Courseiva

CCNA Configuring Access and Security Questions

75 questions · Configuring Access and Security · All types, answers revealed

1
MCQmedium

An engineer needs to allow HTTP traffic from the internet to a set of Compute Engine instances that have the network tag 'web-server'. The instances are in a VPC with a default firewall rule that denies all ingress. Which command creates the required firewall rule?

A.gcloud compute firewall-rules create allow-http --allow tcp:80 --source-tags web-server
B.gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges web-server
C.gcloud compute firewall-rules create allow-http --allow http --target-tags web-server
D.gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges 0.0.0.0/0 --target-tags web-server
AnswerD

This command correctly opens inbound TCP port 80 to traffic from any IPv4 address (0.0.0.0/0) and applies the rule only to VM instances tagged with 'web-server', matching the requirement precisely. The combination of --source-ranges 0.0.0.0/0 for internet sources and --target-tags web-server to scope the rule to the intended backend VMs is the standard way to allow HTTP in GCP. No other flags are needed, and the protocol:port syntax 'tcp:80' is accurately specified.

Why this answer

The rule must allow TCP port 80 from source 0.0.0.0/0 to instances with target tag 'web-server'. The correct command uses '--allow tcp:80', '--source-ranges 0.0.0.0/0', and '--target-tags web-server'. Priority can be default (1000).

2
Multi-Selectmedium

An engineer wants to create a VPC with a custom subnet mode and then create a subnet with Private Google Access enabled. Which two commands should they use? (Choose TWO.)

Select 2 answers
A.gcloud compute networks subnets create my-subnet --network my-vpc --region us-central1 --range 10.0.0.0/24 --enable-private-ip-google-access
B.gcloud compute networks create my-vpc --subnet-mode custom
C.gcloud compute networks subnets create my-subnet --network my-vpc --region us-central1 --range 10.0.0.0/24
D.gcloud compute firewall-rules create allow-http --allow tcp:80
E.gcloud compute networks create my-vpc --subnet-mode auto
AnswersA, B

This command explicitly creates a subnet in a custom mode VPC (assuming the VPC already exists) and enables Private Google Access, allowing instances in that subnet to reach Google APIs and services through their internal IP addresses without needing a NAT or external IP. In a custom mode VPC, you must create each subnet manually, and this command defines the region and IP range, making it a required step after the VPC is created. Without this flag, the subnet would lack the Private Google Access capability, which is often a prerequisite for workloads that should reach Google services without public IPs.

Why this answer

Option B is correct because creating a VPC in custom subnet mode requires the command `gcloud compute networks create my-vpc --subnet-mode custom`, which prevents Google Cloud from automatically creating subnets in each region and is the necessary first step for the scenario. Option A is correct because `gcloud compute networks subnets create my-subnet --network my-vpc --region us-central1 --range 10.0.0.0/24 --enable-private-ip-google-access` creates the subnet with the `--enable-private-ip-google-access` flag, which turns on Private Google Access so instances without external IPs can reach Google APIs and services. Option C is incorrect because it creates the subnet without the `--enable-private-ip-google-access` flag, so Private Google Access would remain disabled.

Option D is incorrect because it creates a firewall rule for HTTP traffic, which is unrelated to subnet mode or Private Google Access. Option E is incorrect because `--subnet-mode auto` creates an auto mode VPC, which contradicts the requirement for a custom subnet mode VPC.

Exam trap

ACE often tests the distinction between VPC-level and subnet-level settings — candidates pick the subnet create command without the Private Google Access flag, forgetting that the flag is what actually enables the feature.

3
MCQmedium

To meet compliance requirements, a company must encrypt all data at rest in Cloud SQL using customer-managed encryption keys (CMEK). What is required to enable CMEK on a Cloud SQL instance?

A.Specify the key during instance creation using --disk-encryption-key, and ensure the Cloud SQL service account has encryption/decryption permissions on the key
B.Create the instance without encryption, then use gcloud sql instances patch to add CMEK later
C.Enable CMEK by setting an organization policy that requires CMEK for all Cloud SQL instances
D.Use the default encryption; CMEK is not supported for Cloud SQL
AnswerA

For Cloud SQL, customer-managed encryption keys (CMEK) must be supplied at the moment you create the instance. You specify the key with the --disk-encryption-key flag in the gcloud sql instances create command, and the Cloud SQL service account must be granted Cloud KMS CryptoKey Encrypter/Decrypter permissions so it can use the key to encrypt data at rest. If these permissions are missing, instance creation fails; the key cannot be retroactively attached to an existing instance because the encryption setting is immutable.

Why this answer

CMEK on Cloud SQL requires the key to be specified at instance creation time via the --disk-encryption-key flag (or the equivalent API/console field), and the Cloud SQL service account for the project must be granted roles/cloudkms.cryptoKeyEncrypterDecrypter on the key. Without both, the instance creation fails or falls back to Google-managed encryption.

Exam trap

ACE often tests the misconception that CMEK can be added to an existing Cloud SQL instance via patch — in reality, CMEK is a creation-time decision, and the service account IAM binding is the step candidates most often forget.

How to eliminate wrong answers

Option B is wrong because Cloud SQL does not support converting an existing instance from Google-managed to CMEK via patch — CMEK must be set at creation, and changing keys later requires exporting/importing data or recreating the instance. Option C is wrong because organization policies (e.g., constraints/gcp.restrictNonCmekServices) can block non-CMEK resources but cannot themselves enable CMEK on an instance. Option D is wrong because Cloud SQL fully supports CMEK for both MySQL, PostgreSQL, and SQL Server editions.

4
MCQmedium

You need to allow a Compute Engine instance to securely access a Cloud Storage bucket without managing service account keys. The instance already has a service account attached. What is the best practice to grant access?

A.Download a service account key file and store it on the instance.
B.Grant the necessary IAM roles to the service account attached to the instance.
C.Create a new service account and use its key on the instance.
D.Use the default compute engine service account and grant it Storage Admin.
AnswerB

Attached service accounts supply credentials automatically through the metadata server, so granting the required IAM roles directly to that service account lets the instance access the bucket without any exported key files. This satisfies the no-key-management constraint.

Why this answer

Granting the necessary IAM roles to the service account attached to the instance is the best practice because it allows the instance to authenticate to Cloud Storage using the service account's credentials automatically, without managing keys. This leverages the instance's metadata server to obtain access tokens, ensuring secure and seamless access.

Exam trap

The trap is thinking that you need to download a key file to authenticate, but the best practice is to use the attached service account. Candidates might also think that using the default service account is fine, but it's better to use a dedicated one with least privilege.

How to eliminate wrong answers

Option A is wrong because downloading a service account key file and storing it on the instance is insecure and against best practices; keys can be leaked or stolen. Option C is wrong because creating a new service account and using its key still involves key management, which is unnecessary and less secure. Option D is wrong because using the default compute engine service account and granting it Storage Admin is overly permissive and violates least privilege; it's better to use a dedicated service account with specific roles.

5
Multi-Selectmedium

An organization wants to enforce that all Compute Engine instances in a project use customer-managed encryption keys (CMEK) for their boot disks. Which TWO steps should the security team take?

Select 2 answers
A.Set an organization policy constraint that requires CMEK for Compute Engine disks
B.Specify the CMEK key in each instance template used for managed instance groups
C.Grant the Cloud KMS Admin role to the project's compute service account
D.Create a Cloud Audit Logs sink to monitor instances without CMEK
E.Grant the Cloud KMS CryptoKey Encrypter/Decrypter role to the Compute Engine service account
AnswersA, E

Setting an organization policy constraint (iam.disableServiceAccountKeyCreation is not relevant; here it's a custom constraint or the predefined compute.disableNestedVirtualization? Actually for CMEK, the relevant org policy is a custom constraint or the new `constraints/compute.requireCmek` that enforces CMEK on new Compute Engine disks at creation time. This is the only preventive control among the options because it blocks the disk-creation API call unless a valid CMEK key is supplied, making noncompliant instances impossible to create. It operates at the organization or folder level and is enforced by the resource manager before the Compute Engine API accepts the request.

Why this answer

To enforce CMEK, you can set an organization policy constraint (e.g., constraints/compute.requireCmek) to prevent creation of instances without CMEK. Additionally, you must grant the compute engine service account permission to use the KMS key so it can encrypt disks. Simply specifying the key in the instance template does not enforce the policy, and the Cloud KMS Admin role is too broad.

6
MCQeasy

Which IAM role should be granted to a user to allow them to create and manage secrets in Secret Manager?

A.roles/secretmanager.admin
B.roles/secretmanager.secretAccessor
C.roles/editor
D.roles/secretmanager.viewer
AnswerA

roles/secretmanager.admin is the correct choice because it grants the full set of Secret Manager permissions needed to create, update, and delete secrets, versions, and their IAM policies. It includes actions such as secretmanager.secrets.create, secretmanager.secrets.update, secretmanager.secrets.delete, and secretmanager.versions.add, allowing complete lifecycle management without granting unrelated service permissions.

Why this answer

roles/secretmanager.admin provides full control over secrets, including creation, deletion, and granting access. roles/secretmanager.secretAccessor only allows reading secret payloads. roles/editor is too broad and not specific. roles/viewer is read-only.

7
MCQeasy

You need to allow inbound HTTP traffic to a set of Compute Engine instances that have the tag 'web-server'. All other inbound traffic should be denied. Which firewall rule configuration should you create?

A.Create an allow rule for tcp:80 with target tags 'web-server' and source range 0.0.0.0/0, and a deny rule for all other traffic.
B.Create an allow rule for tcp:80 with source range 0.0.0.0/0 and apply to all instances.
C.Create a deny rule for all ports except tcp:80 with target tags 'web-server'.
D.Create an allow rule for tcp:80 with source range 0.0.0.0/0 and target tags 'web-server'. No deny rule is needed.
AnswerD

This is correct because VPC networks include an implicit deny-all rule for inbound traffic, so the only rule needed is an explicit allow for HTTP traffic (TCP port 80) from all source IP addresses (0.0.0.0/0) to instances tagged with 'web-server'. Target tags let you apply the rule selectively, ensuring only web server VMs accept inbound HTTP while all other instances remain blocked by the implicit deny. No additional deny rule is required or advisable.

Why this answer

In Google Cloud VPC firewall rules, you create an allow rule for tcp:80 with source range 0.0.0.0/0 and target tags 'web-server'. GCP firewall rules are stateful and use an implied deny-all ingress rule at the lowest priority (65535), so no explicit deny rule is needed — all traffic not matching an allow rule is automatically denied. This satisfies the requirement to allow HTTP to tagged instances while denying everything else.

Exam trap

ACE often tests whether candidates know GCP's implied deny-all ingress rule — the trap is adding an explicit deny rule (Option A) because candidates assume a deny rule is required, when GCP denies by default.

How to eliminate wrong answers

Option A is wrong because it adds an unnecessary explicit deny rule — GCP already has an implied deny-all ingress rule, so the deny rule is redundant and could cause confusion or priority conflicts. Option B is wrong because applying the rule to all instances (no target tags) allows HTTP to every VM in the network, not just the 'web-server' tagged instances, violating the scoping requirement. Option C is wrong because GCP firewall rules do not support 'deny all except' syntax in a single rule — you would need an allow rule for tcp:80 plus rely on the implied deny, and deny rules in GCP are separate and lower priority than allow rules by default.

8
MCQmedium

A developer wants to allow a Compute Engine instance to access Cloud Storage without using a service account key file. What is the recommended approach?

A.Use Application Default Credentials with a user account.
B.Download a service account key and store it on the instance.
C.Create a service account, grant it the required roles, and attach it to the instance using the --service-account flag.
D.Set up a VPN connection to Cloud Storage.
AnswerC

Create a service account, grant it the required IAM roles (for example, roles/storage.objectViewer for Cloud Storage read access), and attach it to the instance using the --service-account flag at instance creation time. The instance then automatically authenticates to Google Cloud APIs through the instance's metadata server, which provides OAuth 2.0 access tokens on behalf of the service account without storing any secret material on the disk. This is the standard, secure pattern for granting a Compute Engine instance access to other GCP resources, as it leverages the cloud-native identity and avoids managing static credentials.

Why this answer

The recommended approach is to create a service account, grant it the required roles, and attach it to the instance using the --service-account flag. This allows the instance to use the service account's credentials via the metadata server, eliminating the need for key files and providing secure, short-lived credentials.

Exam trap

ACE often tests the misconception that service account keys are required for GCE to access GCP services, when attaching a service account is the secure, recommended method.

How to eliminate wrong answers

Option A is wrong because Application Default Credentials with a user account would require user credentials, which are not suitable for production instances and still may involve key files. Option B is wrong because downloading a service account key and storing it on the instance is insecure and not recommended; keys can be leaked and must be managed. Option D is wrong because a VPN connection to Cloud Storage is not a valid method for authentication; Cloud Storage is accessed via APIs over the internet or private Google access, not via VPN for auth.

9
MCQhard

An organization has a hierarchy: Organization -> Folder A -> Project 1. An IAM policy at the organization level grants roles/editor to user@example.com. A policy at Folder A denies roles/editor to the same user. What is the effective role for the user in Project 1?

A.The user has the editor role only in resources directly under the organization, not under Folder A.
B.The user does not have the editor role in Project 1 because the deny policy at the folder level blocks it.
C.The user has the editor role because organization-level grants override folder-level denials.
D.The user has the editor role in Project 1 unless there is a specific project-level deny.
AnswerB

IAM deny policies are evaluated with higher precedence than allow policies, so a deny rule on Folder A explicitly blocks any inherited editor grant from reaching resources below that folder. Project 1, being a child of Folder A, inherits both the organization-level editor role and the folder-level deny, but deny rules win. As a result, even though the user was granted editor at the organization, the user's effective permissions in Project 1 do not include editor; the deny policy specifically prevents that role from being granted.

Why this answer

In Google Cloud IAM, deny policies take precedence over allow policies in the resource hierarchy. A deny policy at Folder A blocks the roles/editor grant even though the organization-level allow policy grants it, because the deny is evaluated first and overrides any inherited allow for that principal and permission. Therefore the user has no editor role in Project 1.

Exam trap

The trap is assuming that a higher-level allow (organization) always wins over a lower-level deny (folder) — in GCP, deny policies are evaluated first and override inherited allows.

How to eliminate wrong answers

Option A is wrong because the deny at Folder A applies to all resources beneath it, including resources directly under the organization that fall within Folder A's subtree — and the question asks about Project 1, which is under Folder A. Option C is wrong because organization-level allows do NOT override folder-level denies; deny policies always take precedence in GCP IAM evaluation. Option D is wrong because the deny at Folder A already blocks the role for Project 1; a project-level deny is not required for the deny to take effect.

10
MCQmedium

A company has a Cloud SQL instance with CMEK enabled. The Cloud KMS key used for encryption is accidentally disabled. What is the impact on the Cloud SQL instance?

A.The instance will be automatically deleted after 30 days.
B.The instance becomes unavailable and cannot be started until the key is re-enabled.
C.A read replica can be promoted to replace the primary.
D.The instance continues to operate normally, but new data cannot be encrypted.
AnswerB

Cloud SQL with CMEK uses the customer-managed key for every data-plane operation, including reads and writes to the database, logs, and system tables. When the key is disabled, the instance loses access to the key material, causing the database engine to fail all I/O requests immediately. Consequently, the instance becomes unavailable and cannot be started or used until the key is re-enabled in Cloud KMS; re-enabling the key automatically restores normal operation without manual intervention.

Why this answer

When a Cloud KMS key used for CMEK is disabled, the Cloud SQL instance cannot access the key to decrypt its data. As a result, the instance becomes unavailable and cannot be started until the key is re-enabled. This is because the instance requires the key for both read and write operations.

Exam trap

ACE often tests the misconception that a disabled CMEK key only affects new data encryption, when in fact it renders the entire instance unavailable because existing data cannot be decrypted.

How to eliminate wrong answers

Option A is wrong because the instance is not automatically deleted; it remains in an unavailable state until the key is restored. Option C is wrong because a read replica also depends on the same CMEK key for encryption, so it cannot be promoted to replace the primary if the key is disabled. Option D is wrong because the instance does not continue to operate normally; it becomes unavailable because it cannot decrypt data without the key.

11
MCQeasy

You need to view the current IAM policy for a project named 'my-project' in JSON format. Which command should you use?

A.gcloud projects add-iam-policy-binding my-project --format json
B.gcloud projects get-iam-policy my-project --format json
C.gcloud iam service-accounts list --project my-project
D.gcloud projects set-iam-policy my-project policy.json
AnswerB

`gcloud projects get-iam-policy my-project --format json` is the correct command for viewing the current IAM policy of a project. It retrieves the full policy, including all role bindings, conditions, and the etag, and returns it in a structured JSON format. The `--format json` flag ensures the output is machine-readable, which is useful for auditing, scripting, or feeding into other tools like `jq`. This command performs no mutation and is the standard way to inspect IAM policy state.

Why this answer

The `gcloud projects get-iam-policy` command retrieves the existing IAM policy bindings for a project and returns them in the requested format. Adding `--format json` outputs the policy as a JSON document, which is exactly what is needed to view the current policy. This is a read-only operation that does not modify any bindings.

Exam trap

The trap here is confusing read verbs (`get-iam-policy`) with write verbs (`add-iam-policy-binding`, `set-iam-policy`) — candidates often pick the command they've used most recently for granting access rather than the one that retrieves the policy.

How to eliminate wrong answers

Option A is wrong because `add-iam-policy-binding` is used to grant a new role to a member, not to view the existing policy. Option C is wrong because `gcloud iam service-accounts list` lists service accounts, not the project's IAM policy. Option D is wrong because `set-iam-policy` replaces the entire policy with the contents of a file, which is a write operation, not a view.

12
MCQhard

An engineer is configuring a Cloud NAT to allow private Compute Engine instances to access the internet. After creating the Cloud Router and NAT gateway, the instances still cannot connect to the internet. What is the most likely missing configuration?

A.The VPC does not have a default route (0.0.0.0/0) to the default internet gateway.
B.The firewall rules do not allow egress traffic.
C.The Cloud Router is in a different region.
D.The instances are not assigned a network tag used by the NAT.
AnswerA

For Cloud NAT to work, the VPC network must contain a default route (0.0.0.0/0) whose next hop is the default internet gateway. This route is what causes outbound packets from instances to be sent to the gateway, where Cloud NAT performs the source IP translation. Without this route, packets destined for the internet have no valid next hop and are dropped, so the instances cannot reach the internet at all—Cloud NAT alone does not create routing logic.

Why this answer

Cloud NAT requires that the subnet has Private Google Access enabled for certain Google APIs, but for general internet access, the instances must have a default route to the internet gateway (0.0.0.0/0 next hop to default internet gateway). If this route is missing, traffic won't be sent to NAT. The other options are possible but less common.

13
MCQmedium

A DevOps engineer needs to grant a service account the ability to pull images from a specific Container Registry repository in project 'my-project'. The service account is in project 'other-project'. Which command should the engineer use?

A.gcloud projects add-iam-policy-binding my-project --member user:admin@other-project.com --role roles/storage.objectViewer
B.gcloud iam service-accounts add-iam-policy-binding sa@other-project.iam.gserviceaccount.com --member serviceAccount:sa@other-project.iam.gserviceaccount.com --role roles/storage.objectViewer
C.gcloud projects add-iam-policy-binding other-project --member serviceAccount:sa@other-project.iam.gserviceaccount.com --role roles/storage.objectViewer
D.gcloud projects add-iam-policy-binding my-project --member serviceAccount:sa@other-project.iam.gserviceaccount.com --role roles/storage.objectViewer
AnswerD

This correctly adds an IAM policy binding on my-project, which owns the Container Registry artifacts, and defines the member as the service account from other-project using the `serviceAccount:` prefix. Since `roles/storage.objectViewer` grants read access to Cloud Storage objects that back GCR, this allows sa@other-project.iam.gserviceaccount.com to pull images and list repositories in my-project without needing a key or user account. The binding is cross-project: the member belongs to other-project, but the resource is in my-project, which is exactly the required configuration.

Why this answer

To grant a service account from 'other-project' permission to pull images from a repository in 'my-project', the IAM policy binding must be applied to the resource-owning project ('my-project') with the service account as the member. Option D does exactly this: it binds roles/storage.objectViewer on my-project to the service account from other-project.

Exam trap

The trap is confusing the resource the policy is bound to (must be the project owning the registry) with the member's home project, and confusing service-account-level IAM bindings (who can use the SA) with project-level bindings (what the SA can do).

How to eliminate wrong answers

Option A is wrong because it binds the role to a user (admin@other-project.com) rather than the service account, and uses a user: prefix instead of serviceAccount:. Option B is wrong because it applies the binding to the service account resource itself (gcloud iam service-accounts add-iam-policy-binding), which controls who can impersonate or manage the SA — not what the SA can access. Option C is wrong because it binds the role on 'other-project' (the SA's home project) instead of 'my-project' (where the Container Registry repository lives), so the SA would not gain access to the target repository.

14
Multi-Selectmedium

A security engineer wants to audit all attempts to access a specific Cloud Storage bucket, including successful and failed read requests. Which THREE steps should they take? (Choose THREE)

Select 3 answers
A.Create a log sink to BigQuery for the bucket's admin activity logs.
B.Enable Data Access audit logs for the Cloud Storage service.
C.Use Log Explorer to filter for the bucket's data access logs.
D.Grant the auditor the roles/logging.viewer role on the project.
E.Enable Admin Activity audit logs for the bucket.
AnswersB, C, D

Enabling Data Access audit logs for the Cloud Storage service is correct because these logs specifically record every successful and failed read, write, and metadata operation on objects and buckets. By default, Data Access audit logs are disabled, so they must be explicitly turned on for Cloud Storage for the auditor to capture access attempts. Once enabled, each entry includes the principal, source IP, operation (e.g. storage.objects.get), and timestamp—providing the detailed evidence needed for an audit trail.

Why this answer

Option B is correct because Cloud Storage read requests (both successful and failed) are recorded only in Data Access audit logs, which are disabled by default and must be explicitly enabled for the Cloud Storage service. Option C is correct because once Data Access logs are enabled, they can be queried in Log Explorer using filters such as resource.type="gcs_bucket" and the bucket name to isolate the relevant read attempts. Option D is correct because the auditor needs the roles/logging.viewer role (or equivalent) on the project to view and filter those audit logs in Log Explorer.

Option A is not needed because BigQuery sinks are for exporting/analyzing logs, not for auditing access attempts directly, and Admin Activity logs do not capture data reads. Option E is incorrect because Admin Activity audit logs are always enabled and record administrative/config changes, not successful or failed object read requests.

Exam trap

ACE often tests the distinction between Admin Activity logs (always on, control-plane) and Data Access logs (opt-in, data-plane) — candidates who pick 'enable Admin Activity logs' miss that reads are data-plane events.

15
MCQmedium

A developer wants to create a service account for an application running on Compute Engine. The application needs to access Cloud Storage. What is the best practice for granting this access?

A.Use Workload Identity Federation to grant access.
B.Create a service account, grant it the Cloud Storage roles, and attach it to the instance using the --service-account flag.
C.Use the default Compute Engine service account and grant it Cloud Storage roles.
D.Create a service account, download its key, and store it on the instance.
AnswerB

Creating a dedicated service account, granting it only the required Cloud Storage IAM roles such as roles/storage.objectViewer, and attaching it to the instance with the --service-account flag at creation time follows the principle of least privilege. The VM's metadata server then provides short-lived access tokens to the application, avoiding the need to manage or download any service account keys. This is the recommended, secure pattern for a GCE workload to access Cloud Storage with minimal permissions.

Why this answer

The best practice is to create a dedicated user-managed service account, grant it only the required Cloud Storage IAM roles (e.g., roles/storage.objectViewer), and attach it directly to the Compute Engine instance via the --service-account flag. This follows the principle of least privilege and avoids long-lived credentials. Attaching the service account to the instance lets the application obtain short-lived access tokens automatically from the metadata server.

Exam trap

The trap here is that candidates confuse Workload Identity Federation (for external identities) with attaching a service account to a GCE instance, or they default to the built-in Compute Engine service account thinking it is 'the' service account for instances.

How to eliminate wrong answers

Option A is wrong because Workload Identity Federation is designed for external identities (AWS, Azure AD, OIDC) to impersonate GCP service accounts, not for native GCE workloads. Option C is wrong because the default Compute Engine service account is broadly scoped and shared across all instances, violating least privilege. Option D is wrong because downloading and storing service account keys creates long-lived credentials that can be leaked, which Google explicitly discourages.

16
MCQeasy

An engineer needs to view the current IAM policy for a project in JSON format. Which gcloud command should they use?

A.gcloud iam projects describe-iam-policy PROJECT_ID --format json
B.gcloud projects add-iam-policy-binding PROJECT_ID --format json
C.gcloud projects set-iam-policy PROJECT_ID --format json
D.gcloud projects get-iam-policy PROJECT_ID --format json
AnswerD

This is the correct read-only command for retrieving a project's IAM policy. It outputs the complete policy document, including bindings, version, etag, and audit configs, and '--format json' formats that document as JSON for easy parsing. It is the standard tool for viewing current IAM state and is the basis for making offline changes with set-iam-policy.

Why this answer

The `gcloud projects get-iam-policy` command retrieves the IAM policy attached to a project and returns it in the requested format. Adding `--format json` outputs the policy as a JSON document, which is exactly what the engineer needs. This is the standard read-only command for inspecting project-level IAM bindings.

Exam trap

ACE often tests the distinction between read verbs (get/describe/list) and write verbs (add/set/remove) in gcloud commands — candidates who skim often pick `add-iam-policy-binding` because it sounds like it 'handles' the policy.

How to eliminate wrong answers

Option A is wrong because `gcloud iam projects describe-iam-policy` is not a valid gcloud command — `iam` is a command group for service accounts and roles, not project policy retrieval. Option B is wrong because `add-iam-policy-binding` is a write operation that adds a new binding to the policy; it does not display the existing policy. Option C is wrong because `set-iam-policy` replaces the entire IAM policy with a supplied file and is a destructive write operation, not a read.

17
MCQmedium

You are configuring a Cloud NAT to allow private Compute Engine instances to access the internet for updates. What other resource is required to set up Cloud NAT?

A.A Cloud VPN tunnel
B.An interconnect attachment
C.A Cloud Router
D.A VPC peering connection
AnswerC

A Cloud Router is the correct component because Cloud NAT requires a Cloud Router in the same region and VPC network to function. The Cloud Router holds the NAT gateway's configuration, manages the NAT IP addresses, and dynamically exchanges routes with the VPC network. Without a Cloud Router, Cloud NAT cannot be created or operate, making it the essential resource for allowing private Compute Engine instances to access the internet or other destinations while remaining private.

Why this answer

Cloud NAT requires a Cloud Router to provide the control plane for NAT translation. The Cloud Router is used to program the NAT gateway with translation rules and to manage the IP addresses used for NAT. Without a Cloud Router, you cannot configure Cloud NAT.

Exam trap

ACE often tests the dependency between Cloud NAT and Cloud Router; candidates may think a VPN or peering is needed, but the correct answer is always Cloud Router.

How to eliminate wrong answers

Option A is wrong because a Cloud VPN tunnel is for secure connectivity between on-premises and GCP, not for NAT. Option B is wrong because an interconnect attachment is for dedicated private connectivity, not NAT. Option D is wrong because VPC peering connects two VPC networks, but does not provide NAT functionality.

18
Multi-Selectmedium

A security team wants to restrict access to a Cloud Storage bucket so that only objects encrypted with a specific CMEK key can be uploaded. Which three actions are needed? (Choose 3)

Select 3 answers
A.Grant authorized users the roles/cloudkms.cryptoKeyEncrypterDecrypter role.
B.Grant all users the roles/cloudkms.cryptoKeyEncrypterDecrypter role.
C.Create a bucket IAM policy that denies storage.objects.create without the encryption header matching the CMEK key.
D.Enable Uniform Bucket-Level Access.
E.Create a Cloud KMS key and set it as the default key on the bucket using --kms-key.
AnswersA, C, E

Granting authorized users the roles/cloudkms.cryptoKeyEncrypterDecrypter role on the Cloud KMS key is correct because this IAM role grants permission to call the Cloud KMS Encrypt and Decrypt operations, which are required for objects to be uploaded with and read from a CMEK-encrypted bucket. Even if a user has bucket-level permissions, they cannot create or read objects encrypted with that key unless they have this role on the key itself. This ensures only the intended authorized principals can use the customer-managed key for cryptographic operations.

Why this answer

Setting the CMEK key on the bucket, creating a bucket-level policy denying uploads without the key, and granting the encrypt/decrypt role to users are required.

19
MCQeasy

Which Google Cloud service provides a managed, scalable, and secure way to store API keys, passwords, and certificates?

A.Cloud Key Management Service (Cloud KMS)
B.Cloud IAM
C.Secret Manager
D.Cloud Storage
AnswerC

Secret Manager is the dedicated Google Cloud service for storing, managing, and accessing secrets such as API keys, passwords, and certificates. It provides built-in secret versioning with immutable payloads, IAM-based access control at the secret-version level, automatic replication for high availability, and full audit logging via Cloud Audit Logs. This makes it the managed and scalable solution that directly matches the requirement.

Why this answer

Secret Manager is a fully managed Google Cloud service designed specifically for storing, managing, and accessing sensitive data such as API keys, passwords, and certificates. It provides versioning, fine-grained IAM access control, automatic replication, and audit logging, making it the ideal choice for secret storage. Unlike Cloud KMS, which manages encryption keys, Secret Manager stores the secrets themselves.

Cloud IAM handles identity and access management, not secret storage, and Cloud Storage is a general object store not optimized for secrets.

Exam trap

The trap here is confusing Cloud KMS with Secret Manager: candidates often think KMS stores secrets because it deals with keys, but KMS only manages encryption keys, not the secrets themselves.

How to eliminate wrong answers

Option A is wrong because Cloud KMS is used to create and manage cryptographic keys for encryption/decryption, not to store arbitrary secrets like API keys or passwords. Option B is wrong because Cloud IAM is an identity and access management service that controls permissions, not a secret storage system. Option D is wrong because Cloud Storage is a scalable object storage service for files and data, but it lacks built-in secret management features like versioning, rotation, and fine-grained access control specifically for secrets.

20
MCQmedium

A security team wants to ensure that all Compute Engine instances in a project automatically use a custom service account with minimal permissions. What must the engineer do when creating new instances?

A.Create a custom role and assign it to the instance's service account through the instance metadata.
B.Use gcloud compute instances create with the --service-account flag pointing to the custom service account.
C.Set the project-wide default service account to the custom service account in the project settings.
D.Create a startup script that configures the instance to use the custom service account after boot.
AnswerB

When creating an instance, you must specify the service account with `gcloud compute instances create --service-account <SA_EMAIL>`, which attaches that identity to the instance for its entire lifetime. Once attached, the instance metadata server returns OAuth credentials for that service account, so all API calls from the instance are made as that identity. This is the correct way to ensure the instance uses a custom, least-privileged service account, provided the account has been granted the necessary IAM roles.

Why this answer

The --service-account flag on gcloud compute instances create explicitly attaches the specified custom service account to the new instance at creation time, ensuring the VM uses minimal-permission credentials instead of the default Compute Engine service account. This is the correct declarative way to enforce per-instance identity in GCP.

Exam trap

ACE often tests the misconception that service accounts can be assigned post-boot or via metadata — candidates pick the startup-script option, not realizing identity is immutable at runtime.

How to eliminate wrong answers

Option A is wrong because service accounts are attached via the instance's service account configuration, not through instance metadata — metadata is for keys like startup-script and ssh-keys. Option C is wrong because GCP does not provide a project-wide 'default service account' setting that can be swapped to a custom account; the default Compute Engine service account is fixed per project. Option D is wrong because a service account cannot be changed on a running instance via a startup script — the service account is bound at instance creation and requires stopping the instance to modify.

21
MCQmedium

A developer needs to store a database password in Secret Manager and then allow a Compute Engine instance to access it. The instance uses the default compute engine service account. Which role should be granted to the service account?

A.roles/cloudsql.client
B.roles/secretmanager.admin
C.roles/viewer
D.roles/secretmanager.secretAccessor
AnswerD

roles/secretmanager.secretAccessor is the correct predefined role for accessing a secret payload because it includes the secretmanager.versions.access permission, which is the exact IAM permission required to retrieve the stored database password. This role is narrowly scoped; it grants no management capabilities like secret creation, deletion, or IAM policy changes. For a developer whose sole need is to fetch the secret value at runtime, this role provides the minimum access needed while supporting least privilege best practices.

Why this answer

To access the secret version's payload, the service account needs the 'secretmanager.secretAccessor' role on the secret (or project). That role allows accessing secret versions. roles/secretmanager.admin is too broad. roles/cloudsql.client is for Cloud SQL, not Secret Manager. roles/viewer does not allow access to secret payloads.

22
MCQeasy

An engineer wants to allow HTTP traffic from the internet to a set of Compute Engine instances that have the network tag 'web-server'. Which firewall rule should they create?

A.gcloud compute firewall-rules create allow-http --allow tcp:80 --source-tags web-server
B.gcloud compute firewall-rules create allow-http --allow tcp:80 --source-tags web-server --target-ranges 0.0.0.0/0
C.gcloud compute firewall-rules create allow-http --direction egress --allow tcp:80 --destination-ranges 0.0.0.0/0 --target-tags web-server
D.gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges 0.0.0.0/0 --target-tags web-server
AnswerD

The rule satisfies both constraints: `--source-ranges 0.0.0.0/0` permits internet traffic, and `--target-tags web-server` scopes enforcement to instances carrying that network tag. Google Cloud VPC firewall rules apply to tagged instances, so only the designated Compute Engine instances receive the inbound TCP port 80 allowance.

Why this answer

To allow HTTP traffic from the internet to instances with the network tag 'web-server', the firewall rule must specify --allow tcp:80, --source-ranges 0.0.0.0/0 (to allow all internet IPs), and --target-tags web-server (to apply to instances with that tag). This correctly defines an ingress rule allowing TCP port 80 from any source to the tagged instances.

Exam trap

ACE often tests the difference between --source-tags and --source-ranges, and candidates may confuse ingress with egress rules or use the wrong flag for the direction.

How to eliminate wrong answers

Option A is wrong because --source-tags web-server would only allow traffic from instances with the 'web-server' tag, not from the internet. Option B is wrong because --source-tags and --target-ranges are not valid together in this context; --target-ranges is used for egress rules, and the combination is incorrect. Option C is wrong because --direction egress creates an egress rule, not ingress, and --destination-ranges is for egress.

Option D is correct.

23
MCQmedium

A company wants to use Customer-Managed Encryption Keys (CMEK) for a Cloud SQL instance. What must be done first?

A.Create a bucket and upload a key file.
B.Create a Cloud KMS key ring and key, and grant the Cloud SQL service account the cloudkms.cryptoKeyEncrypterDecrypter role.
C.Enable Cloud KMS API and use default encryption.
D.Set the --disk-encryption-key flag to an existing key in Cloud KMS.
AnswerB

This is the correct prerequisite for enabling CMEK on a Cloud SQL instance. You must create a key ring and a crypto key in Cloud KMS, then grant the Cloud SQL service account (e.g., service-<project>@gcp-sa-cloudsql.iam.gserviceaccount.com) the cloudkms.cryptoKeyEncrypterDecrypter role. That IAM binding lets Cloud SQL call Cloud KMS to encrypt and decrypt the data encryption keys used to protect the instance.

Why this answer

To use Customer-Managed Encryption Keys (CMEK) with Cloud SQL, you must first create a Cloud KMS key ring and key, then grant the Cloud SQL service account the cloudkms.cryptoKeyEncrypterDecrypter role. This allows Cloud SQL to use the key to encrypt the instance's data at rest. The service account must have permission to use the key for encryption and decryption operations.

Exam trap

ACE often tests the misconception that enabling the Cloud KMS API or using a key file is sufficient for CMEK, but the critical step is granting the Cloud SQL service account the correct IAM role on the KMS key.

How to eliminate wrong answers

Option A is wrong because CMEK for Cloud SQL uses Cloud KMS keys, not key files stored in a bucket; uploading a key file is not part of the CMEK setup. Option C is wrong because enabling the Cloud KMS API alone does not configure CMEK; default encryption uses Google-managed keys, not customer-managed keys. Option D is wrong because the --disk-encryption-key flag is used for Compute Engine persistent disks, not for Cloud SQL instances; Cloud SQL CMEK is configured via the Cloud SQL instance settings, not a flag.

24
MCQmedium

A company has a VPC with a subnet that has Private Google Access enabled. They want their Compute Engine instances to access Google APIs and services through internal IP addresses. Which additional configuration is required?

A.No additional configuration is required.
B.Configure Cloud NAT to enable access to Google APIs.
C.Set up Cloud VPN tunnels to Google APIs.
D.Create a VPC peering connection with the Google APIs VPC.
AnswerA

Private Google Access is a subnet-level setting that already routes traffic from VM instances with only internal IP addresses to Google APIs and services over Google's internal network. When this is enabled on the subnet, DNS resolution for googleapis.com automatically maps to Google's internal IP ranges, so the existing VPC routing handles API calls without any extra networking components. Therefore, no additional configuration is required.

Why this answer

Private Google Access allows Compute Engine instances with only internal IP addresses to reach Google APIs and services (such as Cloud Storage, BigQuery, and Pub/Sub) using internal IP addresses, without requiring an external IP or Cloud NAT. Once the subnet-level setting is enabled, no additional routing, NAT, or peering configuration is needed because Google APIs are reachable via the default route to the private Google access VIP (199.36.153.8/30 or the restricted.googleapis.com VIPs).

Exam trap

The trap here is confusing Private Google Access (internal access to Google APIs) with Cloud NAT (outbound internet access) — candidates often assume NAT is required for any outbound traffic, but Google APIs are a special case handled by PGA.

How to eliminate wrong answers

Option B is wrong because Cloud NAT is used to give instances without external IPs outbound internet access, not access to Google APIs — Private Google Access already handles Google API traffic internally. Option C is wrong because Cloud VPN tunnels are for connecting on-premises networks or other clouds to a VPC, not for reaching Google APIs from within GCP. Option D is wrong because VPC peering with a 'Google APIs VPC' is not a real configuration — Google APIs are reached through the default internet gateway route with Private Google Access, not through a peered VPC.

25
Multi-Selecthard

An engineer needs to audit all Data Access logs for a project to detect unauthorized access to sensitive data. The engineer must ensure that logs are retained for 5 years and are immutable. Which THREE steps should the engineer take?

Select 3 answers
A.Configure the Cloud Storage bucket with a retention policy and enable object versioning
B.Enable Data Access audit logs for the relevant services in the project's IAM audit config
C.Use the default Logging retention of 30 days
D.Set up a Cloud Monitoring alert for any Data Access log entries
E.Create a log sink to export logs to a Cloud Storage bucket
AnswersA, B, E

The retention policy on the Cloud Storage bucket prevents objects from being deleted or overwritten for a specified duration, and object versioning preserves every version of each object, so even if an object is deleted or replaced, an immutable prior version remains. This is critical for compliance because audit logs must be tamper-proof and available for a multi-year period. However, this step alone does not capture logs; it secures the destination bucket where the log sink delivers exported log entries.

Why this answer

To achieve this, the engineer must: 1. Enable Data Access audit logs for the required services (e.g., Cloud Storage, BigQuery) in the project's IAM audit config. 2. Create a log sink that exports the logs to a Cloud Storage bucket (which provides cost-effective long-term retention). 3.

Configure the bucket with retention policy and object versioning to make logs immutable and protect against deletion. Using Logging's default retention is only 30 days, not 5 years. Cloud Monitoring does not store logs.

BigQuery is not ideal for immutable storage.

26
MCQeasy

You want to view the current IAM policy for a project in JSON format using the gcloud command-line tool. Which command should you run?

A.gcloud projects get-iam-policy <project-id> --format json
B.gcloud iam service-accounts get-iam-policy <service-account> --format json
C.gcloud iam policies get <project-id> --format json
D.gcloud projects describe <project-id> --format json
AnswerA

This is the correct command. `gcloud projects get-iam-policy` invokes the Cloud Resource Manager `getIamPolicy` API for the specified project, and the `--format json` flag requests the output as a structured JSON object containing the policy's `etag`, `version`, and `bindings`. It is the standard way to view all project-level IAM bindings.

Why this answer

The command 'gcloud projects get-iam-policy <project-id> --format json' retrieves the IAM policy for a project in JSON format. This command directly fetches the policy bindings and audit configs for the specified project.

Exam trap

ACE often tests the confusion between commands for different resources (project vs. service account) and invalid command syntax like 'gcloud iam policies get'.

How to eliminate wrong answers

Option B is wrong because it retrieves the IAM policy for a service account, not a project. Option C is wrong because 'gcloud iam policies get' is not a valid command; IAM policies are managed via resource-specific commands like 'gcloud projects get-iam-policy'. Option D is wrong because 'gcloud projects describe' returns project metadata, not the IAM policy.

27
MCQmedium

An engineer needs to view the current IAM policy for a project in JSON format to analyze bindings. Which command should be used?

A.gcloud resource-manager folders get-iam-policy my-project --format json
B.gcloud projects get-iam-policy my-project --format yaml
C.gcloud projects get-iam-policy my-project --format json
D.gcloud iam policies get my-project --format json
AnswerC

This is the correct command. It uses the 'gcloud projects get-iam-policy' subcommand to retrieve the IAM policy for the specified project ID ('my-project') and sets the output format to JSON via '--format json'. The command returns the Policy object containing bindings, roles, members, etag, and version, all serialized in the requested JSON structure.

Why this answer

The command gcloud projects get-iam-policy PROJECT_ID --format json retrieves the IAM policy for the project in JSON format. Other commands either get policies for different resources or use a different format.

28
MCQmedium

An organization has multiple projects under a folder. They want to grant a network admin the ability to create firewall rules in all projects in the folder. Which IAM policy binding achieves this with least privilege?

A.Grant roles/owner at the folder level
B.Grant roles/compute.admin at the project level for each project
C.Grant roles/compute.networkAdmin at the folder level
D.Grant roles/compute.securityAdmin at the folder level
AnswerD

Granting roles/compute.securityAdmin at the folder level is the most precise solution because this role includes the compute.firewalls.create, compute.firewalls.update, and compute.firewalls.delete permissions needed to manage firewall rules, but does not include broader permissions to manage instances, networks, or IAM. IAM policies at the folder level are inherited by all projects and resources within that folder, so this single binding covers every descendant project, including newly created ones. This follows least privilege by granting exactly the permissions needed for firewall rule management and nothing extra.

Why this answer

Grant the roles/compute.securityAdmin role at the folder level. This allows managing firewall rules across all projects under that folder. Granting at project level would require adding the role to each project individually.

The compute.networkAdmin role does not include firewall rule management.

29
MCQeasy

You need to store a database password securely in Google Cloud. The password will be used by a Compute Engine instance. Which service should you use?

A.Secret Manager
B.Cloud Storage
C.Cloud KMS
D.Cloud Firestore
AnswerA

Secret Manager is the dedicated GCP service for securely storing secrets such as database passwords, API keys, and TLS certificates. It provides automatic encryption at rest and in transit, granular IAM-permission binding, versioning, and audit logging, enabling applications to retrieve secrets on demand via API without embedding them in code. As a fully managed and centralized secret store, it is purpose-built to safeguard database credentials in compliance with security best practices.

Why this answer

Google Cloud Secret Manager is designed to store, manage, and access sensitive data like passwords, API keys, and certificates. It provides versioning, IAM-based access control, and audit logging, making it the correct choice for storing a database password used by a Compute Engine instance.

Exam trap

ACE often tests the difference between Secret Manager (for secrets) and Cloud KMS (for encryption keys), tricking candidates into choosing KMS when asked to store a password.

How to eliminate wrong answers

Option B is wrong because Cloud Storage is for object storage and lacks the specialized secret management features (encryption, rotation, access auditing) required for sensitive credentials. Option C is wrong because Cloud KMS manages encryption keys, not arbitrary secrets; it can encrypt secrets but doesn't provide a secret store with versioning and access control for the secret value itself. Option D is wrong because Cloud Firestore is a NoSQL document database, not a secret management service; storing passwords there would be insecure and lack dedicated secret handling.

30
MCQhard

A company has an organization with multiple folders and projects. They want to audit all IAM policy changes across the entire organization. Which approach meets the requirement with minimal effort?

A.View Admin Activity audit logs in Logs Explorer, which are enabled by default.
B.Use Organization Policy to deny IAM policy changes and monitor violations.
C.Enable Data Access audit logs for all services in the organization.
D.Enable audit logging on each project individually using gcloud logging sinks.
AnswerA

Admin Activity audit logs are enabled by default for every Google Cloud project and record all IAM policy changes, including modifications to roles, bindings, and service account keys. To see who changed permissions, you can go directly to the Logs Explorer and query protoPayload.methodName=SetIamPolicy without creating any sinks or enabling additional features. This is the only option that directly answers the question with zero configuration effort.

Why this answer

Admin Activity audit logs are enabled by default for all Google Cloud projects and organizations, and they automatically capture IAM policy changes (e.g., SetIamPolicy calls) at the organization, folder, and project levels. Because they are always on and aggregated at the organization level, you can view them in Logs Explorer without enabling anything or configuring per-project sinks. This meets the audit requirement with minimal effort.

Exam trap

ACE often tests the misconception that you must enable audit logs to see IAM changes, when in fact Admin Activity logs are on by default and already capture them; candidates may incorrectly choose Data Access logs or per-project sinks.

How to eliminate wrong answers

Option B is wrong because Organization Policy is a preventive control (e.g., constraints like constraints/iam.disableServiceAccountKeyCreation) that blocks or restricts actions; it does not provide an audit trail of IAM changes and would not help you audit them. Option C is wrong because Data Access audit logs record reads/writes of data (e.g., reading a Cloud Storage object) and are disabled by default; they are not needed to audit IAM policy changes, and enabling them for all services would generate massive volume and cost. Option D is wrong because Admin Activity logs are already enabled by default and aggregated at the organization level; creating per-project sinks is unnecessary and does not meet the 'minimal effort' requirement.

31
MCQeasy

A developer needs to allow a Compute Engine instance to access a Cloud Storage bucket without using a service account key file. The instance runs in a project that has the necessary APIs enabled. What should the developer do?

A.Use the instance's default Compute Engine service account and grant it the Editor role.
B.Create a service account key and store it on the instance's persistent disk.
C.Attach a service account to the instance and grant it the necessary IAM roles.
D.Enable Cloud Storage API access on the instance's network interface.
AnswerC

Attaching a service account to a Compute Engine instance automatically provides the instance with credentials via the metadata server. The application can use the default credentials to authenticate to Google Cloud APIs. By granting the service account appropriate IAM roles, such as Storage Object Viewer, the instance gains access without managing any key files.

Why this answer

Attaching a service account to the instance allows the instance to obtain short-lived credentials from the metadata server, eliminating the need for key files. Granting that service account the necessary IAM roles ensures it has the required permissions to access the Cloud Storage bucket. This is the recommended secure and manageable approach for Compute Engine workloads.

Exam trap

The trap here is assuming that network-level settings or default service accounts with broad roles are the right way to grant access, rather than using a dedicated service account with least privilege.

32
MCQmedium

An engineer wants to create a Google-managed SSL certificate for an HTTPS load balancer. Which command should they use?

A.gcloud compute ssl-policies create my-policy --profile MODERN
B.gcloud compute ssl-certificates create my-cert --domains example.com
C.gcloud compute ssl-certificates create my-cert --certificate cert.pem --private-key key.pem
D.gcloud compute target-https-proxies create my-proxy --ssl-certificates my-cert
AnswerB

This is the correct command because it explicitly instructs Compute Engine to provision a Google-managed certificate for the specified domains. The --domains flag triggers Google's automatic certificate management lifecycle: Google Cloud obtains the certificate and handles renewals approximately 30 days before expiration, though you must verify domain ownership first. After creation, the certificate resource still needs to be attached to a target HTTPS proxy and associated with a forwarding rule before it can serve traffic.

Why this answer

Google-managed SSL certificates are created with `gcloud compute ssl-certificates create` and only require the `--domains` flag; Google provisions and renews the certificate automatically. The absence of `--certificate` and `--private-key` is what distinguishes a Google-managed cert from a self-managed one. The resulting certificate resource can then be attached to a target HTTPS proxy.

Exam trap

ACE often tests the distinction between Google-managed and self-managed certificates, so candidates who see `--certificate` and `--private-key` flags assume they are required and pick the self-managed option.

How to eliminate wrong answers

Option A is wrong because `gcloud compute ssl-policies create` creates an SSL policy (a TLS version/cipher-suite profile such as MODERN), not a certificate. Option C is wrong because supplying `--certificate cert.pem --private-key key.pem` creates a self-managed certificate, not a Google-managed one. Option D is wrong because `gcloud compute target-https-proxies create` creates the HTTPS proxy that consumes a certificate; it does not create the certificate itself.

33
Multi-Selectmedium

An engineer needs to allow a set of Compute Engine instances (with tag 'web-server') to receive traffic on port 443 from the internet. The VPC has a default network with default firewall rules. Which TWO actions should the engineer take? (Choose TWO)

Select 2 answers
A.Create a firewall rule allowing ingress from 0.0.0.0/0 on port 443 with target tag 'https-server' and priority 1000.
B.Modify the default-allow-https rule to change the target tag to 'web-server'.
C.Delete the default-allow-https rule to avoid conflicts.
D.Create a firewall rule allowing ingress from 0.0.0.0/0 on port 443 with target tag 'web-server' and priority 1000.
E.Ensure that instances have the 'web-server' network tag applied.
AnswersD, E

Default network rules permit internal traffic and deny most external ingress, so an explicit ingress rule is required. Specifying 0.0.0.0/0 as source, port 443, target tag 'web-server' and priority 1000 permits internet HTTPS traffic to precisely those tagged instances, satisfying the stated requirement.

Why this answer

Option D is correct because a VPC firewall rule must explicitly match the instances it protects via a target tag, so creating an ingress rule from 0.0.0.0/0 on tcp:443 with target tag 'web-server' and a priority (1000) permits the desired HTTPS traffic to exactly those instances. Option E is correct because firewall target tags only apply to instances that actually carry the matching network tag, so the Compute Engine instances must have the 'web-server' tag applied for the rule to take effect. Option A is wrong because its target tag 'https-server' does not match the instances tagged 'web-server', so the rule would not apply to them.

Option B is wrong because the default network's default-allow-https rule targets 'https-server', and modifying it to 'web-server' would affect all instances with that tag rather than cleanly scoping the change, and it is not the required action here. Option C is wrong because deleting the default-allow-https rule is unnecessary and would remove existing HTTPS access for instances tagged 'https-server' without solving the tagging mismatch.

Exam trap

ACE often tests the need to both create a firewall rule with the correct target tag and ensure instances have that tag, so candidates may forget to apply the tag or choose the wrong tag.

34
MCQmedium

An engineer needs to create a firewall rule that allows incoming HTTPS traffic only from a specific IP range to instances tagged 'web-server'. Which command should they use?

A.gcloud compute firewall-rules create allow-https --allow tcp:443 --source-ranges 192.168.0.0/16 --target-tags web-server
B.gcloud compute firewall-rules create allow-https --allow tcp:443 --source-tags web-server
C.gcloud compute firewall-rules create allow-https --allow udp:443 --source-ranges 192.168.0.0/16 --target-tags web-server
D.gcloud compute firewall-rules create allow-https --allow tcp:443 --source-ranges 0.0.0.0/0 --target-tags web-server
AnswerA

This rule is correct because it explicitly restricts inbound HTTPS (TCP port 443) to source IPs within the RFC 1918 private range 192.168.0.0/16 and applies only to VM instances bearing the network tag 'web-server'. The combination of --source-ranges with a CIDR and --target-tags ensures the rule targets exactly the intended web servers and only allows traffic from the specified internal subnet, satisfying the requirement.

Why this answer

The correct command uses --allow tcp:443 to permit HTTPS, --source-ranges 192.168.0.0/16 to restrict the source IP range, and --target-tags web-server to apply the rule only to instances tagged 'web-server'. This matches all three requirements: protocol/port, source restriction, and target selection. The gcloud compute firewall-rules create syntax requires --allow with protocol:port and uses --target-tags (not --source-tags) to select destination instances.

Exam trap

ACE often tests the confusion between --source-tags (source instances) and --target-tags (destination instances), and between TCP and UDP for HTTPS, causing candidates to pick a rule that allows the wrong traffic.

How to eliminate wrong answers

Option B is wrong because --source-tags filters by the tags of the source instances, not the destination, and it omits the required --source-ranges for the specific IP range; it also does not target the web-server instances correctly. Option C is wrong because it specifies udp:443, but HTTPS uses TCP port 443 — UDP 443 is used by HTTP/3 (QUIC), not standard HTTPS, so this would not allow the intended traffic. Option D is wrong because --source-ranges 0.0.0.0/0 allows HTTPS from any source on the internet, violating the requirement to restrict to a specific IP range.

35
MCQeasy

An engineer wants to create a Google-managed SSL certificate for a domain and attach it to an HTTPS load balancer. Which gcloud command should they use to create the certificate?

A.gcloud compute target-https-proxies create --ssl-certificates
B.gcloud compute ssl-certificates create --domains example.com
C.gcloud compute ssl-policies create
D.gcloud compute ssl-certificates create --certificate example.crt --private-key example.key
AnswerB

The `gcloud compute ssl-certificates create` command with the `--domains` flag provisions a Google-managed SSL certificate, which satisfies the stem’s requirement for a Google-managed certificate rather than a self-managed one. This command triggers Google’s Certificate Authority to automatically handle domain validation and renewal for `example.com`, eliminating the need for manual certificate uploads. It directly attaches to the HTTPS load balancer’s target proxy, meeting the load-balancer constraint.

Why this answer

The gcloud command 'gcloud compute ssl-certificates create --domains example.com' creates a Google-managed SSL certificate, which is automatically provisioned and renewed by Google Cloud. The --domains flag specifies the domain names for which the certificate should be issued, and Google handles the certificate lifecycle without requiring the user to provide a private key or certificate file. This is the correct command for creating a Google-managed certificate to attach to an HTTPS load balancer.

Exam trap

ACE often tests the distinction between creating a certificate versus attaching it to a proxy, and between Google-managed versus self-managed certificates — candidates frequently select the command that uploads a certificate file when the question asks for a Google-managed certificate.

How to eliminate wrong answers

Option A is wrong because 'gcloud compute target-https-proxies create --ssl-certificates' creates or updates the HTTPS target proxy and attaches an existing certificate to it — it does not create the certificate itself. Option C is wrong because 'gcloud compute ssl-policies create' creates an SSL policy that defines TLS versions and cipher suites, not an SSL certificate. Option D is wrong because 'gcloud compute ssl-certificates create --certificate example.crt --private-key example.key' creates a self-managed SSL certificate by uploading a certificate and private key, which is the opposite of a Google-managed certificate.

36
MCQmedium

An engineer wants to view the current IAM policy for a project in JSON format. Which command should they use?

A.gcloud resource-manager folders get-iam-policy my-project --format json
B.gcloud projects describe my-project --format json
C.gcloud projects get-iam-policy my-project --format json
D.gcloud iam policies get my-project --format json
AnswerC

This is the exact, valid CLI command for retrieving a project's IAM policy. The subcommand get-iam-policy reads the IAM policy bound to the specified project resource, and --format json renders it as a JSON array of bindings, including roles, members, and conditions. It is the correct tool for this task.

Why this answer

The command 'gcloud projects get-iam-policy my-project --format json' retrieves the IAM policy bound to a project and outputs it in JSON. This is the correct gcloud command for viewing a project's IAM policy, which lists bindings between members and roles. The --format json flag ensures machine-readable JSON output.

Exam trap

The trap is confusing project metadata retrieval (describe) with IAM policy retrieval (get-iam-policy), or assuming a generic 'iam policies get' command exists — ACE tests precise command syntax and resource scope.

How to eliminate wrong answers

Option A is wrong because 'gcloud resource-manager folders get-iam-policy' operates on folders, not projects, and 'my-project' is a project ID — the command would fail or target the wrong resource hierarchy level. Option B is wrong because 'gcloud projects describe' returns project metadata (name, ID, number, lifecycle state), not the IAM policy. Option D is wrong because 'gcloud iam policies get' is not a valid gcloud command — IAM policies are retrieved via resource-specific get-iam-policy commands, not a generic iam policies get.

37
MCQmedium

An engineer needs to grant an external auditor read-only access to view IAM policies on a GCP project. The auditor should not have access to any other resources. Which IAM role should be assigned?

A.roles/iam.roleAdmin
B.roles/iam.serviceAccountAdmin
C.roles/viewer
D.roles/iam.securityReviewer
AnswerD

roles/iam.securityReviewer is the correct choice because it grants permission to view IAM policies (for example, 'getIamPolicy') across all resources without allowing any modifications. It also includes permissions to list and get roles, which is exactly what an external auditor needs to review access configuration. This role aligns with least privilege for a read-only audit.

Why this answer

The `roles/iam.securityReviewer` role grants permission to view IAM policies without granting access to other resources. It is specifically designed for security auditors.

38
MCQhard

An organization has a folder hierarchy with multiple projects. They want to grant a support team the ability to view all IAM policies across the entire folder. What is the most efficient way?

A.Grant roles/iam.securityReviewer at the folder level.
B.Grant roles/iam.securityReviewer on each project individually.
C.Grant roles/owner at the folder level.
D.Grant roles/viewer at the folder level.
AnswerA

Granting roles/iam.securityReviewer at the folder level is correct because IAM permissions propagate through the resource hierarchy. This predefined role includes resourcemanager.folders.getIamPolicy and resourcemanager.projects.getIamPolicy, allowing the user to read IAM policies on the folder and every project, folder, and resource beneath it. Because the audit scope is the entire folder hierarchy, one grant at the folder root covers all child projects without per-project assignments, satisfying the requirement efficiently and with least privilege.

Why this answer

Granting roles/iam.securityReviewer at the folder level is the most efficient approach because IAM policies in Google Cloud are hierarchical and inherited. A single binding at the folder level automatically applies to every project and resource beneath it, so the support team gains visibility into all IAM policies across all projects without per-project configuration. This follows the principle of least privilege while minimizing administrative overhead.

Exam trap

ACE often tests the misconception that roles/viewer or roles/owner are sufficient for auditing IAM — candidates forget that viewer lacks IAM read permissions and owner is over-privileged, and they overlook that folder-level inheritance is the efficient answer.

How to eliminate wrong answers

Option B is wrong because granting the role on each project individually is operationally inefficient and error-prone — new projects added later would not be covered, and it requires N separate bindings instead of one. Option C is wrong because roles/owner grants full control over all resources (including billing, IAM modification, and deletion), which is far more privilege than needed to merely view IAM policies and violates least privilege. Option D is wrong because roles/viewer grants read access to most resources but does not include the specific iam.policies.get and related permissions needed to review IAM policies; securityReviewer is the purpose-built role for auditing IAM.

39
MCQmedium

A company has multiple VPC networks in their project. They want Compute Engine instances in one VPC to communicate with instances in another VPC using internal IP addresses. Which feature should they use?

A.Cloud NAT
B.VPC Network Peering
C.Cloud VPN
D.Firewall rules
AnswerB

VPC Network Peering directly connects two VPC networks over Google's private backbone, allowing instances in each network to communicate using internal RFC 1918 addresses without needing public IPs or a VPN. It is the recommended method for inter-VPC connectivity because it offers low latency, no bandwidth restrictions, and no single point of failure. Peering works across projects and organizations, and it automatically exchanges routes for all subnets in the peered networks, so it fully satisfies the requirement to connect multiple VPC networks.

Why this answer

VPC Peering allows connectivity between two VPC networks using internal IPs. VPN is for on-premises connectivity. Cloud NAT is for outbound internet access.

Firewall rules control traffic but do not enable routing between VPCs.

40
MCQhard

A company has a Google Cloud organization with multiple folders and projects. The security team wants to audit all actions that create or modify IAM policies across the entire organization. Which type of audit log should they examine?

A.System Event audit logs
B.Data Access audit logs
C.VPC Flow Logs
D.Admin Activity audit logs
AnswerD

Admin Activity audit logs are enabled by default and capture all API calls that modify the configuration or metadata of resources, including IAM policy updates. For an organization with multiple folders, these logs at the org level record IAM binding changes on any resource in the hierarchy, such as 'setIamPolicy' from projects or folders. They provide an audit trail of who changed what, when, from where, and for which resource, making them the correct log type for investigating IAM policy modifications.

Why this answer

Admin Activity audit logs in Google Cloud record all API calls that modify resource configurations, including IAM policy changes (e.g., setIamPolicy). They are enabled by default, cannot be disabled, and are the correct log type for auditing who created or modified IAM policies across the organization.

Exam trap

ACE often tests the distinction between Admin Activity (config changes) and Data Access (data reads/writes), causing candidates to pick Data Access when the question is about IAM policy modifications.

How to eliminate wrong answers

Option A is wrong because System Event audit logs record Google-initiated system actions (e.g., live migration, automatic restarts), not user-driven IAM changes. Option B is wrong because Data Access audit logs record reads and writes of user data (e.g., reading a GCS object), not administrative configuration changes like IAM policy modifications. Option C is wrong because VPC Flow Logs capture network traffic metadata (IP, port, protocol) for VPC subnets, not IAM or API activity.

41
MCQeasy

You need to add an IAM binding for a user to a project using the gcloud command. Which command should you use?

A.gcloud projects add-iam-policy-binding
B.gcloud iam service-accounts add-iam-policy-binding
C.gcloud projects set-iam-policy
D.gcloud iam roles update
AnswerA

gcloud projects add-iam-policy-binding PROJECT_ID --member=user:email@example.com --role=roles/viewer is the correct command because it performs an additive update to the project's IAM policy. It reads the current policy, appends the new binding (role + member) to the existing set, and writes the merged policy back atomically, leaving all other bindings untouched. This is the standard CLI operation for granting a specific role to a user at the project scope.

Why this answer

The correct command to add an IAM binding for a user to a project is gcloud projects add-iam-policy-binding, which modifies the project's IAM policy by granting a role to a member. This command is the standard way to manage project-level IAM bindings using gcloud. It requires the project ID, the member (user, group, or service account), and the role.

Exam trap

The trap is mixing up commands for different resource types (project vs. service account) and confusing IAM binding commands with role update commands.

How to eliminate wrong answers

Option B is wrong because gcloud iam service-accounts add-iam-policy-binding is used to grant roles on a service account resource, not on a project. Option C is wrong because gcloud projects set-iam-policy is not a valid gcloud command; IAM policies are modified via add-iam-policy-binding or set-iam-policy on some resources, but not with that exact syntax for projects. Option D is wrong because gcloud iam roles update modifies a custom role's permissions, not a user's IAM binding on a project.

42
Multi-Selecteasy

An engineer wants to view the current IAM policy for a project. Which TWO commands will accomplish this?

Select 2 answers
A.gcloud projects get-iam-policy my-project --format json
B.gcloud resource-manager folders get-iam-policy my-folder
C.gcloud iam service-accounts get-iam-policy my-sa@my-project.iam.gserviceaccount.com
D.gcloud projects get-iam-policy my-project
E.gcloud projects get-ancestors-iam-policy my-project
AnswersA, D

This is the correct command to retrieve the IAM policy for a specific project, and using `--format json` explicitly instructs the CLI to output the policy as a JSON object. The `--format` flag does not change the underlying policy data, but it provides a structured, machine-readable representation that is ideal for scripting with tools like `jq` or for programmatic inspection. Without this flag, the same data would be rendered in YAML by default, so this flag only ensures the output format is standard and predictable.

Why this answer

The gcloud projects get-iam-policy command retrieves the IAM policy for a project. The gcloud projects get-ancestors-iam-policy retrieves policies from ancestors, not the project itself. The other commands are for different purposes.

43
Multi-Selectmedium

A company needs to audit all actions that modify a Cloud Storage bucket. Which TWO steps should they take to enable this? (Choose 2 answers.)

Select 2 answers
A.Use Log Explorer to filter logs by the Cloud Storage service and the 'data_access' log type.
B.Create a VPC Service Controls perimeter.
C.Enable Admin Activity audit logs for the Cloud Storage service.
D.Assign the roles/logging.viewer role to the security team.
E.Enable Data Access audit logs for the Cloud Storage service in the project's IAM audit config.
AnswersA, E

Using Log Explorer in the Google Cloud console lets you query and filter audit logs once they are enabled. By applying a filter for the Cloud Storage service and the 'data_access' log type, you can view object-level operations such as writes, deletes, and overwrites. This is the final step that makes the audit trail visible and actionable for compliance, but it requires Data Access logging to already be enabled in the IAM audit config.

Why this answer

To audit data access modifications, you need to enable Data Access audit logs for the storage service and then view those logs in Log Explorer. Admin Activity logs record configuration changes (like creating a bucket), but data modifications (like uploading objects) require Data Access logs.

44
MCQmedium

An organization needs to audit all data access (read/write) to a Cloud Storage bucket for compliance. Which type of audit log should they enable?

A.System Event audit logs
B.Access Transparency logs
C.Admin Activity audit logs
D.Data Access audit logs
AnswerD

Data Access audit logs are the correct Cloud Audit Logs category for recording data-plane read/write operations, including Cloud Storage object GETs, BigQuery query reads, and Pub/Sub message publishes/pulls. They are typically disabled by default for most services and must be explicitly enabled for each service in the Audit Logs configuration, after which they deliver the who/what/when trail needed to audit data access across the organization.

Why this answer

Data Access audit logs record read and write operations on user data, including Cloud Storage object reads (e.g., storage.objects.get) and writes (e.g., storage.objects.create). They are specifically designed for auditing data access, unlike Admin Activity logs which capture configuration changes. Therefore, to audit all data access to a bucket, Data Access audit logs must be enabled.

Exam trap

ACE often tests the distinction between Admin Activity and Data Access logs, and candidates frequently confuse configuration changes with data access, leading them to choose Admin Activity logs when data access auditing is required.

How to eliminate wrong answers

Option A is wrong because System Event audit logs capture Google Cloud administrative actions that modify resource configurations, not data access. Option B is wrong because Access Transparency logs record actions taken by Google personnel, not customer data access. Option C is wrong because Admin Activity audit logs record configuration changes (e.g., bucket creation, IAM policy updates) but not data reads or writes.

45
MCQeasy

A company wants to automate the rotation of encryption keys for Cloud Storage buckets every 30 days. Which key type should be used?

A.Customer-Managed Encryption Keys (CMEK)
B.Google-managed encryption keys
C.Key Access Justification
D.Customer-Supplied Encryption Keys (CSEK)
AnswerA

Customer-Managed Encryption Keys (CMEK) is correct because it lets you control and automate key rotation through Cloud KMS. You define a rotation period (e.g., 30 days) on a key, and Cloud KMS automatically generates a new key version on that schedule while continuing to decrypt data with older versions. This provides both automated rotation and full auditability of when each version is used, which aligns with a company's requirement to rotate encryption keys without manual intervention.

Why this answer

Customer-Managed Encryption Keys (CMEK) allow the customer to control the key lifecycle, including rotation, through Cloud KMS. Because the customer owns and manages the key in KMS, they can set a rotation schedule (e.g., every 30 days) and automate it. Google-managed keys are rotated automatically by Google on a schedule the customer cannot control, and CSEK keys are supplied per-request and cannot be rotated by a schedule.

Exam trap

The trap is assuming that setting a rotation schedule on CMEK automatically re-encrypts existing data — it does not; rotation only creates new key versions, and existing objects must be rewritten to use them.

How to eliminate wrong answers

Option B is wrong because Google-managed encryption keys are rotated automatically by Google on Google's schedule, and the customer has no ability to set or automate a 30-day rotation policy. Option C is wrong because Key Access Justification is a control that provides justification for key access requests (an audit/access-transparency feature), not a key type used for encryption or rotation. Option D is wrong because Customer-Supplied Encryption Keys (CSEK) are provided with each API request and are not stored in Cloud KMS, so there is no built-in rotation mechanism — the customer would have to re-encrypt objects manually.

46
MCQmedium

You need to create a service account for a Compute Engine instance to allow it to access Cloud Storage objects. The service account should have minimal permissions. What is the recommended approach?

A.Create a service account and assign it to the instance using gcloud compute instances set-service-account after creation
B.Use the default compute engine service account and grant it roles/storage.objectAdmin
C.Create a service account, download a JSON key, and store it on the instance's local disk
D.Create a service account, grant it the required roles, and specify it when creating the instance using the --service-account flag
AnswerD

Creating a dedicated service account, granting it only the IAM roles the application needs, and passing it via the --service-account flag at instance creation time is the Google-recommended pattern. This attaches the identity to the instance without ever downloading a key, so the instance authenticates through the metadata server's short-lived OAuth tokens. It ensures least privilege and avoids the security risk of storing long-lived credentials on the VM.

Why this answer

The recommended approach is to create a dedicated service account, grant it only the required roles (e.g., roles/storage.objectViewer for read access), and attach it to the instance at creation time using the --service-account flag. This ensures the instance uses the least-privilege identity from the start and avoids the risks of default accounts or downloaded keys.

Exam trap

ACE often tests the misconception that downloading a JSON key is acceptable — the exam expects you to know that attached service accounts with least privilege are the recommended pattern, and keys should be avoided.

How to eliminate wrong answers

Option A is wrong because while you can change a service account after creation, the question asks for the recommended approach — attaching at creation is cleaner and avoids the instance running with default credentials in the interim. Option B is wrong because the default compute engine service account has broad permissions (Editor by default) and granting it roles/storage.objectAdmin violates least privilege. Option C is wrong because downloading a JSON key and storing it on disk is an anti-pattern — keys can be leaked, are hard to rotate, and Google recommends avoiding them in favor of attached service accounts.

47
MCQeasy

You need to create a Google-managed SSL certificate for an external HTTPS load balancer. The domain is 'www.example.com'. Which command creates the certificate?

A.gcloud compute ssl-certificates create my-cert --certificate example.crt --private-key example.key
B.gcloud compute ssl-certificates create my-cert --certificate example.crt
C.gcloud compute ssl-certificates create my-cert --domains www.example.com
D.gcloud compute ssl-certificates create my-cert --domains www.example.com --managed
AnswerC

The --domains flag is the correct mechanism to request a Google-managed certificate: gcloud will create an SslCertificate resource in MANAGED state, and Google's Certificate Authority will issue a certificate for the specified domain, handling the entire lifecycle including automatic renewal. No additional flags are required, because the presence of --domains unambiguously selects the managed provisioning mode. This command is the exact answer for creating a managed certificate via the gcloud CLI.

Why this answer

The correct command is gcloud compute ssl-certificates create with the --domains flag. This creates a Google-managed certificate that will be provisioned and renewed automatically.

48
MCQeasy

Which of the following is required to enable Private Google Access on a subnet?

A.Configuring the subnet with --enable-private-ip-google-access
B.A Cloud Router in the same region
C.A Cloud NAT gateway
D.VPC peering with a Google-managed network
AnswerA

The subnet-level flag --enable-private-ip-google-access is the required element because it configures the VPC subnet to route traffic from instances without external IPs directly to Google's public API endpoints over the Google network. Without this flag, VMs that lack an external IP address cannot reach Google APIs and services, even if the subnet has a default route with an internet gateway. This flag is set per subnet, and enabling it on the relevant subnet is the fundamental prerequisite for Private Google Access.

Why this answer

Private Google Access is enabled per-subnet using the gcloud flag --enable-private-ip-google-access (or the equivalent 'Private Google Access: On' setting in the console). This allows VM instances that only have internal IP addresses to reach Google APIs and services (such as Cloud Storage, BigQuery, and the metadata server) using Google's internal routing, without requiring an external IP or NAT. The setting is scoped to the subnet, so each subnet must be configured individually.

Exam trap

ACE often tests the confusion between Private Google Access (internal-only access to Google APIs) and Cloud NAT (outbound internet access), causing candidates to pick Cloud NAT as a prerequisite.

How to eliminate wrong answers

Option B is wrong because a Cloud Router is used for dynamic routing via BGP (Cloud NAT and hybrid connectivity), not for enabling Private Google Access; PGA works purely through Google's internal network fabric. Option C is wrong because Cloud NAT provides outbound internet access for instances without external IPs, but it is not required for Private Google Access — PGA traffic never leaves Google's network and does not traverse NAT. Option D is wrong because VPC peering with a Google-managed network is unrelated to PGA; PGA is a per-subnet toggle, not a peering construct.

49
Multi-Selecthard

A company wants to implement a least-privilege security model for a service account that needs to read secrets from Secret Manager and publish messages to Pub/Sub. Which TWO IAM roles should be granted? (Choose TWO)

Select 2 answers
A.roles/pubsub.publisher
B.roles/secretmanager.viewer
C.roles/secretmanager.secretAccessor
D.roles/pubsub.admin
E.roles/secretmanager.admin
AnswersA, C

roles/pubsub.publisher is the correct least-privilege choice because it contains only the pubsub.topics.publish permission, which is exactly what a producer needs to send messages to a Pub/Sub topic. It does not grant permission to create, delete, or modify topics, subscribe, or manage IAM, so a compromised token from this service account could not reconfigure messaging infrastructure.

Why this answer

Option A, roles/pubsub.publisher, is correct because it grants exactly the permission needed to publish messages to a Pub/Sub topic (pubsub.topics.publish) without granting administrative capabilities, which fits the least-privilege requirement. Option C, roles/secretmanager.secretAccessor, is correct because it provides the minimal permission to access the payload of a secret (secretmanager.versions.access), which is precisely what the service account needs to read secrets. Option B, roles/secretmanager.viewer, is not appropriate because it allows viewing secret metadata but not accessing the secret payload, so it would not satisfy the read-secrets requirement.

Option D, roles/pubsub.admin, is too broad since it grants full control over Pub/Sub resources, violating least privilege. Option E, roles/secretmanager.admin, is also overly permissive, granting full administrative control over Secret Manager rather than just read access.

Exam trap

ACE often tests the difference between viewer and accessor roles — candidates pick secretmanager.viewer thinking it allows reading the secret, but it only exposes metadata, not the payload.

50
MCQmedium

An engineer needs to enable Private Google Access for a subnet to allow instances without external IPs to access Google APIs and services. Which flag should be used when creating or updating the subnet?

A.--enable-google-access
B.--private-google-access
C.--enable-private-ip-google-access
D.--enable-private-ip
AnswerC

This is the correct flag. According to the gcloud compute networks subnets update documentation, "--enable-private-ip-google-access" modifies the subnet's privateIpGoogleAccess field, allowing VM instances without external IP addresses to reach Google APIs using the subnet's default route. This is the only flag listed that maps directly to the REST API parameter.

Why this answer

Private Google Access is enabled on a subnet using the `--enable-private-ip-google-access` flag. This allows instances in the subnet to reach Google APIs via the default route.

51
Multi-Selecthard

A company wants to allow developers to create and manage secrets in Secret Manager, but prevent them from viewing secret values. Which TWO predefined roles should be combined to achieve this?

Select 2 answers
A.roles/secretmanager.admin
B.roles/secretmanager.secretAccessor
C.roles/secretmanager.secretManager
D.roles/secretmanager.secretVersionManager
E.roles/secretmanager.viewer
AnswersC, D

roles/secretmanager.secretManager grants permissions to create, get, list, update, and delete secret resources, plus view metadata, but deliberately omits secretmanager.versions.access. This lets developers fully manage the secret lifecycle without ever being able to view the sensitive payload, making it the correct least-privilege choice for the stated requirement to create and manage secrets while preventing access to values.

Why this answer

The roles/secretmanager.admin role includes permissions to create and manage secrets but not to access secret versions (i.e., view values). However, it includes the permission to access versions. Actually, the admin role includes secretmanager.versions.access, so it can view values.

To separate manage from view, you need roles/secretmanager.secretVersionManager (manage versions without access) and roles/secretmanager.secretManager (manage secrets). Wait, the correct combination is roles/secretmanager.secretVersionManager (create/disable/destroy versions) and roles/secretmanager.secretManager (create/update/delete secrets). Neither includes secretmanager.versions.access.

The roles/secretmanager.viewer allows viewing metadata but not values. The roles/secretmanager.secretAccessor allows accessing versions. To manage without viewing, combine roles that exclude access.

Check accurate roles: roles/secretmanager.admin includes all permissions including access. roles/secretmanager.secretManager includes manage secrets but not access versions? Let's verify: roles/secretmanager.secretManager has permissions: secretmanager.secrets.create, secretmanager.secrets.delete, secretmanager.secrets.get, secretmanager.secrets.update, secretmanager.secrets.list. It does NOT include secretmanager.versions.access. roles/secretmanager.secretVersionManager has permissions: secretmanager.versions.create, secretmanager.versions.disable, secretmanager.versions.destroy, secretmanager.versions.enable, secretmanager.versions.get, secretmanager.versions.list. It does NOT include secretmanager.versions.access.

So combining these two roles allows managing secrets and versions but not accessing the payload. roles/secretmanager.viewer allows viewing metadata but not accessing payload. roles/secretmanager.secretAccessor allows accessing payload. So the correct two are secretManager and secretVersionManager.

52
MCQeasy

You need to grant a user the ability to view audit logs for a project but not modify any resources. Which predefined IAM role should you assign?

A.roles/iam.securityReviewer
B.roles/owner
C.roles/viewer
D.roles/logging.viewer
AnswerD

roles/logging.viewer is the predefined role for read-only access to Cloud Logging data. It includes permissions such as logging.logEntries.list, logging.logEntries.get, and logging.logs.list, which are required to view audit logs in the Logs Explorer. This role cannot modify log sinks or delete logs, providing the least-privileged access to view audit logs.

Why this answer

The roles/logging.viewer role provides read-only access to logs, including audit logs. roles/iam.securityReviewer provides read access to IAM policies but not logs. roles/viewer is too broad. roles/owner is administrative.

53
MCQmedium

A security team wants to audit all Data Access attempts in a project for a specific Cloud Storage bucket, including who accessed which object and when. Which configuration is required?

A.Configure VPC Flow Logs on the VPC network
B.Set up Cloud Monitoring alerts on the bucket
C.Enable Admin Activity audit logs for Cloud Storage in the project
D.Enable Data Access audit logs for Cloud Storage in the project's IAM audit config
AnswerD

Data Access audit logs for Cloud Storage capture object-level read (e.g., object.get) and write (e.g., object.create) API calls, including the principal, source IP, timestamp, and the specific resource accessed. Because Data Access audit logs are disabled by default, they must be explicitly enabled in the project's IAM audit config to satisfy security auditing requirements.

Why this answer

To audit data access attempts on a Cloud Storage bucket, including who accessed which object and when, you must enable Data Access audit logs for Cloud Storage in the project's IAM audit configuration. Data Access logs record read and write operations on objects, whereas Admin Activity logs only record configuration changes. Enabling Data Access logs at the project level ensures all bucket access is captured.

Exam trap

The trap is confusing Admin Activity logs (configuration changes) with Data Access logs (object reads/writes), leading candidates to pick the wrong log type for auditing data access.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP, port, protocol) but not application-level object access or user identity. Option B is wrong because Cloud Monitoring alerts notify on metrics or logs but do not themselves generate the audit data; they depend on logs already being enabled. Option C is wrong because Admin Activity audit logs only record administrative actions like creating or deleting buckets, not object reads or writes.

54
MCQhard

An organization uses Organization Policies to restrict the use of certain IAM roles. The security team wants to audit all modifications to IAM policies across the organization, including at the project level. Which log type should be enabled and analyzed?

A.Admin Activity audit logs
B.System Event audit logs
C.Data Access audit logs (READ)
D.Data Access audit logs (WRITE)
AnswerA

Admin Activity audit logs record all API calls that modify configuration or metadata of resources, including IAM policy changes. In Cloud Logging, they are enabled by default and retained for 400 days. Since setting an IAM policy (e.g., projects.setIamPolicy) is a configuration-modifying operation, it's captured here. That's why this is the correct choice.

Why this answer

Admin Activity audit logs record all API calls or other actions that modify the configuration or metadata of resources, including IAM policy changes. They are enabled by default and cannot be disabled. To audit modifications to IAM policies at the organization and project level, Admin Activity logs are the correct choice.

Exam trap

ACE often tests the confusion between Admin Activity and Data Access logs, but IAM policy changes are Admin Activity, not Data Access.

How to eliminate wrong answers

Option B is wrong because System Event audit logs record Google Cloud administrative actions that modify resources, but they are for system-generated events, not user-initiated IAM changes. Option C is wrong because Data Access audit logs (READ) record read operations, not modifications. Option D is wrong because Data Access audit logs (WRITE) record write operations, but they are not enabled by default and are for data access, not admin activity; IAM policy changes are considered admin activity, not data access.

55
MCQhard

An organization wants to use Cloud NAT to allow private Compute Engine instances to access the internet for updates. They have a VPC with a custom subnet and a Cloud Router configured. However, instances cannot reach the internet. What is the most likely cause?

A.The Cloud NAT gateway has not been created on the Cloud Router.
B.The instances do not have external IP addresses.
C.The firewall rules block egress traffic.
D.The subnet does not have Private Google Access enabled.
AnswerA

A Cloud Router alone is only a BGP session manager; it does not perform address translation by itself. To enable NAT on a VPC, you must explicitly create a Cloud NAT gateway and attach it to the Cloud Router for a given region and subnetwork, which then maps private IPs to a pool of external IPs. Without that gateway, outbound packets from private instances are dropped when they try to reach the internet, regardless of routing.

Why this answer

Cloud NAT requires a NAT gateway to be explicitly created and associated with a Cloud Router and a subnet/region. If the Cloud Router exists but no NAT gateway has been configured on it, private instances have no translation path to the internet, which is the most likely cause of the failure. Creating the NAT gateway on the Cloud Router resolves the issue.

Exam trap

ACE often tests the assumption that configuring a Cloud Router automatically enables NAT — candidates must know that the NAT gateway is a separate resource that must be explicitly created and bound to the router.

How to eliminate wrong answers

Option B is wrong because private instances are not supposed to have external IPs — Cloud NAT exists precisely to let instances without external IPs reach the internet, so their absence is expected, not the cause. Option C is wrong because default egress firewall rules in GCP allow outbound traffic; while a custom rule could block it, the scenario states a Cloud Router is configured but doesn't mention restrictive firewall rules, making this less likely than a missing NAT gateway. Option D is wrong because Private Google Access only enables access to Google APIs and services, not general internet access — it's unrelated to reaching external update servers.

56
MCQhard

A company is using Cloud NAT to allow private Compute Engine instances to access the internet. They notice that traffic from some instances is not being NATed. What is the most likely cause?

A.The instances have external IP addresses assigned.
B.The Cloud Router is not configured correctly.
C.The firewall rules block egress traffic.
D.The instances are in a different region than the Cloud NAT gateway.
AnswerA

Cloud NAT is designed to provide source network address translation for private instances that do not have external IP addresses. If an instance is assigned an external IP, even an ephemeral one, its outbound traffic will use that IP as the source address, completely bypassing Cloud NAT. Therefore, the observation that traffic is 'not being NATed' is exactly what would happen when instances have external IPs, not a sign of NAT misconfiguration.

Why this answer

Cloud NAT only applies to instances that do not have external IP addresses. If an instance has an external IP, it will use that IP for outbound traffic and bypass Cloud NAT.

57
MCQeasy

What is the primary benefit of using a Google-managed SSL certificate for an HTTPS Load Balancer?

A.It is free of charge.
B.It automatically renews the certificate before expiration.
C.It can be used with any type of load balancer.
D.It provides stronger encryption than self-managed certificates.
AnswerB

Google-managed certificates automatically handle both provisioning and renewal, so you never have to manually track expiration dates or replace certificates. After you configure the certificate on an HTTPS target proxy, Google Cloud's certificate manager regularly checks the certificate's validity and renews it approximately 30 days before expiration, provided the domain's DNS record still points to the load balancer. This automation is the key advantage because it prevents outages caused by expired certificates.

Why this answer

Google-managed SSL certificates are provisioned and renewed automatically by Google, eliminating the operational burden of manual renewal and reducing the risk of expiration-related outages. The primary benefit is this automated lifecycle management, which ensures the certificate stays valid without intervention.

Exam trap

ACE often tests the misconception that Google-managed certificates work with all load balancer types or that their main advantage is cost, when the real benefit is automatic renewal.

How to eliminate wrong answers

Option A is wrong because while Google-managed certificates are provided at no additional cost, 'free of charge' is not the primary benefit — the key value is automation, and cost is secondary. Option C is wrong because Google-managed certificates are only supported on external HTTP(S) load balancers, not on any type of load balancer (e.g., internal TCP/UDP or SSL proxy load balancers). Option D is wrong because encryption strength is determined by the cipher suites and TLS versions negotiated, not by whether the certificate is Google-managed or self-managed; both can use strong encryption.

58
Multi-Selectmedium

A developer wants to automate the creation of a service account and assign it a role using the gcloud command-line tool. Which TWO commands are needed? (Choose 2 answers.)

Select 2 answers
A.gcloud projects add-iam-policy-binding
B.gcloud iam service-accounts keys create
C.gcloud projects set-iam-policy
D.gcloud iam service-accounts create
E.gcloud iam roles create
AnswersA, D

gcloud projects add-iam-policy-binding is the precise command to grant an existing service account an IAM role on a project. It performs an additive update to the project's IAM policy, leaving all other bindings intact, which is exactly what is needed when automating service account creation and subsequent access provisioning. The command requires the service account's email as the member and the role name (e.g., roles/storage.objectViewer), and it applies the binding only at the project level, matching the scenario.

Why this answer

First, you create the service account with `gcloud iam service-accounts create`. Then, you grant a role to the service account by adding an IAM policy binding to the project.

59
MCQeasy

Which IAM role should be granted to a service account to allow it to access a secret stored in Secret Manager?

A.roles/secretmanager.secretAccessor
B.roles/secretmanager.admin
C.roles/iam.serviceAccountUser
D.roles/secretmanager.viewer
AnswerA

roles/secretmanager.secretAccessor is the correct and minimal predefined role for service accounts that need to retrieve secret payloads. It includes the `secretmanager.versions.access` permission, which allows the caller to access the encryption-decrypted secret value from a specified version, and `secretmanager.versions.get` for metadata of that version. It does not permit creating, deleting, or modifying secrets, nor changing IAM policies, making it the exact role for a workload that reads a secret at runtime without administrative side effects.

Why this answer

The role 'secretmanager.secretAccessor' grants access to read secret versions.

60
MCQeasy

A developer wants to store a database password securely and make it accessible to a Compute Engine instance. Which Google Cloud service should be used?

A.Secret Manager
B.Cloud Storage
C.Cloud Filestore
D.Cloud KMS
AnswerA

Secret Manager is the correct choice because it is Google Cloud's purpose-built service for storing sensitive data such as database passwords, API keys, and certificates. It provides fine-grained IAM policies, automatic versioning, audit logging of secret access, and integration with services like Cloud Functions and GKE. Additionally, it supports secret rotation and allows you to enforce retention policies, making it the secure and native solution for managing a database password.

Why this answer

Secret Manager is Google Cloud's dedicated service for storing, managing, and accessing sensitive data such as API keys, passwords, and certificates. It provides versioning, IAM-based access control, audit logging, and automatic encryption. Applications on Compute Engine can retrieve secrets via the Secret Manager API using their attached service account.

Exam trap

The trap is confusing Cloud KMS with Secret Manager — candidates think KMS stores secrets, but KMS only manages encryption keys; Secret Manager is the correct service for storing credentials.

How to eliminate wrong answers

Option B is wrong because Cloud Storage is object storage and lacks secret-specific features like versioning, rotation, and fine-grained access auditing for credentials. Option C is wrong because Cloud Filestore is a managed NFS file system for file sharing, not a secret store. Option D is wrong because Cloud KMS manages encryption keys, not arbitrary secrets like database passwords — KMS is used to encrypt data, not to store credentials directly.

61
MCQmedium

An engineer creates a firewall rule allowing ingress on port 8080 from source range 10.0.0.0/8 with priority 1000. Another rule denies ingress on port 8080 from source range 10.0.0.0/24 with priority 500. What is the effective behavior for traffic from 10.0.0.1?

A.Traffic is denied only if the source is exactly 10.0.0.1; otherwise allowed.
B.Traffic is denied because the deny rule has a higher priority (lower number).
C.Traffic is allowed because the allow rule covers a larger range.
D.Traffic is allowed because both rules match and the default is to allow.
AnswerB

In Google Cloud VPC firewall rules, priority values determine evaluation order; lower numbers are evaluated first. The deny rule has a priority of 500, whereas the allow rule has 1000, so the deny rule is matched first. Because GCP applies the first matching rule and then stops, the traffic is denied before the allow rule is ever considered.

Why this answer

GCP firewall rules are evaluated by priority, where a lower number means higher priority. The deny rule has priority 500, which is lower than the allow rule's priority 1000, so the deny rule is evaluated first and matches traffic from 10.0.0.1 (which falls within 10.0.0.0/24). Therefore, the traffic is denied.

Exam trap

ACE often tests the inverted priority logic in GCP — candidates assume higher numbers mean higher priority (as in some other systems), but in GCP, lower numbers win.

How to eliminate wrong answers

Option A is wrong because the deny rule applies to the entire 10.0.0.0/24 subnet, not just the single IP 10.0.0.1, and the behavior is not conditional on the exact source. Option C is wrong because rule priority, not the size of the source range, determines which rule takes effect; a more specific deny with higher priority overrides a broader allow. Option D is wrong because GCP does not default to allow when rules conflict — the highest-priority matching rule wins, and there is no implicit allow for ingress (the implied default is deny).

62
MCQhard

An organization wants to enable Data Access audit logs for all Cloud Storage buckets in a project. Which step is necessary?

A.Use gcloud logging to create a log sink for Cloud Storage.
B.Enable Data Access logs in each bucket's settings.
C.Configure an organization policy or IAM audit config to enable Data Access logs for Cloud Storage.
D.Add an IAM binding with the roles/logging.admin role to a user.
AnswerC

This is the correct approach: Data Access audit logs for Cloud Storage are enabled by adding a Cloud Storage audit config at the project, folder, or organization level using the IAM 'Audit Logs' tab or by setting an auditConfig in the IAM policy. You can specify the service storage.googleapis.com and include the desired permission types—ADMIN_READ, DATA_READ, DATA_WRITE—or use ALL. After the audit config is applied, Cloud Logging begins recording data access events on the matching buckets automatically, with no further per-bucket steps needed.

Why this answer

To enable Data Access audit logs for all Cloud Storage buckets in a project, you must configure audit logging at the project or organization level using IAM audit configs or an organization policy. This sets the desired audit log type (DATA_READ, DATA_WRITE, ADMIN_READ) for the Cloud Storage service across all buckets, rather than configuring each bucket individually.

Exam trap

ACE often tests the misconception that Data Access logs are enabled per-resource (like a bucket) or via log sinks, when in fact they are enabled at the project/organization level through IAM audit configs.

How to eliminate wrong answers

Option A is wrong because a log sink routes logs to a destination but does not enable Data Access logs; the logs must first be enabled via audit config. Option B is wrong because Data Access logs are not enabled per-bucket in Cloud Storage settings; they are controlled at the project/organization IAM audit config level. Option D is wrong because granting roles/logging.admin to a user only provides permissions to manage logging, not the act of enabling Data Access logs for a service.

63
Multi-Selecthard

Which THREE configurations are required to enable Private Google Access for Compute Engine instances in a custom VPC subnet? (Select 3 correct answers)

Select 3 answers
A.Create a Cloud Router to advertise routes to Google.
B.Create a subnet with the --enable-private-ip-google-access flag.
C.Create a VPC network.
D.Launch Compute Engine instances in the subnet.
E.Configure Cloud NAT to route traffic to Google APIs.
AnswersB, C, D

Enabling the --enable-private-ip-google-access flag on the subnet is the core requirement because it tells Google Cloud to allow instances in that subnet to reach Google APIs using only their internal IP addresses. After this flag is set, the VPC's routing table automatically includes a route for Google's API ranges that sends traffic over the internal Google network instead of the public internet. This flag must be present on every subnet where you want Private Google Access to work; enabling it on the VPC or a single instance is not possible.

Why this answer

Private Google Access is enabled on a subnet. Instances in that subnet can reach Google APIs using internal IPs. It does not require Cloud NAT, Cloud VPN, or internet access.

The three required elements are: a VPC network, a subnet with Private Google Access enabled, and instances in that subnet.

64
MCQeasy

Which command is used to view the current IAM policy for a Google Cloud project in JSON format?

A.gcloud compute instances get-iam-policy [INSTANCE]
B.gcloud organizations get-iam-policy [ORG_ID]
C.gcloud projects get-iam-policy [PROJECT_ID] --format json
D.gcloud iam service-accounts get-iam-policy [SERVICE_ACCOUNT]
AnswerC

This command correctly retrieves the IAM policy for the specified GCP project, including all role bindings for members at the project level. The --format json flag ensures the output is machine-readable JSON, which is useful for automation or programmatic inspection. It is the standard gcloud command for viewing project-level IAM policies.

Why this answer

The 'gcloud projects get-iam-policy' command retrieves the IAM policy for a project. The '--format json' flag outputs it in JSON. The other options are for other resources or wrong scope.

65
MCQhard

A company uses Cloud SQL with Customer-Managed Encryption Keys (CMEK). The security team wants to rotate the encryption key. What is the impact on the Cloud SQL instance?

A.The instance becomes unavailable until the key rotation is complete.
B.All data in the instance is re-encrypted immediately.
C.The instance must be stopped and restarted after the key rotation.
D.There is no impact; the instance automatically uses the new key version.
AnswerC

This is the correct operational behavior. After rotating the key version in Cloud KMS, you must restart the Cloud SQL instance using the console, gcloud command, or API so that it recognizes the new key version as the encryption key for upcoming writes. The restart is required because the instance caches the old key version in memory, and the new version is only picked up during instance startup. This allows existing data to still be decrypted with the prior version while new encrypted data uses the updated version.

Why this answer

When rotating a CMEK for Cloud SQL, the instance must be restarted to use the new key version. Data remains encrypted at all times.

66
MCQmedium

A DevOps team needs to grant a CI/CD service account the ability to create secrets in Secret Manager. Which role should be assigned?

A.roles/secretmanager.admin
B.roles/secretmanager.secretCreator
C.roles/secretmanager.secretAccessor
D.roles/secretmanager.viewer
AnswerA

The `roles/secretmanager.admin` role includes the `secretmanager.secrets.create` permission required for adding a new secret via the Cloud Console, gcloud CLI, or Secret Manager API. It also grants full management of versions, IAM policies, and deletion, so it is the predefined role that reliably supports all CI/CD operations that need to provision and rotate secrets.

Why this answer

The roles/secretmanager.admin role grants full control, including creating secrets. roles/secretmanager.secretCreator does not exist; the admin role includes create permission.

67
MCQmedium

A security engineer needs to ensure that all VMs in a subnet use Private Google Access to reach Google APIs without external IP addresses. What must be enabled?

A.A firewall rule allowing egress to 0.0.0.0/0.
B.VPC Flow Logs on the subnet.
C.Cloud NAT on the VPC.
D.Private Google Access on the subnet.
AnswerD

Private Google Access on the subnet is the correct configuration to enable VMs without external IPs to reach Google APIs and services. When enabled, the subnet's VMs can send traffic to Google's public API IPs, which are then routed internally through the VPC's default route and into Google's network without ever needing an external IP. This is a subnet-level Boolean flag that must be turned on for each subnet where you want the capability; it applies to the entire subnet and works with the standard default route. Enabling this is the direct, documented mechanism that satisfies the security engineer's requirement.

Why this answer

Private Google Access allows VMs without external IP addresses to reach Google APIs and services using internal IP addresses. Enabling it on the subnet is the correct configuration to meet the requirement.

Exam trap

ACE often tests the confusion between Private Google Access and Cloud NAT; candidates may think Cloud NAT is needed for Google APIs, but Private Google Access is the correct feature for internal access to Google services.

How to eliminate wrong answers

Option A is wrong because a firewall rule allowing egress to 0.0.0.0/0 does not enable Private Google Access; it only permits outbound traffic, but without external IPs, VMs cannot reach Google APIs unless Private Google Access is enabled. Option B is wrong because VPC Flow Logs only capture network traffic for monitoring, not enable access. Option C is wrong because Cloud NAT provides outbound internet access for VMs without external IPs, but it does not specifically enable access to Google APIs via internal addresses; Private Google Access is the dedicated feature for that.

68
MCQhard

An organization has a requirement that all Compute Engine instances must be able to access only a specific set of Google Cloud APIs, and no others. The security team wants to enforce this using IAM and access scopes. Which combination should they use?

A.Set the instance's access scopes to the specific APIs needed and grant the service account only the necessary IAM roles.
B.Disable all access scopes and rely solely on IAM roles to control API access.
C.Set the instance's access scopes to cloud-platform and grant the service account the Editor role.
D.Use the default access scopes and grant the service account the Viewer role.
AnswerA

Access scopes define the maximum set of APIs an instance can call, while IAM roles determine the actual permissions. By setting scopes to only the required APIs and granting minimal IAM roles, the instance is restricted to exactly the needed APIs. This enforces defense in depth and meets the requirement of limiting access to a specific set.

Why this answer

Access scopes and IAM roles together control what APIs an instance can access. Scopes set the maximum allowed APIs, while IAM roles grant specific permissions. To restrict an instance to a specific set of APIs, set the scopes to only those APIs and grant the service account only the IAM roles needed for those APIs.

This layered approach ensures least privilege and meets the security requirement.

Exam trap

The trap here is thinking that IAM roles alone control API access, or that broad scopes like cloud-platform are necessary for functionality.

69
MCQhard

A company has multiple firewall rules. Rule A (priority 1000) allows TCP 80 from 0.0.0.0/0. Rule B (priority 500) denies TCP 80 from 10.0.0.0/8. An instance with IP 10.0.0.1 tries to connect to TCP 80. What happens?

A.The result depends on the order of creation.
B.Traffic is allowed because Rule A allows all sources.
C.Both rules are applied and traffic is allowed.
D.Traffic is denied because Rule B has higher priority.
AnswerD

Rule B has a priority of 500, which is numerically lower than Rule A's priority of 1000, so GCP evaluates Rule B first. Because Rule B's action is to deny and the traffic matches its conditions, that denial is the final decision. Rule A is not evaluated, so the traffic is denied as expected.

Why this answer

GCP firewall rules are evaluated by priority, where a lower number means higher priority; Rule B has priority 500, which is lower than Rule A's 1000, so Rule B is evaluated first. Because Rule B denies TCP 80 from 10.0.0.0/8 and the instance's IP 10.0.0.1 falls in that range, the traffic is denied. The matching deny rule wins before the allow rule is ever considered.

Exam trap

ACE often tests the inverted priority semantics of GCP firewall rules, so candidates who assume a higher number means higher priority conclude that Rule A allows the traffic.

How to eliminate wrong answers

Option A is wrong because GCP firewall evaluation is deterministic based on priority, not creation order. Option B is wrong because Rule A's allow is overridden by the higher-priority deny in Rule B for this source IP. Option C is wrong because GCP does not apply both rules and allow; the first matching rule (by priority) determines the outcome, and here it is a deny.

70
Multi-Selectmedium

A company is using Cloud Identity and wants to grant a group of auditors read-only access to all resources in a project, but they must not be able to modify any IAM policies. Which two roles should be granted to the group? (Choose two.)

Select 2 answers
A.roles/editor
B.roles/viewer
C.roles/iam.organizationRoleAdmin
D.roles/resourcemanager.projectIamAdmin
E.roles/iam.securityReviewer
AnswersB, E

The Viewer role provides read-only access to all resources within a project, excluding sensitive data and IAM policies. It allows auditors to view resources without the ability to modify them. This role is appropriate for granting broad read access while preventing changes, and it does not include permissions to alter IAM policies.

Why this answer

The Viewer role provides read-only access to resources, while the Security Reviewer role allows viewing IAM policies without modification. Together, they enable auditors to inspect all resources and access controls without the ability to make changes. This combination adheres to the principle of least privilege and meets the requirement of read-only access with no IAM policy modifications.

Exam trap

The trap here is assuming that roles with 'viewer' or 'reviewer' in the name might include write permissions, or that broader roles like Editor are needed for comprehensive access.

71
MCQeasy

What is the purpose of creating a Cloud NAT gateway?

A.To enable private instances to reach the internet for updates and patches.
B.To allow VPN connections to on-premises networks.
C.To provide a static IP address for inbound traffic.
D.To provide DNS resolution for VPC networks.
AnswerA

Cloud NAT lets instances without external IP addresses initiate outbound connections to the internet for updates and patches, while remaining unreachable from inbound internet traffic. This satisfies the requirement for private instances to obtain updates without exposing them publicly.

Why this answer

Cloud NAT allows instances without external IP addresses to access the internet for outbound connections, while preventing inbound connections from the internet.

72
MCQhard

An engineer created a VPC with a subnet in us-central1 and enabled Private Google Access on that subnet. Compute Engine instances in that subnet can reach Google APIs and services using internal IPs. However, the instances cannot reach external IP addresses on the internet. What should the engineer configure to allow internet access while minimizing cost and management overhead?

A.Create a Cloud NAT gateway using a Cloud Router
B.Disable Private Google Access and assign external IPs to the instances
C.Add a NAT instance (a Compute Engine VM configured as a NAT gateway)
D.Create a Cloud VPN tunnel to a third-party NAT service
AnswerA

Cloud NAT, configured through a Cloud Router, provides managed outbound internet connectivity to private Compute Engine instances without assigning them external IP addresses. It uses the Cloud Router to dynamically exchange routing information with the VPC network, allowing instances with internal IPs to initiate connections to the internet while remaining unreachable from outside. This is the recommended, highly available, and serverless solution because Cloud NAT automatically scales to handle thousands of instances and does not require manual patching or failover configuration.

Why this answer

Cloud NAT on a Cloud Router provides managed, outbound-only internet access for instances with internal IPs, without assigning external IPs or running a NAT VM. It integrates with the VPC and scales automatically, minimizing cost and operational overhead. Private Google Access can remain enabled alongside Cloud NAT.

Exam trap

The trap here is assuming that Private Google Access alone provides full internet access; it only covers Google APIs and services, so a separate NAT solution is required for general internet egress.

How to eliminate wrong answers

Option B is wrong because disabling Private Google Access and assigning external IPs reintroduces public exposure and management overhead, and external IPs are not required for NAT. Option C is wrong because a NAT instance is a self-managed VM that must be patched, scaled, and monitored, increasing cost and overhead. Option D is wrong because a Cloud VPN tunnel to a third-party NAT service adds unnecessary complexity, latency, and cost compared to native Cloud NAT.

73
MCQhard

An organization uses Secret Manager to store database credentials. A new application runs on Compute Engine and needs to access a secret. The application uses the default compute engine service account. What is the most secure way to grant access to the secret?

A.Hardcode the secret in the application configuration file
B.Create a new service account with the secretAccessor role, create a key, and store it on the instance
C.Grant the roles/editor role to the default compute engine service account
D.Grant the roles/secretmanager.secretAccessor role to the compute engine default service account
AnswerD

Granting the roles/secretmanager.secretAccessor role to the Compute Engine default service account is the correct approach because it gives the instance's identity the minimum permission needed to access secret versions. The instance authenticates through the metadata server, so no long-lived keys are stored on the instance. This makes it the most secure and operationally simple method, and it aligns with Google's recommended practice of using IAM roles on service accounts rather than embedding credentials.

Why this answer

The most secure way is to grant the roles/secretmanager.secretAccessor role directly to the Compute Engine default service account, leveraging the instance's attached identity. This avoids long-lived credentials, uses IAM for least-privilege access, and lets the application call the Secret Manager API via the metadata server. No keys are stored on disk, and access is auditable.

Exam trap

The trap is choosing an option that creates a service account key or uses a broad role, when the exam-tested best practice is to grant the narrow secretAccessor role to the existing attached service account.

How to eliminate wrong answers

Option A is wrong because hardcoding secrets in configuration files exposes them in source control, logs, and instance images — a critical security anti-pattern. Option B is wrong because creating a service account key and storing it on the instance introduces a long-lived credential that can be exfiltrated; Google recommends avoiding SA keys in favor of attached service accounts. Option C is wrong because roles/editor is a broad basic role granting extensive permissions far beyond secret access, violating least privilege.

74
MCQeasy

Which command creates a Google-managed SSL certificate for the domain 'example.com'?

A.gcloud compute ssl-certificates create my-cert --domains example.com
B.gcloud compute addresses create my-cert --global
C.gcloud compute ssl-policies create my-policy
D.gcloud compute target-https-proxies create my-proxy --ssl-certificates my-cert
AnswerA

This command correctly creates a Google-managed SSL certificate for the domain 'example.com'. The --domains flag tells the Cloud API to request a managed certificate, which Google will automatically obtain and renew without requiring you to upload a private key. Note that for a global external load balancer, you should also include --global, but the essential syntax for a managed certificate is exactly this.

Why this answer

Google-managed certificates are created with 'gcloud compute ssl-certificates create' with the '--domains' flag. The other commands are for different purposes.

75
MCQhard

A developer created a service account with the roles/storage.admin role and wants to use it from a Compute Engine instance without downloading a key file. What is the best practice?

A.Download the service account key and store it on the instance's persistent disk.
B.Use gcloud auth activate-service-account on the instance with the service account email.
C.Attach the service account to the instance using the --service-account flag when creating the instance.
D.Store the service account email in an instance metadata and use gcloud commands.
AnswerC

Attaching the service account via the --service-account flag at instance creation is the correct approach because it binds the identity to the VM and makes credentials available through the metadata server. Code running on the instance can fetch OAuth 2.0 tokens from the metadata endpoint (http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token) and act on behalf of the service account. This avoids managing key files and ensures that IAM permissions are automatically applied to the instance.

Why this answer

The best practice is to attach the service account to the Compute Engine instance at creation time using the --service-account flag. This allows the instance to automatically obtain credentials via the metadata server, avoiding the need to download and manage a service account key file. Downloading keys should be avoided due to security risks.

Ready to test yourself?

Try a timed practice session using only Configuring Access and Security questions.