ACE · domain
Configuring Access and Security
This domain covers Google Cloud IAM, service accounts, firewall rules, CMEK, VPC Service Controls, and audit logging. Questions present concrete scenarios—folder-level bindings, log retention, key rotation, rule priority conflicts—and ask you to pick the least-privilege, most correct configuration or predict the resulting behavior.
Focused practice
Practice Configuring Access and Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Configuring Access and Security
Be able to choose the correct IAM binding scope, enable and export Data Access logs with Bucket Lock, predict firewall rule outcomes from priority and ranges, and explain CMEK key rotation effects. The single most important thing: apply least privilege at the right resource hierarchy level.
IAM policy bindings at organization, folder, project, and resource levels using predefined and custom roles
Cloud Audit Logs: Admin Activity, Data Access, and immutable retention via Cloud Storage buckets with Bucket Lock
VPC firewall rule evaluation by priority, direction, and source ranges with implied deny rules
Cloud KMS CMEK configuration and key rotation impact on Cloud SQL and other CMEK-integrated services
Watch out for
Common Configuring Access and Security exam traps
- ▸Granting roles at project level when a folder-level binding would satisfy the requirement with less administrative overhead and broader consistent coverage.
- ▸Assuming Data Access logs are enabled by default; they must be explicitly enabled per service and exported for long-term immutable retention.
- ▸Forgetting that firewall rules are evaluated by priority number, where lower numbers win, and that a matching deny overrides a matching allow.
Question index
All Configuring Access and Security questions (75)
Click any question to see the full explanation, or start a practice session above.
An engineer needs to allow HTTP traffic from the internet to a set of Compute Engine instances that have the network tag 'web-server'. The instances are in a VPC with a default firewall rule that denies all ingress. Which command creates the required firewall rule?
Medium2An engineer wants to create a VPC with a custom subnet mode and then create a subnet with Private Google Access enabled. Which two commands should they use? (Choose TWO.)
Medium3To meet compliance requirements, a company must encrypt all data at rest in Cloud SQL using customer-managed encryption keys (CMEK). What is required to enable CMEK on a Cloud SQL instance?
Medium4You need to allow a Compute Engine instance to securely access a Cloud Storage bucket without managing service account keys. The instance already has a service account attached. What is the best practice to grant access?
Medium5An organization wants to enforce that all Compute Engine instances in a project use customer-managed encryption keys (CMEK) for their boot disks. Which TWO steps should the security team take?
Medium6Which IAM role should be granted to a user to allow them to create and manage secrets in Secret Manager?
Easy7You need to allow inbound HTTP traffic to a set of Compute Engine instances that have the tag 'web-server'. All other inbound traffic should be denied. Which firewall rule configuration should you create?
Easy8A developer wants to allow a Compute Engine instance to access Cloud Storage without using a service account key file. What is the recommended approach?
Medium9An organization has a hierarchy: Organization -> Folder A -> Project 1. An IAM policy at the organization level grants roles/editor to user@example.com. A policy at Folder A denies roles/editor to the same user. What is the effective role for the user in Project 1?
Hard10A company has a Cloud SQL instance with CMEK enabled. The Cloud KMS key used for encryption is accidentally disabled. What is the impact on the Cloud SQL instance?
Medium11You need to view the current IAM policy for a project named 'my-project' in JSON format. Which command should you use?
Easy12An engineer is configuring a Cloud NAT to allow private Compute Engine instances to access the internet. After creating the Cloud Router and NAT gateway, the instances still cannot connect to the internet. What is the most likely missing configuration?
Hard13A DevOps engineer needs to grant a service account the ability to pull images from a specific Container Registry repository in project 'my-project'. The service account is in project 'other-project'. Which command should the engineer use?
Medium14A security engineer wants to audit all attempts to access a specific Cloud Storage bucket, including successful and failed read requests. Which THREE steps should they take? (Choose THREE)
Medium15A developer wants to create a service account for an application running on Compute Engine. The application needs to access Cloud Storage. What is the best practice for granting this access?
Medium16An engineer needs to view the current IAM policy for a project in JSON format. Which gcloud command should they use?
Easy17You are configuring a Cloud NAT to allow private Compute Engine instances to access the internet for updates. What other resource is required to set up Cloud NAT?
Medium18A security team wants to restrict access to a Cloud Storage bucket so that only objects encrypted with a specific CMEK key can be uploaded. Which three actions are needed? (Choose 3)
Medium19Which Google Cloud service provides a managed, scalable, and secure way to store API keys, passwords, and certificates?
Easy20A security team wants to ensure that all Compute Engine instances in a project automatically use a custom service account with minimal permissions. What must the engineer do when creating new instances?
Medium21A developer needs to store a database password in Secret Manager and then allow a Compute Engine instance to access it. The instance uses the default compute engine service account. Which role should be granted to the service account?
Medium22An engineer wants to allow HTTP traffic from the internet to a set of Compute Engine instances that have the network tag 'web-server'. Which firewall rule should they create?
Easy23A company wants to use Customer-Managed Encryption Keys (CMEK) for a Cloud SQL instance. What must be done first?
Medium24A company has a VPC with a subnet that has Private Google Access enabled. They want their Compute Engine instances to access Google APIs and services through internal IP addresses. Which additional configuration is required?
Medium25An engineer needs to audit all Data Access logs for a project to detect unauthorized access to sensitive data. The engineer must ensure that logs are retained for 5 years and are immutable. Which THREE steps should the engineer take?
Hard26You want to view the current IAM policy for a project in JSON format using the gcloud command-line tool. Which command should you run?
Easy27An engineer needs to view the current IAM policy for a project in JSON format to analyze bindings. Which command should be used?
Medium28An organization has multiple projects under a folder. They want to grant a network admin the ability to create firewall rules in all projects in the folder. Which IAM policy binding achieves this with least privilege?
Medium29You need to store a database password securely in Google Cloud. The password will be used by a Compute Engine instance. Which service should you use?
Easy30A company has an organization with multiple folders and projects. They want to audit all IAM policy changes across the entire organization. Which approach meets the requirement with minimal effort?
Hard31A developer needs to allow a Compute Engine instance to access a Cloud Storage bucket without using a service account key file. The instance runs in a project that has the necessary APIs enabled. What should the developer do?
Easy32An engineer wants to create a Google-managed SSL certificate for an HTTPS load balancer. Which command should they use?
Medium33An engineer needs to allow a set of Compute Engine instances (with tag 'web-server') to receive traffic on port 443 from the internet. The VPC has a default network with default firewall rules. Which TWO actions should the engineer take? (Choose TWO)
Medium34An engineer needs to create a firewall rule that allows incoming HTTPS traffic only from a specific IP range to instances tagged 'web-server'. Which command should they use?
Medium35An engineer wants to create a Google-managed SSL certificate for a domain and attach it to an HTTPS load balancer. Which gcloud command should they use to create the certificate?
Easy36An engineer wants to view the current IAM policy for a project in JSON format. Which command should they use?
Medium37An engineer needs to grant an external auditor read-only access to view IAM policies on a GCP project. The auditor should not have access to any other resources. Which IAM role should be assigned?
Medium38An organization has a folder hierarchy with multiple projects. They want to grant a support team the ability to view all IAM policies across the entire folder. What is the most efficient way?
Hard39A company has multiple VPC networks in their project. They want Compute Engine instances in one VPC to communicate with instances in another VPC using internal IP addresses. Which feature should they use?
Medium40A company has a Google Cloud organization with multiple folders and projects. The security team wants to audit all actions that create or modify IAM policies across the entire organization. Which type of audit log should they examine?
Hard41You need to add an IAM binding for a user to a project using the gcloud command. Which command should you use?
Easy42An engineer wants to view the current IAM policy for a project. Which TWO commands will accomplish this?
Easy43A company needs to audit all actions that modify a Cloud Storage bucket. Which TWO steps should they take to enable this? (Choose 2 answers.)
Medium44An organization needs to audit all data access (read/write) to a Cloud Storage bucket for compliance. Which type of audit log should they enable?
Medium45A company wants to automate the rotation of encryption keys for Cloud Storage buckets every 30 days. Which key type should be used?
Easy46You need to create a service account for a Compute Engine instance to allow it to access Cloud Storage objects. The service account should have minimal permissions. What is the recommended approach?
Medium47You need to create a Google-managed SSL certificate for an external HTTPS load balancer. The domain is 'www.example.com'. Which command creates the certificate?
Easy48Which of the following is required to enable Private Google Access on a subnet?
Easy49A company wants to implement a least-privilege security model for a service account that needs to read secrets from Secret Manager and publish messages to Pub/Sub. Which TWO IAM roles should be granted? (Choose TWO)
Hard50An engineer needs to enable Private Google Access for a subnet to allow instances without external IPs to access Google APIs and services. Which flag should be used when creating or updating the subnet?
Medium51A company wants to allow developers to create and manage secrets in Secret Manager, but prevent them from viewing secret values. Which TWO predefined roles should be combined to achieve this?
Hard52You need to grant a user the ability to view audit logs for a project but not modify any resources. Which predefined IAM role should you assign?
Easy53A security team wants to audit all Data Access attempts in a project for a specific Cloud Storage bucket, including who accessed which object and when. Which configuration is required?
Medium54An organization uses Organization Policies to restrict the use of certain IAM roles. The security team wants to audit all modifications to IAM policies across the organization, including at the project level. Which log type should be enabled and analyzed?
Hard55An organization wants to use Cloud NAT to allow private Compute Engine instances to access the internet for updates. They have a VPC with a custom subnet and a Cloud Router configured. However, instances cannot reach the internet. What is the most likely cause?
Hard56A company is using Cloud NAT to allow private Compute Engine instances to access the internet. They notice that traffic from some instances is not being NATed. What is the most likely cause?
Hard57What is the primary benefit of using a Google-managed SSL certificate for an HTTPS Load Balancer?
Easy58A developer wants to automate the creation of a service account and assign it a role using the gcloud command-line tool. Which TWO commands are needed? (Choose 2 answers.)
Medium59Which IAM role should be granted to a service account to allow it to access a secret stored in Secret Manager?
Easy60A developer wants to store a database password securely and make it accessible to a Compute Engine instance. Which Google Cloud service should be used?
Easy61An engineer creates a firewall rule allowing ingress on port 8080 from source range 10.0.0.0/8 with priority 1000. Another rule denies ingress on port 8080 from source range 10.0.0.0/24 with priority 500. What is the effective behavior for traffic from 10.0.0.1?
Medium62An organization wants to enable Data Access audit logs for all Cloud Storage buckets in a project. Which step is necessary?
Hard63Which THREE configurations are required to enable Private Google Access for Compute Engine instances in a custom VPC subnet? (Select 3 correct answers)
Hard64Which command is used to view the current IAM policy for a Google Cloud project in JSON format?
Easy65A company uses Cloud SQL with Customer-Managed Encryption Keys (CMEK). The security team wants to rotate the encryption key. What is the impact on the Cloud SQL instance?
Hard66A DevOps team needs to grant a CI/CD service account the ability to create secrets in Secret Manager. Which role should be assigned?
Medium67A security engineer needs to ensure that all VMs in a subnet use Private Google Access to reach Google APIs without external IP addresses. What must be enabled?
Medium68An organization has a requirement that all Compute Engine instances must be able to access only a specific set of Google Cloud APIs, and no others. The security team wants to enforce this using IAM and access scopes. Which combination should they use?
Hard69A company has multiple firewall rules. Rule A (priority 1000) allows TCP 80 from 0.0.0.0/0. Rule B (priority 500) denies TCP 80 from 10.0.0.0/8. An instance with IP 10.0.0.1 tries to connect to TCP 80. What happens?
Hard70A company is using Cloud Identity and wants to grant a group of auditors read-only access to all resources in a project, but they must not be able to modify any IAM policies. Which two roles should be granted to the group? (Choose two.)
Medium71What is the purpose of creating a Cloud NAT gateway?
Easy72An engineer created a VPC with a subnet in us-central1 and enabled Private Google Access on that subnet. Compute Engine instances in that subnet can reach Google APIs and services using internal IPs. However, the instances cannot reach external IP addresses on the internet. What should the engineer configure to allow internet access while minimizing cost and management overhead?
Hard73An organization uses Secret Manager to store database credentials. A new application runs on Compute Engine and needs to access a secret. The application uses the default compute engine service account. What is the most secure way to grant access to the secret?
Hard74Which command creates a Google-managed SSL certificate for the domain 'example.com'?
Easy75A developer created a service account with the roles/storage.admin role and wants to use it from a Compute Engine instance without downloading a key file. What is the best practice?
HardOther domains
All ACE exam domains
Frequently asked questions
- What does the Configuring Access and Security domain cover on the ACE exam?
- Be able to choose the correct IAM binding scope, enable and export Data Access logs with Bucket Lock, predict firewall rule outcomes from priority and ranges, and explain CMEK key rotation effects. The single most important thing: apply least privilege at the right resource hierarchy level.
- How many questions are in this domain?
- This page lists all 75 Configuring Access and Security questions in the ACE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Configuring Access and Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.