) allow you to define ingress rules that grant access to protected resources from identities outside the perimeter. In this scenario, the service account running in Cloud Run is outside the perimeter, so an ingress rule must explicitly permit that service account to access the specific BigQuery dataset and Cloud Storage bucket. This approach maintains the security boundary while enabling the required data pipeline access.

Exam trap

Google Cloud often tests the misconception that IAM roles can override VPC Service Controls, but the trap here is that VPC-SC operates independently of IAM and requires explicit ingress or egress rules for cross-perimeter access.

How to eliminate wrong answers

Option A is wrong because adding the entire Cloud Run project to the VPC-SC perimeter would extend the security boundary to include all resources in that project, which is overly permissive and may violate security policies. Option C is wrong because granting `roles/bigquery.admin` and `roles/storage.admin` does not bypass VPC-SC restrictions; VPC-SC enforces access controls at the network layer, and IAM roles alone cannot override perimeter boundaries. Option D is wrong because moving the Cloud Run service into a VPC and setting up VPC peering does not address VPC-SC restrictions; VPC peering operates at the network level and does not grant access to resources protected by VPC-SC.

417
Multi-Selectmedium

A DevOps engineer wants to set up budget alerts for a GCP project so that the finance team is notified when costs reach 50% and 90% of the budget. Which two configurations are required? (Choose TWO.)

Select 2 answers
A.Enable billing export to BigQuery
B.Create a budget in the Cloud Billing console
C.Set up a Cloud Function to monitor billing
D.Configure alert thresholds at 50% and 90%
E.Assign the roles/billing.admin IAM role to the finance team
AnswersB, D

Creating a budget in the Cloud Billing console is the foundational action that enables all budget alerting. You define the total budget amount, optionally scope it to specific projects, folders, or billing accounts, and then attach alert threshold rules. Without an actual budget object, there is nothing to trigger a notification, so this is the non-negotiable first step in the workflow.

Why this answer

Option B is correct because a Cloud Billing budget must first be created in the Cloud Billing console (or via the Billing Budgets API) before any cost-based notifications can be triggered; the budget defines the scope (project, folder, or billing account) and the amount against which spend is measured. Option D is correct because within that budget you must configure alert thresholds — setting them at 50% and 90% of the budget amount — which causes GCP to send email notifications (to billing admins and users, or to a Pub/Sub topic) when actual or forecasted spend crosses those percentages. Option A is not required: BigQuery billing export is only needed for detailed cost analysis and custom reporting, not for standard budget alerts.

Option C is not required because budget alerts are a native Cloud Billing feature and do not need a Cloud Function to poll or monitor costs. Option E is not required because the roles/billing.admin role grants broad billing account administration, whereas budget alert recipients are configured through the budget's notification settings rather than by granting that IAM role.

Exam trap

ACE often tests whether candidates over-engineer the solution by adding BigQuery export or Cloud Functions, when the question only requires the two native steps: create the budget and set the thresholds.

418
Multi-Selecthard

A DevOps engineer is responsible for deploying a new microservice to GKE. They need to expose the service externally on a static IP address and scale based on HTTP request load. Which THREE resources must be created? (Choose 3 correct answers.)

Select 3 answers
A.Ingress
B.Deployment
C.Service (type LoadBalancer)
D.ConfigMap
E.HorizontalPodAutoscaler
AnswersB, C, E

A Deployment is the core workload resource that declaratively manages a set of identical pods through a ReplicaSet. It defines the desired state—container image, replicas, and labels—and performs rolling updates and rollbacks, ensuring pods converge to that state. For a stateless microservice, a Deployment is mandatory to run the application reliably; scaling (manually or via HPA) and service selection all operate on the Deployment's pod labels. Without it, you would have no managed pod lifecycle, no self-healing, and no update strategy.

Why this answer

To expose a microservice externally with a static IP and load-based scaling, you typically create a Deployment, a Service of type LoadBalancer (which provisions a TCP load balancer with a static IP), and a HorizontalPodAutoscaler to scale based on CPU (or custom metrics). Ingress is not required if using LoadBalancer, but it's another option. ConfigMap is not needed for this.

419
MCQmedium

Microservices in a GKE cluster need to discover each other by name without using public DNS. Service A calls Service B at `http://service-b.production.svc.cluster.local`. Which GCP/Kubernetes feature provides this internal DNS resolution?

A.Cloud DNS private zone configured for the cluster's namespace
B.Kubernetes cluster DNS (CoreDNS) resolving Service names within the cluster
C.Anthos Service Mesh — required for service-to-service DNS
D.A custom /etc/hosts entry on each Pod
AnswerB

CoreDNS is the standard in-cluster DNS server for Kubernetes. It automatically creates DNS records for every Service in the format `[service].[namespace].svc.cluster.local`, so Pods can resolve those names to cluster IPs and reach Services without hardcoding IPs. This built-in DNS is the foundation of service-to-service discovery on GKE, requiring no additional configuration or external DNS infrastructure.

Why this answer

Kubernetes cluster DNS, typically implemented by CoreDNS, is the built-in mechanism that resolves Service names like `service-b.production.svc.cluster.local` to the corresponding ClusterIP. This allows Pods to discover each other by name without relying on external or public DNS. CoreDNS runs as a Deployment in the kube-system namespace and automatically creates DNS records for every Service based on its name and namespace.

Exam trap

The trap here is that candidates confuse Cloud DNS (a GCP-managed DNS service for VPCs) with Kubernetes cluster DNS, or assume that a service mesh like Anthos is necessary for internal service discovery, when in fact CoreDNS provides this capability out of the box in any standard GKE cluster.

How to eliminate wrong answers

Option A is wrong because Cloud DNS private zones are used for resolving custom domain names within a VPC network, not for Kubernetes internal Service DNS; the cluster's internal DNS is handled entirely by CoreDNS within the cluster. Option C is wrong because Anthos Service Mesh (based on Istio) provides traffic management, security, and observability, but it is not required for basic service-to-service DNS resolution; CoreDNS works independently of any service mesh. Option D is wrong because manually editing /etc/hosts on each Pod is impractical, does not scale, and would require constant updates as Services are added or removed; Kubernetes DNS automates this resolution dynamically.

420
MCQeasy

A developer deployed a new version of a Compute Engine instance but the startup script fails to run. The developer needs to debug the startup script. Which step should be taken first?

A.RDP into the instance and check the system logs.
B.Check the instance's metadata for startup script errors.
C.Recreate the instance with a new image.
D.Review the serial port 1 output in the Google Cloud console.
AnswerD

The serial port 1 (COM1) output in the Google Cloud console is the canonical way to see the full boot sequence, kernel messages, and any startup script output or errors. Unlike network-based access (RDP/SSH), serial output is available even if the instance has not fully booted or has no network connectivity. This is why Cloud Console provides a 'Serial port 1' view under the instance's 'Logs' section, and it is the first place to look for startup script failures.

Why this answer

Serial port 1 output in the Google Cloud console captures the instance's serial console logs, including startup script execution output and any errors. This is the first and most direct step to debug a failing startup script because it shows the script's stdout, stderr, and any system messages during boot, without requiring network access or additional tools.

Exam trap

The trap here is that candidates confuse checking instance metadata (which stores the script) with viewing execution logs (serial port output), or they assume RDP/SSH is available when the script failure may prevent those services from starting.

How to eliminate wrong answers

Option A is wrong because Compute Engine instances typically run Linux, not Windows, so RDP is not applicable; even for Windows instances, RDP may not be available if the startup script fails before the network stack is ready. Option B is wrong because the instance's metadata stores the startup script content and configuration, not runtime errors or execution logs; checking metadata will not show why the script failed. Option C is wrong because recreating the instance with a new image does not help debug the existing script failure; it would only reset the environment without revealing the root cause.

421
Multi-Selecthard

A team is deploying a containerized microservice on GKE. They want to ensure the service is externally accessible via a stable IP address and can automatically scale the number of pods based on CPU utilization. Which TWO actions should they perform?

Select 2 answers
A.Expose the deployment using kubectl expose deployment my-service --type=LoadBalancer
B.Set the service type as ClusterIP
C.Create a Cluster Autoscaler on the GKE cluster
D.Create a HorizontalPodAutoscaler targeting the deployment with kubectl autoscale deployment my-service --cpu-percent=80 --min=1 --max=10
E.Expose the deployment using kubectl expose deployment my-service --type=NodePort
AnswersA, D

Running `kubectl expose deployment my-service --type=LoadBalancer` creates a Service of type LoadBalancer, which on GKE signals the cloud controller manager to provision a Google Cloud TCP/UDP load balancer. This load balancer receives a stable external IP address that persists for the lifetime of the Service, independent of node lifecycle. It is the standard way to expose a single deployment to the internet, as it also automatically forwards traffic to the backing pods.

Why this answer

Option A is correct because exposing the deployment with `kubectl expose deployment my-service --type=LoadBalancer` creates a Kubernetes Service of type LoadBalancer, which on GKE provisions a Google Cloud external load balancer with a stable external IP address, satisfying the requirement for external accessibility via a stable IP. Option D is correct because `kubectl autoscale deployment my-service --cpu-percent=80 --min=1 --max=10` creates a HorizontalPodAutoscaler that scales the number of pods between 1 and 10 based on a target CPU utilization of 80%, directly fulfilling the automatic scaling requirement. Option B is incorrect because a ClusterIP service only provides an internal cluster-only virtual IP and is not externally accessible.

Option C is incorrect because a Cluster Autoscaler scales the number of nodes in the node pool, not the number of pods, so it does not address pod-level scaling based on CPU. Option E is incorrect because a NodePort service exposes the service on a static port on each node's IP, which is not a stable external IP address and is not the recommended approach for external access on GKE.

Exam trap

ACE often tests the confusion between Cluster Autoscaler (scales nodes) and HorizontalPodAutoscaler (scales pods), and between Service types (LoadBalancer vs. NodePort vs. ClusterIP) for external exposure with a stable IP.

422
MCQmedium

A Cloud Function needs to be triggered whenever a message is published to a Pub/Sub topic. Which 'gcloud functions deploy' command flag is required to set the trigger?

A.--trigger-topic
B.--trigger-http
C.--trigger-event
D.--trigger-bucket
AnswerA

This flag directly associates the Cloud Function with a Pub/Sub topic. When a message is published to that topic, Pub/Sub delivers it as an event to the function, which is how you configure a message-triggered function. Unlike other triggers, this is the standard and only appropriate flag for Pub/Sub message events in the gcloud beta functions deploy command. It ensures the function is invoked asynchronously with the message payload as the event data.

Why this answer

For a Cloud Function triggered by Pub/Sub messages, the required flag is --trigger-topic, which specifies the Pub/Sub topic name. This flag automatically wires the function as a subscriber to that topic and sets the correct event type.

Exam trap

ACE often tests the difference between --trigger-topic (Pub/Sub), --trigger-bucket (Cloud Storage), and --trigger-event (generic events) — candidates who haven't deployed Pub/Sub functions may pick --trigger-event by mistake.

How to eliminate wrong answers

Option B is wrong because --trigger-http deploys an HTTP-triggered function, not a Pub/Sub-triggered one. Option C is wrong because --trigger-event is used for generic event triggers (such as Cloud Storage or Firestore) and requires a separate --trigger-resource, not a Pub/Sub topic name. Option D is wrong because --trigger-bucket is specifically for Cloud Storage object events, not Pub/Sub messages.

423
MCQeasy

You need to add an IAM binding for a user to a project using the gcloud command. Which command should you use?

A.gcloud projects add-iam-policy-binding
B.gcloud iam service-accounts add-iam-policy-binding
C.gcloud projects set-iam-policy
D.gcloud iam roles update
AnswerA

gcloud projects add-iam-policy-binding PROJECT_ID --member=user:email@example.com --role=roles/viewer is the correct command because it performs an additive update to the project's IAM policy. It reads the current policy, appends the new binding (role + member) to the existing set, and writes the merged policy back atomically, leaving all other bindings untouched. This is the standard CLI operation for granting a specific role to a user at the project scope.

Why this answer

The correct command to add an IAM binding for a user to a project is gcloud projects add-iam-policy-binding, which modifies the project's IAM policy by granting a role to a member. This command is the standard way to manage project-level IAM bindings using gcloud. It requires the project ID, the member (user, group, or service account), and the role.

Exam trap

The trap is mixing up commands for different resource types (project vs. service account) and confusing IAM binding commands with role update commands.

How to eliminate wrong answers

Option B is wrong because gcloud iam service-accounts add-iam-policy-binding is used to grant roles on a service account resource, not on a project. Option C is wrong because gcloud projects set-iam-policy is not a valid gcloud command; IAM policies are modified via add-iam-policy-binding or set-iam-policy on some resources, but not with that exact syntax for projects. Option D is wrong because gcloud iam roles update modifies a custom role's permissions, not a user's IAM binding on a project.

424
MCQmedium

You want to allow a vendor to upload files to a specific Cloud Storage bucket in your project without creating a GCP account for them. The upload URL should expire after 24 hours. Which mechanism should you use?

A.Create a GCP service account for the vendor and share the key JSON file.
B.Generate a Signed URL with a 24-hour expiration for the specific bucket path.
C.Make the Cloud Storage bucket publicly writable and share the bucket URL.
D.Add the vendor's email to the bucket's IAM policy with Storage Object Creator role.
AnswerB

A signed URL with a 24-hour expiration provides a time-limited, authenticated upload (HTTP PUT) link for a specific Cloud Storage object path. The URL is signed with a service account private key that you retain, and the vendor does not need a Google account or any extra credentials—they simply perform an HTTP PUT to the unique, query-parameter-bearing URL. Once 24 hours pass, the link expires and access is automatically revoked, making it the ideal solution for a one-time, temporary external upload.

Why this answer

A signed URL allows time-limited, permissionless access to a specific Cloud Storage object or bucket path without requiring a GCP identity. The URL is cryptographically signed using a service account key, and the 24-hour expiration is set via the `expires` parameter. This meets the requirement of allowing the vendor to upload files without creating a GCP account.

Exam trap

Google Cloud often tests the distinction between identity-based access (IAM) and resource-based access (signed URLs), and the trap here is that candidates may confuse adding an email to IAM (which still requires a Google identity) with the truly identity-free, time-limited access provided by a signed URL.

How to eliminate wrong answers

Option A is wrong because creating a GCP service account and sharing the key JSON file effectively gives the vendor a GCP identity, which contradicts the requirement of not creating a GCP account for them; it also introduces long-term credential management risks. Option C is wrong because making the bucket publicly writable allows anyone on the internet to upload files indefinitely, which violates the 24-hour expiration requirement and poses a severe security risk. Option D is wrong because adding the vendor's email to the bucket's IAM policy requires the vendor to have a GCP account (or a Google account) to authenticate, which directly contradicts the requirement of not creating a GCP account for them.

425
Multi-Selecteasy

An engineer wants to view the current IAM policy for a project. Which TWO commands will accomplish this?

Select 2 answers
A.gcloud projects get-iam-policy my-project --format json
B.gcloud resource-manager folders get-iam-policy my-folder
C.gcloud iam service-accounts get-iam-policy my-sa@my-project.iam.gserviceaccount.com
D.gcloud projects get-iam-policy my-project
E.gcloud projects get-ancestors-iam-policy my-project
AnswersA, D

This is the correct command to retrieve the IAM policy for a specific project, and using `--format json` explicitly instructs the CLI to output the policy as a JSON object. The `--format` flag does not change the underlying policy data, but it provides a structured, machine-readable representation that is ideal for scripting with tools like `jq` or for programmatic inspection. Without this flag, the same data would be rendered in YAML by default, so this flag only ensures the output format is standard and predictable.

Why this answer

The gcloud projects get-iam-policy command retrieves the IAM policy for a project. The gcloud projects get-ancestors-iam-policy retrieves policies from ancestors, not the project itself. The other commands are for different purposes.

426
MCQhard

Your application running on GKE is experiencing intermittent 500 errors. You want to create an alert that fires when the 99th percentile latency exceeds 2 seconds OR when the error rate (5xx responses) exceeds 1% of all requests over a 5-minute window. You have Cloud Monitoring configured with the application exporting metrics via OpenTelemetry. What should you create in Cloud Monitoring?

A.Two separate alerting policies — one for latency and one for error rate — each with their own notification channel.
B.A single alerting policy with two conditions (p99 latency and error rate) joined with OR logic.
C.A log-based alert using Cloud Logging to detect 5xx response codes in access logs.
D.An SLO with error budget burn rate alerts configured in Cloud Monitoring.
AnswerB

A single alerting policy can define two separate conditions — one on p99 latency and one on 5xx error rate — and use an OR combiner so that the policy enters the firing state if either condition is breached. Each condition can be built on the appropriate Cloud Monitoring time series, such as a distribution-valued metric for the 99th percentile latency and a ratio metric for the error rate, with its own threshold and duration window. This approach creates a single incident and sends one notification when any condition fires, reducing noise while still covering both critical signals. It is also easier to maintain and update because the notification channels, documentation, and incident grouping are centralized in one policy.

Why this answer

Cloud Monitoring alerting policies support multiple conditions combined with AND/OR logic, allowing you to trigger a single alert when either the 99th percentile latency exceeds 2 seconds or the error rate exceeds 1% over a 5-minute window. This directly matches the requirement without needing separate policies or relying on log-based detection.

Exam trap

Google Cloud often tests the distinction between metric-based alerts and log-based alerts, and the trap here is that candidates may choose a log-based alert (Option C) because they associate error detection with logs, but the question explicitly states metrics are exported via OpenTelemetry, making metric-based alerts the correct and more efficient choice.

How to eliminate wrong answers

Option A is wrong because creating two separate alerting policies would result in two independent alerts, which is unnecessary and less manageable; Cloud Monitoring supports multiple conditions in a single policy with OR logic, making this approach inefficient. Option C is wrong because a log-based alert using Cloud Logging would only detect 5xx errors from access logs, but the question specifies that metrics are exported via OpenTelemetry, so a metric-based alert is more appropriate and avoids log parsing latency. Option D is wrong because an SLO with error budget burn rate alerts is designed for tracking service-level objectives over longer periods (e.g., 30 days), not for real-time threshold-based alerting on latency and error rate over a 5-minute window.

427
MCQeasy

A startup wants to run a small, event-driven application that processes files uploaded to Cloud Storage. The function should be triggered by object finalize events and should have a maximum execution time of 10 minutes. Which compute option is most cost-effective and easy to manage?

A.Compute Engine with a startup script
B.App Engine Standard
C.Cloud Run jobs
D.Cloud Functions (Gen 2)
AnswerD

Cloud Functions (Gen 2) is the right choice because it offers first-class event triggers from Cloud Storage through Eventarc, letting you run code directly when an object is finalized or deleted. It is fully serverless, scales automatically from zero, and you only pay for execution time, which is ideal for a small startup. The maximum timeout of 60 minutes comfortably covers the stated 10-minute processing requirement, and the function is invoked automatically without any polling or VM management.

Why this answer

Cloud Functions (Gen 2) is the most cost-effective and easy-to-manage option for event-driven applications triggered by Cloud Storage object finalize events, with a maximum execution time of 10 minutes. It provides serverless execution, automatic scaling, and native integration with Cloud Storage events. Gen 2 offers longer execution times (up to 60 minutes) and improved performance compared to Gen 1.

Exam trap

The trap is overlooking Cloud Functions' native event triggers and selecting other compute options that require more management or are not designed for event-driven workloads.

How to eliminate wrong answers

Option A is wrong because Compute Engine requires managing VMs, configuring triggers, and handling scaling, which is not cost-effective or easy to manage for a small event-driven app. Option B is wrong because App Engine Standard is designed for web applications and does not natively support Cloud Storage event triggers; it would require additional components. Option C is wrong because Cloud Run jobs are designed for batch or long-running containerized tasks, not for event-driven functions triggered by Cloud Storage events; Cloud Run services could be used but require more setup and are less integrated.

428
MCQeasy

A team is building a mobile app backend that requires real-time data synchronization across devices and offline support. The data model is simple and document-based. Which database service should they use?

A.Cloud Bigtable
B.BigQuery
C.Cloud SQL
D.Firestore
AnswerD

Firestore is a flexible, scalable NoSQL document database designed natively for mobile app development, with real-time listeners that push data changes to clients instantly and offline data persistence that automatically syncs when connectivity returns. Its client SDKs for iOS, Android, and web handle multi-device synchronization, conflict resolution, and data integrity out of the box, making it the ideal choice for this real-time mobile backend use case.

Why this answer

Firestore is a NoSQL document database that provides real-time synchronization and offline support for mobile and web applications. It is designed for mobile app backends with simple document-based data models, offering automatic scaling and strong consistency. Firestore's real-time listeners and offline persistence make it ideal for this use case.

Exam trap

ACE often tests the distinction between Firestore and Firebase Realtime Database; candidates might confuse the two, but Firestore is the newer, more scalable option with richer querying and offline support.

How to eliminate wrong answers

Option A is wrong because Cloud Bigtable is a high-performance NoSQL database for large analytical workloads, not for mobile app real-time synchronization; it lacks built-in offline support and real-time features. Option B is wrong because BigQuery is a serverless data warehouse for analytics, not a transactional database for mobile apps. Option C is wrong because Cloud SQL is a relational database that does not natively support real-time synchronization or offline support for mobile apps.

429
MCQmedium

You have a Compute Engine VM instance that is currently running. You need to resize it to a different machine type. What must you do first?

A.Stop the instance, then use gcloud compute instances set-machine-type, then start the instance.
B.Use gcloud compute instances update --machine-type while the instance is running.
C.Detach all disks, change machine type, then reattach disks.
D.Create a snapshot of the disk and use it to create a new instance with the desired machine type.
AnswerA

Stopping the instance transitions it to the TERMINATED state, which releases the underlying host resources while preserving the boot disk, metadata, and attachment of persistent disks. The `gcloud compute instances set-machine-type` command can then change the vCPU and memory allocation, and after that you start the instance. This is the correct workflow because Compute Engine rejects machine type changes on running instances.

Why this answer

Changing the machine type requires the VM to be in a stopped state. You must stop the instance, change the machine type, then start it.

430
MCQmedium

Your company runs a critical web application on Google Kubernetes Engine (GKE) with a regional cluster. The application uses a Cloud SQL instance for database. Recently, users have been experiencing intermittent connection timeouts. The application logs show database connection errors, but the Cloud SQL instance's CPU and memory usage are low. The GKE cluster and Cloud SQL are in the same region. You notice that the Cloud SQL instance is configured with a private IP address. What is the most likely cause of the timeouts?

A.The Cloud SQL instance is not configured with automatic failover.
B.The Cloud SQL instance's connection pool size is too small.
C.The GKE cluster is not using a Private Service Connect endpoint to reach Cloud SQL.
D.The GKE cluster's nodes are in a different VPC subnet than the Cloud SQL instance.
AnswerD

If the GKE cluster nodes are in a different VPC network/subnet than the Cloud SQL private IP allocation, they lack a route to the private IP range, causing intermittent connection timeouts.

Why this answer

Cloud SQL private IP connectivity is provided by Private Services Access, which creates a VPC peering connection to the Service Networking API. Private Service Connect is an alternative, not a requirement. If the GKE nodes are in a different VPC network/subnet than the Cloud SQL private IP allocation, they do not have a route to that private IP, so connections from the application time out even though the Cloud SQL instance itself is healthy.

Exam trap

Do not assume that Cloud SQL private IP requires a Private Service Connect endpoint. The standard mechanism is Private Services Access (VPC peering via Service Networking); Private Service Connect is optional. Also, same-region placement does not automatically make the private IP reachable.

How to eliminate wrong answers

Option A is wrong because automatic failover affects high availability during a zonal outage, not intermittent connection timeouts when CPU and memory are low. Option B is wrong because a small connection pool would cause connection refused errors or queueing, not timeouts, and the logs show database connection errors, not pool exhaustion. Option D is wrong because the GKE cluster and Cloud SQL are in the same region, and VPC subnets can be different as long as they are in the same VPC and have proper routing; the real issue is the lack of a Private Service Connect endpoint or VPC peering to expose the Cloud SQL private IP.

431
MCQmedium

A FinOps team wants to analyze daily GCP spending trends, allocate costs by team using labels, and create custom dashboards. Which configuration exports billing data for this analysis?

A.Enable Cloud Monitoring billing metrics and build dashboards in Metrics Explorer
B.Download the monthly billing PDF from the Console and import it into a spreadsheet
C.Enable Cloud Billing data export to BigQuery and query the exported dataset
D.Use the Cloud Billing API to pull cost data into Cloud Firestore nightly
AnswerC

Cloud Billing data export to BigQuery is the native, recommended way to access detailed billing data. Google Cloud automatically writes cost and usage line items, including project, SKU, service, usage amount, unit price, cost, and resource labels, into a BigQuery dataset multiple times a day, allowing you to run SQL queries to slice costs by project, label, service, or date for chargeback, budgeting, and trend analysis.

Why this answer

Exporting GCP billing data to BigQuery enables granular, daily cost analysis, label-based allocation, and custom dashboard creation via tools like Looker Studio. BigQuery's SQL interface allows querying detailed cost and usage data, which is essential for the FinOps team's requirements.

Exam trap

Google Cloud often tests the misconception that Cloud Monitoring or simple API pulls are sufficient for detailed cost analysis, but the exam expects candidates to recognize that BigQuery export is the only option that provides the required granularity, label support, and queryability for custom dashboards.

How to eliminate wrong answers

Option A is wrong because Cloud Monitoring billing metrics provide only aggregated, pre-defined cost views and lack the granular, label-based cost allocation and custom querying capabilities needed for detailed analysis. Option B is wrong because monthly billing PDFs offer only a high-level summary, not daily granularity or label-based cost breakdowns, and cannot be queried programmatically for custom dashboards. Option D is wrong because Cloud Firestore is a NoSQL document database not designed for cost analytics; using the Cloud Billing API to pull data into Firestore nightly would require custom code, lacks native querying for cost trends, and is not a standard or scalable approach for this use case.

432
MCQeasy

Which gcloud command is used to set the default project for a configuration profile?

A.gcloud init
B.gcloud config set project
C.gcloud projects set
D.gcloud projects list
AnswerB

gcloud config set project PROJECT_ID is the correct command because it updates the core/project property in the active gcloud configuration. This directly sets the default project used by subsequent gcloud commands when no --project flag or CLOUDSDK_CORE_PROJECT environment variable is provided. It is the standard, non-interactive method to change the current default project within a given configuration.

Why this answer

The command `gcloud config set project` is used to set the default project for the active configuration profile. It updates the `core/project` property in the active configuration, so subsequent gcloud commands use that project unless overridden. This is the standard way to change the default project without reinitializing the entire configuration.

Exam trap

ACE often tests the distinction between commands that initialize or list resources versus those that set configuration properties, causing candidates to confuse `gcloud init` with `gcloud config set project`.

How to eliminate wrong answers

Option A is wrong because `gcloud init` is an interactive command that initializes or reinitializes a configuration, and while it can set a default project, it is not the specific command used solely to set the default project. Option C is wrong because `gcloud projects set` does not exist; the correct command structure is `gcloud config set project`. Option D is wrong because `gcloud projects list` lists projects but does not set a default project.

433
MCQmedium

An organization wants to enforce a policy that disables the creation of VMs with external IPs across all projects. Which resource hierarchy level should the policy be attached to for maximum coverage?

A.Project
B.Resource (VM)
C.Organization
D.Folder
AnswerC

The organization node is the root of the GCP resource hierarchy, and it is the correct place to attach an organization-wide policy. Any IAM role binding or organization policy constraint set at this level is inherited by every folder, project, and resource in the hierarchy, thereby ensuring the policy is enforced across all projects while also applying automatically to any future projects created under the organization.

Why this answer

To enforce a policy across all projects, the policy must be attached at the highest level in the resource hierarchy: the organization. Organization policies are inherited by all descendant resources (folders, projects, and VMs), ensuring uniform enforcement. Attaching at lower levels would not cover all projects unless applied individually, which is inefficient and error-prone.

Exam trap

ACE often tests the resource hierarchy and policy inheritance, and candidates may incorrectly choose folder or project level, forgetting that only organization-level ensures maximum coverage.

How to eliminate wrong answers

Option A is wrong because a project-level policy only applies to that specific project, not all projects in the organization. Option B is wrong because attaching a policy to a resource (VM) is not supported for organization policies; policies are set at organization, folder, or project levels. Option D is wrong because a folder-level policy only applies to projects within that folder, not to all projects across the organization, leaving other folders unaffected.

434
MCQeasy

Where in the Google Cloud Console can a user view all APIs currently enabled for their project and monitor their usage?

A.Cloud Shell > Active Sessions
B.IAM & Admin > Service Accounts
C.APIs & Services > Dashboard
D.Monitoring > Metrics Explorer
AnswerC

APIs & Services > Dashboard is the correct destination because it is the single project-level overview of the Google Cloud API ecosystem. It shows which APIs are enabled, total usage metrics (requests and errors), and per-API quota utilization. From this page you can click through to individual API details, enable or disable APIs, and manage credentials—making it the canonical place to check API enablement status.

Why this answer

The 'APIs & Services > Dashboard' page in the Google Cloud Console provides a centralized view of all enabled APIs for a project, along with real-time usage metrics such as requests per second, error rates, and latency. This dashboard is the primary interface for monitoring API consumption and identifying throttling or quota issues.

Exam trap

The trap here is that candidates confuse the 'APIs & Services > Dashboard' with the 'Monitoring > Metrics Explorer' because both show usage data, but only the Dashboard provides a project-level view of enabled APIs and their aggregate usage in one place.

How to eliminate wrong answers

Option A is wrong because Cloud Shell > Active Sessions shows active terminal sessions in Cloud Shell, not API enablement or usage. Option B is wrong because IAM & Admin > Service Accounts is used to manage service account identities and keys, not to view enabled APIs or their usage metrics. Option D is wrong because Monitoring > Metrics Explorer is a tool for creating custom charts and alerts from Cloud Monitoring metrics, but it does not provide a consolidated list of enabled APIs for the project.

435
Matchingmedium

Match each Cloud Monitoring resource to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Measurable data point from a resource

Notification based on a condition

Customizable view of metrics

Monitors availability of a service

Metric derived from log entries

Why these pairings

Cloud Monitoring resources serve distinct purposes: Workspace organizes monitoring data, Alerting Policies define alert conditions, Notification Channels specify delivery methods, and Uptime Checks verify resource availability. The distractors confuse these roles.

436
MCQmedium

A company is deploying a microservices application on Google Kubernetes Engine (GKE). They want to expose their services to the internet using a single external IP address and route traffic based on the request path. Which resource should they use?

A.An Ingress resource
B.A Service of type NodePort
C.A Service of type LoadBalancer for each microservice
D.A Network Endpoint Group (NEG)
AnswerA

An Ingress resource is the Kubernetes API object that manages external HTTP(S) access to services, providing L7 load balancing with path-based and host-based routing. In GKE, it integrates with Google Cloud Load Balancing to expose all microservices through a single external IP address, forwarding requests to the appropriate backend Service based on the URL path. This makes it the correct choice for routing traffic to multiple microservices without creating separate external IPs.

Why this answer

An Ingress resource is the correct choice because it provides HTTP(S) layer 7 routing, allowing you to expose multiple services behind a single external IP address and route traffic based on request paths (e.g., /api to one service, /web to another). This meets the requirement of using one external IP and path-based routing, which a Service alone cannot achieve.

Exam trap

The trap here is that candidates often confuse a Service of type LoadBalancer with an Ingress, thinking that a LoadBalancer can also provide path-based routing, but a LoadBalancer operates at layer 4 (TCP/UDP) and cannot inspect HTTP paths, whereas Ingress operates at layer 7 and is specifically designed for such routing.

How to eliminate wrong answers

Option B is wrong because a Service of type NodePort exposes the service on a static port on each node's IP, but it does not provide a single external IP or path-based routing; it requires additional infrastructure (like an external load balancer) to route traffic. Option C is wrong because a Service of type LoadBalancer for each microservice would create a separate external IP per service, violating the requirement for a single external IP and not supporting path-based routing. Option D is wrong because a Network Endpoint Group (NEG) is a backend resource used with load balancers to specify endpoints (e.g., pods), but it does not itself expose services or route traffic based on request paths; it is a configuration component, not a routing resource.

437
MCQhard

A company manages a production GKE cluster with node auto-upgrade enabled. They want to ensure that during a node upgrade, the workloads are rescheduled gracefully without downtime. What Kubernetes resource should be configured on their Deployments?

A.PodDisruptionBudget
B.HorizontalPodAutoscaler
C.ResourceQuota
D.Node affinity rules
AnswerA

PodDisruptionBudget (PDB) is the correct answer because it is the Kubernetes object specifically designed to protect applications during voluntary disruptions, such as GKE node auto-upgrades that drain nodes. A PDB uses minAvailable or maxUnavailable to define how many pods must remain available during evictions; when a node is being upgraded, the eviction API checks the PDB and blocks eviction of a pod if it would violate the budget. This ensures the production workload retains a guaranteed number of replicas, preventing downtime during node maintenance.

Why this answer

A PodDisruptionBudget (PDB) limits the number of pods of a replicated application that can be voluntarily disrupted at once (via minAvailable or maxUnavailable). During node upgrades, GKE drains nodes by evicting pods, and the PDB ensures enough replicas remain available to serve traffic, preventing downtime.

Exam trap

ACE often tests the difference between PDB (voluntary disruption control) and HPA (scaling) — candidates pick HPA thinking more replicas automatically prevents downtime, but HPA does not gate evictions.

How to eliminate wrong answers

Option B is wrong because HorizontalPodAutoscaler scales replica count based on metrics like CPU or custom metrics; it does not govern how many pods can be evicted during a drain. Option C is wrong because ResourceQuota limits aggregate resource consumption (CPU, memory, object counts) per namespace, not disruption behavior. Option D is wrong because node affinity rules control which nodes pods are scheduled onto; they do not prevent simultaneous eviction of too many replicas during a node drain.

438
Multi-Selectmedium

A company wants to automate the response to specific log entries by triggering a Cloud Function. Which THREE components are required? (Choose 3)

Select 3 answers
A.Cloud Function (Pub/Sub trigger)
B.Cloud Logging log sink
C.Pub/Sub topic
D.BigQuery dataset
E.Cloud Monitoring notification channel
AnswersA, B, C

A Cloud Function with a Pub/Sub trigger is the compute piece that executes your custom response logic asynchronously. When a message lands on the subscribed topic, the function is invoked with the message payload, letting you parse the log data and call external APIs, send alerts, or modify resources. This event-driven model avoids maintaining a server and scales automatically with message volume. Without this function, the sink and topic would merely transport logs with no automated reaction.

Why this answer

Log entries must be routed to a Pub/Sub topic via a log sink. The Cloud Function subscribes to that topic (triggered by Pub/Sub). The log sink is the exporter, Pub/Sub is the intermediary, and Cloud Function is the action.

A notification channel is for alerts, not triggers. BigQuery is not needed.

439
MCQeasy

A startup's application uses both GCP services and an existing on-premises Kubernetes cluster. They want a single control plane to manage Kubernetes clusters across both environments with consistent policy enforcement. Which Google service provides this?

A.GKE Hub (Fleet management)
B.Anthos (Google Distributed Cloud) for hybrid multi-cluster management
C.Cloud Interconnect — connects on-premises clusters to GCP so they share a control plane
D.Cloud Composer — a managed Kubernetes workflow across environments
AnswerB

Anthos (Google Distributed Cloud) is a hybrid multi-cloud platform built on Kubernetes that provides consistent clusters across on-premises data centers, GCP, AWS, and Azure. It integrates Anthos Config Management for policy propagation, Anthos Service Mesh for traffic and observability, and a unified multicluster control plane, enabling consistent security, CI/CD, and application operations. This platform-level approach is what actually delivers unified hybrid multi-cluster management.

Why this answer

Anthos (Google Distributed Cloud) is the correct answer because it provides a unified control plane for managing Kubernetes clusters across on-premises and GCP environments, enabling consistent policy enforcement, configuration, and observability. Anthos uses GKE on-prem and GKE in the cloud, with a centralized Anthos Config Management and Service Mesh for policy and security consistency, directly addressing the hybrid multi-cluster management requirement.

Exam trap

The trap here is that candidates confuse GKE Hub (a fleet management feature) with the full Anthos platform, forgetting that GKE Hub alone does not manage on-premises clusters without Anthos GKE On-Prem.

How to eliminate wrong answers

Option A is wrong because GKE Hub (Fleet management) is a component within Anthos that provides a centralized view and policy management for GKE clusters, but it is not a standalone service that manages both on-premises and GCP clusters with a single control plane; it relies on Anthos for hybrid capabilities. Option C is wrong because Cloud Interconnect provides dedicated network connectivity between on-premises and GCP, but it does not provide a control plane for managing Kubernetes clusters; it is a networking service, not a cluster management service. Option D is wrong because Cloud Composer is a managed Apache Airflow workflow orchestration service, not a Kubernetes cluster management platform; it can run workflows across environments but does not provide a unified control plane or policy enforcement for Kubernetes clusters.

440
MCQeasy

An engineer needs to monitor the external HTTP availability of a web application hosted on Compute Engine. Which Cloud Monitoring feature should they use?

A.Uptime check
B.Dashboard
C.Metric Explorer
D.Log-based alert
AnswerA

An uptime check is a Cloud Monitoring synthetic probe that periodically sends an HTTP(S) request to the specified URL from configurable global locations. It validates availability by checking for expected HTTP status codes, response time thresholds, and optional content matches, and it emits metrics such as uptime, latency, and check success. This is the correct choice because it actively measures external HTTP reachability from outside the network, which is exactly what is needed to monitor external availability.

Why this answer

Uptime checks are designed to verify that a resource is accessible and measure response latency from various locations. They can check HTTP/HTTPS/TCP endpoints.

441
MCQhard

A media company ingests 500,000 events per second from IoT sensors and needs to store them for time-series analytics queries that scan billions of rows. Which storage service is most appropriate?

A.Cloud Firestore
B.Cloud SQL for MySQL
C.Cloud Bigtable
D.BigQuery streaming inserts
AnswerC

Cloud Bigtable is purpose-built for high-throughput, low-latency NoSQL workloads, including IoT time-series ingestion at 500K events/second. It scales linearly by adding nodes, supports millions of writes per second, and uses row keys like device timestamp to enable fast point reads and range scans. Its wide-column storage model is optimized for analytical patterns over sequential time-series data, making it the ideal choice over relational or document databases.

Why this answer

Cloud Bigtable is the most appropriate service because it is a fully managed, scalable NoSQL database designed for high-throughput, low-latency workloads like IoT sensor data ingestion at 500,000 events per second. It supports time-series analytics queries scanning billions of rows via its wide-column storage model and integration with BigQuery for complex analytics, while providing sub-10ms latency for point lookups and efficient range scans.

Exam trap

Google Cloud often tests the misconception that BigQuery streaming inserts are a storage service for high-ingestion workloads, but the trap here is that BigQuery is a data warehouse for analytics, not a low-latency storage system for time-series data, and its streaming limit is far lower than Bigtable's throughput.

How to eliminate wrong answers

Option A is wrong because Cloud Firestore is a document-oriented NoSQL database optimized for mobile and web app real-time synchronization, not for high-ingestion-rate time-series workloads; it has a maximum write rate of 10,000 writes per second per database, far below 500,000 events per second. Option B is wrong because Cloud SQL for MySQL is a relational database with limited horizontal scaling and a maximum of 30,000 queries per second for the highest tier, making it unsuitable for ingesting 500,000 events per second and scanning billions of rows. Option D is wrong because BigQuery streaming inserts are designed for real-time analytics ingestion into a data warehouse, but they have a per-project streaming limit of 100,000 rows per second (default) and are not optimized for sub-second point lookups or high-frequency time-series storage; Bigtable is the correct storage layer before streaming into BigQuery for analytics.

442
MCQmedium

A security team wants to centrally identify misconfigured GCP resources across their organization — such as publicly accessible Cloud Storage buckets, unencrypted disks, and overly permissive firewall rules. Which GCP service provides these findings?

A.Cloud Asset Inventory — query for all resources and write custom checks
B.Security Command Center (SCC) with Security Health Analytics enabled
C.Cloud Monitoring alert policies with metric conditions for firewall rule changes
D.Cloud Logging audit log analysis for admin activity changes
AnswerB

Security Command Center (SCC) with Security Health Analytics enabled is the correct choice because it automatically runs continuous, built-in scans for known security misconfigurations and vulnerabilities across your GCP resources. It uses detectors based on CIS benchmarks and other GCP best practices, surfacing findings such as publicly exposed Cloud Storage buckets, overly permissive firewall rules, and non-compliant IAM bindings at the organization, folder, and project level. It provides a centralized dashboard and API to see the current security posture without requiring custom logic or manual log parsing.

Why this answer

Security Command Center (SCC) with Security Health Analytics enabled is the correct service because it provides built-in, automated scanning for common misconfigurations such as publicly accessible Cloud Storage buckets, unencrypted disks, and overly permissive firewall rules. Security Health Analytics uses a set of pre-defined detectors (e.g., `PUBLIC_BUCKET_ACL`, `DISK_ENCRYPTION_DISABLED`, `FIREWALL_RULE_OPEN`) to continuously assess resources and surface findings in the SCC dashboard, without requiring custom code or manual queries.

Exam trap

The trap here is that candidates often confuse Cloud Asset Inventory's ability to list all resources with the ability to automatically detect misconfigurations, when in reality it only provides raw resource metadata and requires custom logic to identify security issues.

How to eliminate wrong answers

Option A is wrong because Cloud Asset Inventory is a metadata and history service for querying resource snapshots and changes, but it does not have built-in detectors for security misconfigurations; it requires writing custom checks or exporting data to other tools to identify issues like public buckets or unencrypted disks. Option C is wrong because Cloud Monitoring alert policies with metric conditions can notify on firewall rule changes (e.g., via metric `firewall_rule_count`), but they cannot directly detect the misconfiguration (e.g., overly permissive rules) — they only react to change events, not assess the security posture of the rule itself. Option D is wrong because Cloud Logging audit log analysis for admin activity changes can track who changed a firewall rule or bucket ACL, but it does not evaluate whether the resulting configuration is insecure (e.g., public access or missing encryption); it provides an audit trail, not a security assessment.

443
Drag & Dropmedium

Arrange the steps to deploy a containerized application to Google Kubernetes Engine (GKE) using a Deployment and expose it via a Service.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for deploying a containerized application to GKE is to first create a GKE cluster (the underlying infrastructure), then deploy your application using a Kubernetes Deployment, and finally expose that Deployment via a Service to allow external access. This order ensures all dependencies are met: the cluster must exist before any workloads are created, and the Service references an existing Deployment.

444
Multi-Selectmedium

Your company has a production project and a development project. You want to ensure that no one can delete the production project accidentally. Which TWO actions should you take? (Choose 2)

Select 2 answers
A.Apply an organization policy constraint that blocks project deletion.
B.Set a deletion protection policy on the project.
C.Set a budget alert at 100% of projected spend.
D.Remove the Owner role from all users and grant only Editor.
E.Add a label to the project indicating it is production.
AnswersA, B

Organization policy constraints are centralized guardrails evaluated by Google Cloud Resource Manager before IAM. Applying a boolean constraint such as `constraints/resourcemanager.projectDelete` at the organization or folder level explicitly denies the `resourcemanager.projects.delete` action for every principal, overriding project-level IAM roles. This makes it an authoritative, non-bypassable control that prevents a production project from being deleted from any console or API path.

Why this answer

To prevent accidental deletion, you can set a deletion protection policy at the project level. Additionally, using an organization policy constraint 'constraints/resourcemanager.projectDelete' at the folder or organization level can block deletion. Labels don't prevent deletion.

Removing the Owner role from all users would break management. Budget alerts don't prevent deletion.

445
MCQeasy

A developer accidentally grants the Owner role to a test service account on the production project. The team wants to remove only this specific IAM binding without affecting other members' access. Which gcloud command achieves this?

A.gcloud projects set-iam-policy [PROJECT] --member=serviceAccount:[SA] --role=roles/owner
B.gcloud projects remove-iam-policy-binding [PROJECT] --member=serviceAccount:[SA_EMAIL] --role=roles/owner
C.gcloud iam remove-binding --project=[PROJECT] --member=[SA] --role=owner
D.gcloud projects delete-member [PROJECT] --member=serviceAccount:[SA_EMAIL]
AnswerB

This is the correct command because it surgically removes the specified service account from the roles/owner role on the project while leaving every other IAM binding untouched. The command takes the project name, member string in serviceAccount: format, and role ID to precisely identify the binding to delete. It is the safe, expected way to revoke a single principal's role, and it performs an atomic update to the IAM policy without requiring you to fetch or rewrite the entire policy.

Why this answer

`gcloud projects remove-iam-policy-binding` is the precise command to remove a single IAM binding (member-role pair) from a project's policy without affecting other bindings. It takes the project ID, member (service account email), and role as parameters, ensuring only the specified binding is removed. This command modifies the existing policy by removing only that specific entry, leaving all other IAM bindings intact.

Exam trap

Google Cloud often tests the distinction between commands that modify the entire policy (`set-iam-policy`) versus those that surgically remove a single binding (`remove-iam-policy-binding`), and candidates may confuse the valid command syntax or assume a generic `remove-binding` subcommand exists.

How to eliminate wrong answers

Option A is wrong because `gcloud projects set-iam-policy` replaces the entire IAM policy for the project with a new policy file; it does not remove a single binding and would overwrite all existing permissions if used incorrectly. Option C is wrong because `gcloud iam remove-binding` is not a valid gcloud command; the correct verb is `remove-iam-policy-binding` under the `projects` resource, and the role flag should be `roles/owner` not `owner`. Option D is wrong because `gcloud projects delete-member` is not a valid gcloud command; there is no such subcommand for removing a member from a project.

446
MCQmedium

A Cloud Run service is experiencing high latency. You suspect one revision is causing the issue. The service is configured to split traffic 90% to revision A and 10% to revision B. You want to gradually shift traffic back to revision A only. Which command should you use?

A.kubectl set traffic my-service --revision=my-service-00001=100
B.gcloud run services update-traffic my-service --to-revisions=my-service-00001=100
C.gcloud run revisions delete my-service-00002
D.gcloud run services update my-service --set-revision my-service-00001
AnswerB

This is the correct, supported command for adjusting traffic on a Cloud Run service. The 'update-traffic' subcommand directly modifies the revision routing percents, and '--to-revisions' allows explicit targeting of a specific revision; here, setting 'my-service-00001=100' routes all live traffic to the known-good revision A. This immediately reduces load on the suspect revision B and is exactly how you roll back a bad deployment on Cloud Run.

Why this answer

The `gcloud run services update-traffic` command is the correct tool for adjusting traffic distribution across Cloud Run revisions. Using `--to-revisions=my-service-00001=100` assigns 100% of traffic to revision A (my-service-00001), effectively removing revision B from the serving path. This is the supported, declarative way to shift traffic on a Cloud Run service without redeploying.

Exam trap

The trap here is confusing kubectl syntax with gcloud syntax — candidates who work with Kubernetes may instinctively pick the kubectl option, but Cloud Run traffic management is exclusively a gcloud/API operation.

How to eliminate wrong answers

Option A is wrong because `kubectl set traffic` is not a valid kubectl subcommand — Cloud Run traffic management is done through gcloud or the Cloud Run Admin API, not kubectl. Option C is wrong because deleting revision B does not shift traffic to revision A; it only removes the revision, and traffic would still need to be reassigned explicitly. Option D is wrong because `gcloud run services update --set-revision` is not a valid flag; the correct flag for traffic assignment is `--to-revisions` under `update-traffic`.

447
MCQhard

A security auditor needs to check whether a specific user (user@company.com) currently has sufficient permissions to delete a Cloud SQL instance in project 'prod-db'. Without making any changes, which tool simulates this check?

A.Run the delete command with `--dry-run` flag to simulate without executing
B.Use the IAM Policy Troubleshooter (Policy Simulator) to check if the permission is granted
C.Inspect the IAM policy with `gcloud projects get-iam-policy` and manually trace inheritance
D.Grant the user the permission temporarily, test the delete, then revoke it
AnswerB

The IAM Policy Troubleshooter (also known as the Policy Simulator in some contexts) calculates the effective IAM policy for a specific principal, permission, and resource, taking into account inherited roles, group memberships, conditional bindings, and deny policies. For a Cloud SQL delete, it can verify whether the principal has the `cloudsql.instances.delete` permission. It provides an immediate, non-destructive answer through the Cloud Console or the `gcloud policy-troubleshoot` CLI, without requiring any policy changes.

Why this answer

The IAM Policy Troubleshooter (Policy Simulator) is the correct tool because it allows you to check whether a specific user has a particular permission (e.g., cloudsql.instances.delete) on a given resource (the Cloud SQL instance in project 'prod-db') without making any changes. It evaluates the effective IAM policy, including all inherited roles and policies, and returns a result indicating whether the permission is granted. This directly addresses the auditor's need to simulate a permission check without executing any action.

Exam trap

Google Cloud often tests the misconception that a dry-run flag or manual policy inspection is sufficient for permission checks, but the trap here is that only the IAM Policy Troubleshooter provides a comprehensive, no-change simulation that evaluates all policy types and inheritance paths, which is essential for security audits.

How to eliminate wrong answers

Option A is wrong because the `--dry-run` flag is not supported by the `gcloud sql instances delete` command; Cloud SQL does not implement a dry-run mode for deletion operations, and even if it did, it would simulate the deletion action itself, not check permissions. Option C is wrong because manually inspecting the IAM policy with `gcloud projects get-iam-policy` and tracing inheritance is error-prone, time-consuming, and does not account for all policy types (e.g., deny policies, conditional roles, or resource-level policies) that the Policy Troubleshooter evaluates automatically. Option D is wrong because granting the user the permission temporarily, testing the delete, and then revoking it is an insecure and disruptive approach that changes the environment, violates the 'without making any changes' requirement, and could lead to unintended consequences or audit compliance issues.

448
Multi-Selectmedium

An engineer is setting up a new GCP project for a containerized application. They need to enable the required APIs. Which TWO APIs must be enabled to deploy and manage a Kubernetes cluster and build container images?

Select 2 answers
A.compute.googleapis.com
B.bigquery.googleapis.com
C.cloudbuild.googleapis.com
D.container.googleapis.com
E.cloudfunctions.googleapis.com
AnswersC, D

Cloud Build is Google Cloud's CI/CD service that can compile source code and build Docker container images. If the engineer's containerized application is built from a repository, enabling cloudbuild.googleapis.com is required before Cloud Build can push built images to Container Registry or Artifact Registry. Thus, for a project that automates image creation for GKE, this API is a correct and necessary dependency.

Why this answer

Kubernetes Engine API and Cloud Build API are needed for cluster management and building images.

449
Multi-Selectmedium

A company needs to audit all actions that modify a Cloud Storage bucket. Which TWO steps should they take to enable this? (Choose 2 answers.)

Select 2 answers
A.Use Log Explorer to filter logs by the Cloud Storage service and the 'data_access' log type.
B.Create a VPC Service Controls perimeter.
C.Enable Admin Activity audit logs for the Cloud Storage service.
D.Assign the roles/logging.viewer role to the security team.
E.Enable Data Access audit logs for the Cloud Storage service in the project's IAM audit config.
AnswersA, E

Using Log Explorer in the Google Cloud console lets you query and filter audit logs once they are enabled. By applying a filter for the Cloud Storage service and the 'data_access' log type, you can view object-level operations such as writes, deletes, and overwrites. This is the final step that makes the audit trail visible and actionable for compliance, but it requires Data Access logging to already be enabled in the IAM audit config.

Why this answer

To audit data access modifications, you need to enable Data Access audit logs for the storage service and then view those logs in Log Explorer. Admin Activity logs record configuration changes (like creating a bucket), but data modifications (like uploading objects) require Data Access logs.

450
MCQmedium

A team discovers their Cloud Logging costs are unexpectedly high. The majority of costs come from verbose DEBUG-level logs from a development service in production. They want to stop storing DEBUG logs without modifying the application. What is the solution?

A.Set the application's log level to INFO — this is the only way to reduce log volume
B.Create a Cloud Logging exclusion filter to discard DEBUG-level log entries from the service
C.Move the development service to a separate GCP project with a lower logging tier
D.Delete old DEBUG log entries manually — Cloud Logging charges for stored volume
AnswerB

A Cloud Logging exclusion filter in the Log Router can match DEBUG entries from the service's resource type (e.g., `resource.type="cloud_run_revision"` and `severity=DEBUG`) and discard them before they are written to any sink or storage. Because exclusion filters are evaluated during ingestion, the matched entries are never billed, so this reduces logging costs immediately without code changes or redeployment. The application can keep emitting DEBUG logs; Log Router simply drops them, making this the operational solution that directly addresses the cost driver.

Why this answer

Cloud Logging exclusion filters allow you to discard log entries based on criteria such as severity level, log name, or resource labels before they are ingested and stored. By creating an exclusion filter that matches DEBUG-level log entries from the specific development service, you can stop storing those logs without modifying the application code. This approach directly reduces storage costs because excluded logs are not indexed or retained.

Exam trap

The trap here is that candidates may think modifying the application's log level is the only way to reduce log volume, but Cloud Logging exclusion filters provide a non-invasive, infrastructure-level solution that avoids code changes.

How to eliminate wrong answers

Option A is wrong because setting the application's log level to INFO would require modifying the application code or configuration, which the question explicitly states is not allowed. Option C is wrong because moving the service to a separate GCP project does not reduce log volume; it merely shifts the cost to another project, and Cloud Logging charges are based on ingestion and storage regardless of project. Option D is wrong because deleting old DEBUG log entries manually does not prevent future DEBUG logs from being ingested and stored, and Cloud Logging charges are primarily for ingestion volume, not just stored volume.

Page 5

Page 6 of 11

Page 7

All pages