Courseiva

CCNA Deploying and Implementing a Cloud Solution Questions

75 of 78 questions · Page 1/2 · Deploying and Implementing a Cloud Solution · Answers revealed

1
MCQhard

An engineer is configuring a GKE cluster and wants to enable Horizontal Pod Autoscaling (HPA) for a deployment named 'web-frontend'. The deployment currently has 3 replicas. The engineer wants to automatically scale the number of pods based on CPU utilization, targeting 50% average CPU utilization. Which command should the engineer run?

A.gcloud container clusters autoscale web-frontend --target-cpu-utilization=0.5 --min-nodes=3 --max-nodes=10
B.kubectl autoscale deployment web-frontend --max-cpu=50 --min=3 --max=10
C.kubectl autoscale deployment web-frontend --cpu-percent=50 --min=3 --max=10
D.kubectl autoscale deployment web-frontend --cpu=50 --min=3 --max=10
AnswerC

kubectl autoscale creates a HorizontalPodAutoscaler targeting the deployment, with --cpu-percent=50 setting the target utilisation and --min=3 --max=10 bounding replica count. This satisfies the requirement to scale web-frontend automatically on CPU, starting from its current 3 replicas.

Why this answer

The correct command is 'kubectl autoscale deployment web-frontend --cpu-percent=50 --min=3 --max=10', which creates an HPA targeting 50% average CPU utilization with a minimum of 3 and maximum of 10 replicas. The 'kubectl autoscale' subcommand is the standard imperative way to create an HPA for a deployment. The flags --cpu-percent, --min, and --max are the correct parameters for this command.

Exam trap

The trap is confusing cluster autoscaling (node-level, gcloud) with Horizontal Pod Autoscaling (pod-level, kubectl), and mixing up the --cpu-percent flag with invalid alternatives like --cpu or --max-cpu.

How to eliminate wrong answers

Option A is wrong because 'gcloud container clusters autoscale' configures cluster autoscaling (node-level), not Horizontal Pod Autoscaling, and uses node-oriented flags like --min-nodes and --max-nodes. Option B is wrong because '--max-cpu=50' is not a valid flag for kubectl autoscale; the correct flag is --cpu-percent. Option D is wrong because '--cpu=50' is not a valid flag; the correct flag is --cpu-percent.

2
MCQmedium

After deploying a Kubernetes Deployment named 'web-app', a developer wants to expose it externally on a static IP address. Which kubectl command should they use?

A.kubectl create service clusterip web-app --tcp=80:8080
B.gcloud compute forwarding-rules create web-app --port=80
C.kubectl expose deployment web-app --type=LoadBalancer --port=80 --target-port=8080
D.kubectl expose deployment web-app --type=NodePort --port=80
AnswerC

This is the correct approach because `kubectl expose deployment` with `--type=LoadBalancer` automatically creates a Kubernetes Service that instructs GKE to provision a cloud load balancer and allocate an external IP address. The `--port=80` specifies the Service port, while `--target-port=8080` directs traffic to the container's actual listening port on the Pod, matching the Deployment's container specification. If a reserved static IP is needed, you would reserve it in advance and add the `--load-balancer-ip` flag or annotate the Service; GKE then assigns that address to the load balancer.

Why this answer

The `kubectl expose deployment` command creates a Service from an existing Deployment, and `--type=LoadBalancer` provisions an external load balancer with a stable, externally reachable IP (on GKE, a Google Cloud network load balancer). The `--port=80` sets the Service port and `--target-port=8080` maps traffic to the container's listening port, which is exactly what's needed to expose the app externally on a static IP.

Exam trap

The trap here is confusing Service types — candidates pick NodePort thinking it provides external access, but only LoadBalancer (or Ingress backed by one) yields a static external IP on GKE.

How to eliminate wrong answers

Option A is wrong because `kubectl create service clusterip` creates a ClusterIP Service, which is only reachable inside the cluster and never gets an external IP. Option B is wrong because `gcloud compute forwarding-rules create` is a raw GCE networking command that bypasses Kubernetes Service abstraction and would not correctly target the Deployment's pods or manage endpoints. Option D is wrong because a NodePort Service exposes the app on each node's IP at a high port range (30000-32767) and does not provide a static external IP or a cloud load balancer.

3
MCQmedium

You have a managed instance group (MIG) with instances that need to run a startup script to configure monitoring agents. You created the instance template without a startup script. Which action should you take to add the startup script?

A.Use gcloud compute instances add-metadata to add the startup script to each running instance.
B.Delete the MIG and recreate it with a new template; you cannot change the template of an existing MIG.
C.Edit the existing instance template and add the startup script under 'metadata'.
D.Create a new instance template with the startup script, then update the MIG to use the new template via a rolling update.
AnswerD

The correct approach is to create a new instance template that includes the desired startup script in its metadata, then update the MIG to reference this new template using a rolling update. Since instance templates are immutable, creating a new template is mandatory. A rolling update (e.g., gcloud compute instance-groups managed rolling-action start-update) recreates the managed instances incrementally with the new template, ensuring the startup script executes during their boot. This method preserves availability and aligns with the MIG's declarative management model.

Why this answer

Instance templates are immutable; you cannot modify them. You must create a new instance template with the startup script and update the MIG to use it via rolling update or by setting the template.

4
Multi-Selectmedium

A company is deploying a new application on Google Cloud. The application consists of a frontend service and a backend API. The security team requires that the backend API be accessible only from the frontend service, not from the public internet. The frontend service runs on Compute Engine instances in a managed instance group. The backend API will be deployed on Cloud Run. Which two steps should the team take to meet these requirements? (Choose two.)

Select 2 answers
A.Create a Serverless VPC Access connector and configure the Cloud Run service to use it for all outbound traffic.
B.Configure the backend Cloud Run service with --allow-unauthenticated and rely on firewall rules to block external traffic.
C.Deploy the Cloud Run service with --ingress=internal and --no-allow-unauthenticated.
D.Grant the frontend's service account the Cloud Run Invoker role on the backend Cloud Run service.
E.Set up a private Service Connect endpoint for the Cloud Run service and configure the frontend to use it.
AnswersC, D

Setting --ingress=internal restricts traffic to sources within the same project or VPC network, blocking public internet access. --no-allow-unauthenticated requires authentication for all requests, ensuring that only authorized callers can invoke the service. This combination enforces both network-level and identity-level restrictions, which is necessary to prevent public access while allowing the frontend to authenticate.

Why this answer

To restrict a Cloud Run service to internal access and require authentication, set ingress to internal and disallow unauthenticated invocations. Then, grant the frontend's service account the Cloud Run Invoker role so it can authenticate. These two steps together ensure that only the frontend, with proper identity, can call the backend API, while public internet access is blocked.

Exam trap

The trap here is thinking that a Serverless VPC Access connector or firewall rules can secure inbound access to Cloud Run, when actually Cloud Run ingress and IAM authentication are the mechanisms that control who can reach the service.

5
MCQhard

An engineer needs to migrate a large on-premises database to Cloud SQL for PostgreSQL. The database is 500 GB and can tolerate a few hours of downtime. The migration must minimize manual intervention. Which approach should the engineer use?

A.Use Database Migration Service (DMS)
B.Use pg_dump to export and pg_restore to import
C.Use gcloud sql import to import a dump file
D.Set up a Compute Engine instance to run pg_dump and then gcloud sql import
AnswerA

Database Migration Service (DMS) is a fully managed service that automates the entire migration process, including a one-time full load followed by continuous change data capture (CDC) from the source database. This approach keeps the on-premises database online and synchronized during the migration, so you can cut over with minimal downtime. For a large database, DMS handles the heavy lifting of snapshotting and applying changes without needing to manually create or transfer dump files.

Why this answer

Database Migration Service supports homogeneous migrations (including PostgreSQL to Cloud SQL) and automates the process. It supports continuous replication and minimal downtime. The others are not ideal: pg_dump requires manual steps and downtime; gcloud sql import is for file import; Compute Engine with pg_dump involves manual steps.

6
MCQhard

You are managing a Cloud Functions deployment that processes messages from a Pub/Sub topic. You need to ensure the function can read messages from the topic and acknowledge them. Which IAM role should you assign to the function's service account?

A.roles/pubsub.publisher
B.roles/pubsub.subscriber
C.roles/pubsub.viewer
D.roles/iam.serviceAccountUser
AnswerB

The Pub/Sub Subscriber role (roles/pubsub.subscriber) is the correct, least-privileged role for a Cloud Functions trigger. It includes the permissions needed to pull messages (pubsub.subscriptions.consume) and acknowledge them after processing (pubsub.subscriptions.acknowledge), which is exactly what the function's runtime service account must do to read and complete each message from its subscription.

Why this answer

The Pub/Sub Subscriber role (roles/pubsub.subscriber) grants permission to pull messages and acknowledge them. The function's service account needs this role on the topic or subscription.

7
MCQmedium

An administrator needs to create a Cloud SQL for PostgreSQL instance with 16 vCPUs and 60 GB of memory. Which tier should they specify?

A.db-custom-16-60
B.db-custom-16-61440
C.db-n1-standard-16
D.db-custom-16-60000
AnswerB

This is the correct custom tier string because it conforms to the required db-custom-<vCPUs>-<memory_in_MB> format for Cloud SQL custom machine types. It specifies 16 vCPUs and 61,440 MB of memory, which is exactly 60 GB when applying the binary conversion factor of 1024 MB per GB. This string accurately represents the administrator's desired 16 vCPU / 60 GB configuration in the unit that Cloud SQL actually uses.

Why this answer

Cloud SQL tiers follow the pattern db-custom-#vcpus-#memoryMB. 16 vCPUs and 60 GB (61440 MB) uses db-custom-16-61440.

8
MCQmedium

A developer wants to deploy a containerized application on Google Cloud that automatically scales to zero when not in use and charges only for request processing time. The application is stateless and can be triggered by HTTP requests. Which compute option meets these requirements?

A.Compute Engine with managed instance groups
B.Cloud Functions
C.Cloud Run
D.Google Kubernetes Engine (GKE) with cluster autoscaling
AnswerC

Cloud Run is a fully managed serverless platform that runs stateless HTTP-triggered containers directly from a container image. It automatically scales down to zero when there are no incoming requests, so you incur no charges while idle, and bills only for request duration (CPU, memory, and concurrency metered during request handling). You can deploy any container that listens on HTTP, making it the ideal low-overhead choice for a containerized web application. Unlike GKE or Compute Engine, there is no infrastructure to manage or minimum charge for a running VM.

Why this answer

Cloud Run is a fully managed compute platform that runs stateless containers and automatically scales to zero when there is no traffic, charging only for the resources used during request processing. It supports HTTP requests and is ideal for containerized applications that need to scale dynamically. Cloud Functions is for function-based deployments, not containers, and GKE with cluster autoscaling does not scale to zero and charges for node uptime.

Exam trap

ACE often tests the distinction between serverless container platforms and other compute options, so candidates must remember that Cloud Run is the only option that scales to zero and charges only for request processing time for containers.

How to eliminate wrong answers

Option A is wrong because Compute Engine with managed instance groups does not scale to zero and charges for VM instances even when idle. Option B is wrong because Cloud Functions is a serverless function platform, not a container runtime; it does not support arbitrary containerized applications. Option D is wrong because GKE with cluster autoscaling scales nodes but does not scale to zero (minimum node count is typically 1) and charges for the underlying nodes, not just request processing time.

9
MCQmedium

A company wants to migrate an on-premises MySQL database to Cloud SQL. They need to import an existing SQL dump file stored in a Cloud Storage bucket. Which command should they use?

A.gcloud compute ssh my-instance --command='mysql < dump.sql'
B.gcloud sql import sql my-instance gs://my-bucket/dump.sql --database=mydb
C.gcloud sql databases create mydb --instance=my-instance --import=gs://my-bucket/dump.sql
D.gsutil cp gs://my-bucket/dump.sql | mysql -h my-instance -u root -p
AnswerB

This is the correct command to import a SQL dump file into a Cloud SQL MySQL instance. The `gcloud sql import sql` command takes the instance name, the Cloud Storage URI of the dump, and the `--database` flag to specify the target database. The Cloud SQL instance's service account must have `storage.objectViewer` permission on the bucket, and the database must already exist. This is the supported, asynchronous import method for managed Cloud SQL.

Why this answer

The correct command is gcloud sql import sql, which imports a SQL dump file from a Cloud Storage bucket into a Cloud SQL instance. It requires the instance name, the gs:// URI, and optionally --database to specify the target database.

Exam trap

ACE often tests the correct gcloud sql import syntax and the need for a Cloud Storage URI; candidates may confuse import with database creation or try to use gsutil/mysql directly.

How to eliminate wrong answers

Option A is wrong because it uses SSH to run mysql on a Compute Engine instance, not Cloud SQL import. Option C is wrong because gcloud sql databases create is for creating a database, not importing; the --import flag is not valid. Option D is wrong because it pipes gsutil cp output to mysql, which is not how Cloud SQL import works and requires direct MySQL connectivity.

10
MCQhard

A company is deploying a stateful application on Google Kubernetes Engine (GKE) that requires each pod to have a stable network identity and its own persistent volume. The application uses a clustered database that relies on consistent DNS names for peer discovery. The operations team wants to use GKE-native features to meet these requirements with minimal custom configuration. What should they do?

A.Create a DaemonSet with hostNetwork enabled and use local SSDs for storage.
B.Create a StatefulSet with a headless Service and a PersistentVolumeClaim template.
C.Create a StatefulSet with a regular ClusterIP Service and a single PersistentVolume manually created for each replica.
D.Create a Deployment with a ClusterIP Service and a single PersistentVolume shared by all pods.
AnswerB

A StatefulSet provides stable pod names, stable network identities via a headless Service, and ordered deployment and scaling. The headless Service (clusterIP: None) creates DNS records for each pod, enabling peer discovery. The volumeClaimTemplates automatically provisions a PersistentVolumeClaim for each pod, ensuring dedicated storage. This is the standard GKE-native approach for stateful clustered applications.

Why this answer

StatefulSets are designed for stateful applications that require stable identities and dedicated storage. A headless Service gives each pod a unique DNS name, which is essential for peer discovery in clustered databases. Volume claim templates dynamically create a PersistentVolumeClaim for each pod, ensuring each replica has its own persistent volume.

This combination is the recommended GKE-native solution for stateful workloads.

Exam trap

The trap here is assuming that a regular ClusterIP Service can provide stable per-pod DNS names, when in fact only a headless Service (with clusterIP: None) creates individual DNS records for each pod in a StatefulSet.

11
MCQhard

A team is using Terraform to manage Google Cloud resources. They want to store the Terraform state file in a Cloud Storage bucket to enable collaboration. Which Terraform backend configuration should be used?

A.provider "google" { backend "gcs" { bucket = "my-tf-state" } }
B.terraform { backend "cloud-storage" { bucket = "my-tf-state" path = "prod" } }
C.terraform { backend "gcs" { bucket = "my-tf-state" folder = "prod" } }
D.terraform { backend "gcs" { bucket = "my-tf-state" prefix = "prod" } }
AnswerD

This is the correct way to configure remote state storage for Google Cloud using Terraform. The `terraform` block wraps the backend declaration, the type is `gcs` for Google Cloud Storage, and the `bucket` and `prefix` arguments accurately define the bucket name and the object key within that bucket. Using a distinct prefix like `"prod"` allows multiple environments or components to share the same bucket while keeping their state files isolated and easily retrievable.

Why this answer

The 'gcs' backend in Terraform stores state in a Cloud Storage bucket. The 'bucket' attribute specifies the bucket name, and 'prefix' is optional for folder structure.

12
MCQeasy

Which gcloud command creates a regional GKE cluster named 'my-cluster' with 3 nodes per zone in the 'us-central1' region?

A.gcloud container clusters create my-cluster --zone us-central1 --num-nodes 3
B.gcloud container clusters create my-cluster --zone us-central1-a --num-nodes 3
C.gcloud container clusters create my-cluster --region us-central1 --nodes 3
D.gcloud container clusters create my-cluster --region us-central1 --num-nodes 3
AnswerD

This is the correct command because it uses --region us-central1 to designate a regional cluster, which GKE deploys across multiple zones within that region for redundancy and high availability. The --num-nodes 3 flag sets the number of nodes per zone in the default node pool, ensuring each zone gets three nodes. Together, these flags meet the requirement for a regional GKE cluster named my-cluster.

Why this answer

The correct command uses --region us-central1 to create a regional cluster and --num-nodes 3 to set three nodes per zone. A regional GKE cluster replicates nodes across all zones in the region, so --num-nodes specifies the count per zone. This matches the requirement of a regional cluster with 3 nodes per zone.

Exam trap

ACE often tests the distinction between --zone (zonal cluster) and --region (regional cluster), plus the exact flag --num-nodes versus the invalid --nodes, catching candidates who mix up cluster scope or flag names.

How to eliminate wrong answers

Option A is wrong because --zone us-central1 creates a zonal cluster in a single zone, not a regional cluster, and us-central1 is a region name, not a valid zone. Option B is wrong because --zone us-central1-a creates a zonal cluster in one zone, which does not provide regional multi-zone redundancy. Option C is wrong because --nodes 3 is not a valid flag — the correct flag is --num-nodes, so the command would error out.

13
MCQeasy

A company wants to create a Cloud Storage bucket to store archival data that is accessed infrequently (less than once a year). The data must be stored at the lowest possible cost. Which storage class should they choose?

A.Archive
B.Coldline
C.Nearline
D.Standard
AnswerA

Archive is the correct choice because it is the lowest-cost Cloud Storage class for data that is accessed less than once a year, offering the cheapest per-gigabyte monthly price for long-term retention. It does incur retrieval fees and a 365-day minimum storage duration, but for true archival data with infrequent access these trade-offs are acceptable. This class also has no availability SLA, which is fine for this access pattern but means it should only be used for durable, rarely accessed data.

Why this answer

Archive storage is designed for data accessed less than once a year and offers the lowest storage cost among the classes listed, at the expense of higher retrieval cost and longer access latency (typically hours). Since the requirement explicitly states infrequent access (less than once a year) and lowest possible cost, Archive is the correct match. Coldline, Nearline, and Standard all cost more per gigabyte because they offer faster retrieval.

Exam trap

The trap is confusing the access-frequency thresholds of the storage classes — candidates often pick Coldline or Nearline because they sound 'cold,' but the question's 'less than once a year' maps specifically to Archive, and only Archive guarantees the lowest cost.

How to eliminate wrong answers

Option B is wrong because Coldline is intended for data accessed less than once a quarter (roughly once every 90 days), so it costs more than Archive and is over-provisioned for data touched less than once a year. Option C is wrong because Nearline targets data accessed less than once a month, making it significantly more expensive than Archive and unnecessary for annual access. Option D is wrong because Standard is for frequently accessed 'hot' data with the highest storage cost and lowest retrieval cost, the opposite of the archival requirement.

14
MCQeasy

Which kubectl command lists all pods in the current namespace?

A.kubectl list pods
B.kubectl describe pods
C.kubectl get pods
D.kubectl get all
AnswerC

'kubectl get pods' is the canonical command to list pods in the current namespace. It queries the Kubernetes API and returns a table with columns such as NAME, READY, STATUS, RESTARTS, and AGE, one row per pod. This is the expected answer because the question asks for a command that lists pods, and 'get' is the standard verb for retrieving resource lists.

Why this answer

The command 'kubectl get pods' lists all pods. 'kubectl get all' includes services, deployments, etc. 'kubectl describe pods' shows detailed info. 'kubectl list pods' is invalid.

15
MCQmedium

A team is using Terraform to deploy infrastructure. They want to ensure that the Terraform state file is encrypted at rest using a customer-managed encryption key (CMEK). What should they configure?

A.Use a Cloud Storage bucket with CMEK enabled by default; no Terraform configuration needed
B.Set the encryption block in the google_storage_bucket resource
C.Set the kms_key argument in the google provider block
D.Set the kms_key argument in the terraform backend block
AnswerA, B

Correct. If the Cloud Storage bucket already has CMEK enabled by default, no further Terraform configuration is required for encryption; the bucket's default key handles encryption at rest.

Why this answer

To use CMEK with the GCS backend, you have two valid approaches: 1) Use an existing Cloud Storage bucket that already has CMEK enabled by default—no Terraform encryption configuration is needed because the bucket itself enforces encryption. 2) When creating a new bucket via the `google_storage_bucket` resource, set the `encryption` block with a `default_kms_key_name` to specify a CMEK key. The provider block does not have a `kms_key` argument, and the `terraform` backend block does not support a `kms_key` argument for GCS. Both options A and B are correct.

16
MCQeasy

An engineer needs to SSH into a Compute Engine instance using OS Login. What must be enabled first?

A.Create an SSH key and upload to the instance
B.Grant the compute.osLogin role to the user
C.Add SSH keys to the project metadata
D.Enable OS Login in the project metadata
AnswerD

Enabling OS Login by setting the project metadata key enable-oslogin to TRUE is the foundational step. This tells Compute Engine to use IAM-based authentication for SSH, allowing the engineer to log in with Google credentials rather than managing SSH keys. Once enabled at the project level, instances inherit the setting, and a user with the compute.osLogin role can SSH without manual key distribution. This is the required first action to meet the engineer's need.

Why this answer

OS Login must first be enabled at the project (or instance) level by setting the `enable-oslogin` metadata key to TRUE. Only after OS Login is enabled can IAM roles like `roles/compute.osLogin` be granted and take effect. Enabling OS Login is the prerequisite configuration step that changes how SSH authentication is managed on the instance.

Exam trap

The trap is picking the IAM role grant as the first step — candidates assume permissions come first, but OS Login must be enabled in metadata before any role assignment has effect.

How to eliminate wrong answers

Option A is wrong because manually creating and uploading SSH keys is the legacy metadata-based SSH method — OS Login replaces this by managing keys through IAM, so uploading keys is unnecessary and does not enable OS Login. Option B is wrong because granting the `compute.osLogin` role is necessary but not sufficient — it only works after OS Login is enabled in project metadata; the role alone does nothing if OS Login is off. Option C is wrong because adding SSH keys to project metadata is the old approach that OS Login is designed to supersede; it does not enable OS Login.

17
MCQhard

An engineer is using Terraform to manage GCP resources. They want to store the Terraform state file remotely so that the team can collaborate. Which backend configuration should they use?

A.backend "cloud" { bucket = "my-terraform-state" }
B.backend "local" { path = "terraform.tfstate" }
C.backend "consul" { address = "consul.example.com" }
D.backend "gcs" { bucket = "my-terraform-state" }
AnswerD

Configuring the gcs backend with a bucket name is the correct way to store Terraform state for GCP resources. The gcs backend uses a Cloud Storage bucket, which natively supports state file versioning, server-side encryption (including customer-managed keys via Cloud KMS), and access control through GCP IAM, providing both security and consistency for team use. It also enables state locking via bucket objects to prevent concurrent modifications. This is the recommended solution for centralized, durable remote state in GCP.

Why this answer

Terraform supports storing state in GCS by using the 'gcs' backend. The bucket must be created before configuration. The 'local' backend stores state locally, which does not enable collaboration. 'cloud' is not a valid backend type. 'consul' is not GCP-native.

18
MCQmedium

A company wants to run a stateful application on Compute Engine with persistent storage that can be attached to another instance in case of failure. Which storage option should they use?

A.Filestore
B.Cloud Storage bucket
C.Persistent Disk
D.Local SSD
AnswerC

Persistent Disk is durable, network-attached block storage that you can attach to a Compute Engine instance like a physical disk. It survives instance stops and can be detached from one instance and reattached to another, enabling stateful failover. Persistent Disk also supports snapshots, resizing, and zonal or regional replication, making it the appropriate choice for a stateful application. For these reasons, Persistent Disk is the correct answer.

Why this answer

Persistent Disk is the correct choice because it provides durable, block storage that can be attached to Compute Engine instances and detached and reattached to another instance in case of failure. This makes it suitable for stateful applications requiring persistent storage that can survive instance failures.

Exam trap

The trap is confusing block storage with file or object storage: candidates might pick Filestore or Cloud Storage because they are persistent, but only Persistent Disk provides attachable block storage that can be moved between instances.

How to eliminate wrong answers

Option A is wrong because Filestore is a managed file storage service (NFS) for sharing files across many instances, but it is not block storage and cannot be attached as a single disk to an instance for stateful apps in the same way. Option B is wrong because Cloud Storage is object storage, not block storage, and cannot be mounted as a disk for a stateful application (except via FUSE, which is not ideal for databases). Option D is wrong because Local SSD is ephemeral storage physically attached to the host; data is lost if the instance stops or is terminated, and it cannot be detached and reattached to another instance.

19
MCQmedium

You deployed a Cloud Run service with gcloud run deploy --image gcr.io/my-project/my-image --platform managed --region us-central1 --allow-unauthenticated. Users report intermittent 503 errors. What is the most likely cause?

A.The service is hitting the maximum number of concurrent requests per container instance (default 80) and needs more instances.
B.The region us-central1 does not support Cloud Run.
C.The container image is not compatible with the managed platform.
D.The --allow-unauthenticated flag causes IAM permission errors.
AnswerA

A 503 from Cloud Run specifically signals that a request arrived but no container instance was available to accept it within the timeout window. Each instance can process only a fixed number of concurrent requests—the default concurrency is 80—so when all existing instances are saturated and the autoscaler cannot add new instances quickly enough (or the 'max instances' setting has been reached), the server returns Service Unavailable. The fix is to raise the max instances limit, lower the concurrency setting, or enable additional CPU to reduce per-instance bottleneck.

Why this answer

Cloud Run scales based on concurrent requests per container instance, with a default concurrency limit of 80. When a container instance reaches this limit, additional requests are queued or rejected; if the service cannot scale out fast enough (e.g., due to cold starts or instance limits), users experience intermittent 503 errors. The most likely cause is that the service is hitting this concurrency limit and needs more instances or a higher concurrency setting.

Exam trap

ACE often tests the misconception that 503 errors always indicate a platform or permission issue, when in fact they frequently stem from concurrency limits and scaling delays in serverless services like Cloud Run.

How to eliminate wrong answers

Option B is wrong because us-central1 is a fully supported Cloud Run region with multiple zones. Option C is wrong because Cloud Run supports standard OCI containers; if the image were incompatible, deployment would fail or the service would not start, not produce intermittent 503s. Option D is wrong because --allow-unauthenticated grants public access; it does not cause IAM permission errors—if IAM were misconfigured, users would see 403 errors, not 503s.

20
Multi-Selecteasy

A developer wants to deploy a Cloud Function that is triggered by messages in a Pub/Sub topic. Which TWO flags are required in the gcloud functions deploy command?

Select 2 answers
A.--runtime
B.--trigger-topic
C.--timeout
D.--memory
E.--entry-point
AnswersA, B

The `--runtime` flag is mandatory because it tells the Cloud Functions deployment service which language runtime to use, such as `python312` or `nodejs20`. This value must match the code you are uploading, including the expected base image and dependencies, so the platform can build the function in the correct environment. Without specifying it, the gcloud command will fail, as there is no sensible default language choice.

Why this answer

Option A (--runtime) is correct because gcloud functions deploy requires you to specify the language runtime (for example, --runtime=nodejs20 or --runtime=python311) so the platform knows which execution environment to build and run the function in. Option B (--trigger-topic) is correct because it is the flag that configures the function's event trigger as a Pub/Sub topic, binding the function to messages published to that topic. Option C (--timeout) is not required; it only overrides the default function execution timeout.

Option D (--memory) is not required; it only adjusts the allocated memory for the function. Option E (--entry-point) is not required for a single-function deployment, since the entry point is only needed when the source contains multiple functions and you must disambiguate which one to deploy.

Exam trap

ACE often tests the distinction between required and optional deploy flags — candidates confuse tuning flags like --memory and --timeout with mandatory trigger/runtime flags, or assume --entry-point is always required.

21
MCQmedium

A developer wants to create a Compute Engine instance with the container-optimized OS image in the default network. Which command should they use?

A.gcloud compute instances create my-instance --image-family=ubuntu-2004-lts --image-project=ubuntu-os-cloud
B.gcloud compute instances create my-instance --image-family=cos-stable --image-project=cos-cloud
C.gcloud compute instances create my-instance --image-family=cos-stable
D.gcloud compute instances create my-instance --image=cos-stable --image-project=cos-cloud
AnswerB

This is the correct command because it explicitly selects the 'cos-stable' image family from the 'cos-cloud' project, which yields the latest stable release of Container-Optimized OS. COS is a Google-supported OS with Docker, containerd, and Kubernetes tools preinstalled, optimized for running containerized workloads. Including both --image-family and --image-project ensures that gcloud resolves the family from the proper project, avoiding ambiguity with the default compute project.

Why this answer

The command 'gcloud compute instances create my-instance --image-family=cos-stable --image-project=cos-cloud' correctly specifies both the image family (cos-stable) and the image project (cos-cloud) where Container-Optimized OS images reside. Both flags are required because image families are scoped to a project. This creates an instance with the COS image in the default network (default network is used when --network is omitted).

Exam trap

The trap is omitting --image-project or confusing --image with --image-family; ACE tests exact gcloud flag semantics, and candidates often assume the image family alone is sufficient.

How to eliminate wrong answers

Option A is wrong because it specifies ubuntu-2004-lts and ubuntu-os-cloud, which creates an Ubuntu instance, not a Container-Optimized OS instance. Option C is wrong because it omits --image-project; gcloud requires the image project to resolve the image family, and without it the command fails or uses the wrong project. Option D is wrong because it uses --image=cos-stable instead of --image-family=cos-stable; --image expects a specific image name (e.g., cos-stable-109-17800-147-31), not a family, so the command would fail to find the image.

22
MCQmedium

A company runs a stateless batch processing application on a managed instance group (MIG) of Compute Engine instances. The application reads tasks from a Cloud Pub/Sub subscription and writes results to Cloud Storage. The operations team wants to ensure that when an instance is terminated during scaling down or maintenance, the application finishes its current task before the instance shuts down. The application currently does not handle SIGTERM. What should the operations team do to meet this requirement with minimal changes?

A.Enable autoscaling based on Pub/Sub queue depth and set the minimum number of instances to the maximum expected workload.
B.Configure the MIG to use a graceful shutdown period and modify the application to handle the SIGTERM signal to complete in-flight work.
C.Use a rolling update strategy with a long health check grace period and rely on the load balancer to drain connections.
D.Create a shutdown script that immediately stops the application and deletes any unacknowledged Pub/Sub messages.
AnswerB

Compute Engine sends a SIGTERM signal before stopping an instance, and the shutdown period can be extended beyond the default 90 seconds by setting a graceful shutdown duration on the instance template or MIG. By handling SIGTERM, the application can finish processing the current Pub/Sub message and acknowledge it, ensuring no task is lost during scale-in or maintenance events. This directly addresses the requirement with minimal architectural change.

Why this answer

To gracefully finish work during instance termination, the application must handle the SIGTERM signal, and the MIG must allow enough time for that work to complete. Compute Engine provides a configurable shutdown period that extends the default 90-second window. Without SIGTERM handling, the application is killed abruptly; without an extended period, even a well-behaved application may be terminated before finishing.

Combining both ensures reliable task completion.

Exam trap

The trap here is assuming that autoscaling or load balancing alone can prevent task interruption, when actually the instance shutdown sequence requires application-level signal handling and a configured graceful shutdown period.

23
MCQmedium

An organization wants to deploy a containerized web application on Google Cloud with minimum operational overhead. The application should scale to zero when not in use and only incur costs when serving requests. Which service should they choose?

A.App Engine Flexible Environment
B.Google Kubernetes Engine (GKE)
C.Compute Engine with container-optimized OS
D.Cloud Run
AnswerD

Cloud Run is a fully managed serverless platform that executes containers in a stateless, request-driven model: when there are no incoming requests, it can scale the service down to zero instances, so you are not charged for idle resources. It automatically scales up to handle traffic spikes, and billing is based on request duration and CPU/memory usage during active processing, measured in 100ms increments. This makes it the most operationally efficient choice for a containerized web application that expects variable traffic.

Why this answer

Cloud Run is a fully managed serverless container platform that scales to zero when there is no traffic and charges only for resources consumed during request handling. It abstracts away cluster management, making it the lowest-operational-overhead choice for a containerized web app that must scale to zero.

Exam trap

ACE often tests serverless vs. managed vs. IaaS trade-offs — candidates pick GKE or App Engine Flexible thinking 'containerized' implies Kubernetes, but the scale-to-zero and minimum-overhead requirements point to Cloud Run.

How to eliminate wrong answers

Option A (App Engine Flexible) is wrong because it runs at least one instance at all times and does not scale to zero, so it incurs idle costs. Option B (GKE) is wrong because it requires cluster management (nodes, upgrades, networking) and does not scale to zero unless combined with additional autoscaling tooling, adding operational overhead. Option C (Compute Engine with container-optimized OS) is wrong because it uses VMs that must be managed and do not scale to zero automatically; it is IaaS, not serverless.

24
Multi-Selectmedium

You need to deploy an application that requires a regional MySQL database with automated backups, high availability, and failover. You also need to store static assets that are publicly accessible. Which TWO Google Cloud services should you use?

Select 2 answers
A.Cloud SQL (MySQL)
B.Cloud Storage
C.Bigtable
D.Cloud Filestore
E.Cloud Spanner
AnswersA, B

Cloud SQL for MySQL is a fully managed relational database service that provides the exact MySQL engine required by the application. It supports regional high availability through synchronous replication across two zones, automated backups, and point-in-time recovery, meeting both performance and durability needs without operational overhead. Its compatibility with standard MySQL drivers and protocols makes it the ideal choice for a regional MySQL workload.

Why this answer

Cloud SQL with MySQL provides managed MySQL with high availability (regional) and automated backups. Cloud Storage can host static assets publicly.

25
MCQeasy

You want to deploy a Cloud Function triggered by HTTP requests. The function is written in Node.js and the entry point function is named 'helloHttp'. Which command should you use?

A.gcloud functions deploy my-function --runtime nodejs16 --trigger-http --entry-point=helloHttp --region=us-central1
B.gcloud functions deploy --source . --runtime nodejs16 --trigger-http --entry-point=helloHttp
C.gcloud run deploy my-function --source . --runtime nodejs16 --entry-point=helloHttp
D.gcloud functions deploy my-function --runtime nodejs16 --trigger-topic my-topic --entry-point=helloHttp
AnswerA

This command is correct because it explicitly provides the required function name (`my-function`), specifies the Node.js 16 runtime, sets `--trigger-http` to create an HTTP-triggered Cloud Function, names the entry point (`helloHttp`) that matches the exported function in your source code, and pins the region (`us-central1`) to avoid ambiguity. In Cloud Functions, `--trigger-http` creates a public HTTPS endpoint and deploys the function to the specified location, making this the complete and valid invocation.

Why this answer

The correct command uses `gcloud functions deploy` with the required positional NAME argument (`my-function`), specifies `--runtime nodejs16`, uses `--trigger-http` for an HTTP-triggered function, and sets `--entry-point=helloHttp` to match the exported Node.js function name. The `--region` flag is also valid and commonly required for deterministic deployment. This combination satisfies all requirements stated in the question.

Exam trap

ACE often tests whether candidates confuse Cloud Functions and Cloud Run commands, or forget that `gcloud functions deploy` requires a NAME positional argument before any flags.

How to eliminate wrong answers

Option B is wrong because it omits the required function NAME positional argument, which `gcloud functions deploy` requires (the command syntax is `gcloud functions deploy NAME --runtime=...`); without a name the command fails. Option C is wrong because `gcloud run deploy` deploys to Cloud Run, not Cloud Functions, and Cloud Run does not accept `--runtime` or `--entry-point` flags in that form. Option D is wrong because `--trigger-topic my-topic` configures a Pub/Sub trigger, not an HTTP trigger, contradicting the requirement for HTTP invocation.

26
MCQhard

A DevOps engineer is configuring a managed instance group (MIG) for a stateless web application. They want to ensure that when new instances are created via rolling update or autoscaling, a startup script runs to install security patches and deploy the latest application code from a Cloud Storage bucket. What is the BEST way to achieve this?

A.Create a custom image with pre-installed patches and code, and use that image in the template
B.After the MIG is created, use gcloud compute ssh to run the script on each instance
C.Store the script in Cloud Storage and use gcloud compute instances add-metadata on each instance
D.Add the script to the instance template using the metadata key 'startup-script'
AnswerD

Adding the script to the instance template using the metadata key 'startup-script' is the recommended, automated approach because Compute Engine stores the metadata in the instance template and executes the script on every VM boot. The MIG automatically applies this metadata to all instances it creates, including during autoscaling, rolling updates, and instance recreation after a failure. This guarantees the configuration is consistently applied without manual intervention, and the script can be updated by editing the template and rolling out a new version of the MIG.

Why this answer

The best way to ensure a startup script runs on every new instance in a MIG is to embed it in the instance template using the metadata key 'startup-script'. The template is the blueprint for all instances created by the MIG, so any instance launched by autoscaling or rolling update automatically executes the script on boot.

Exam trap

The trap is choosing per-instance manual steps or custom images — candidates must recognize that MIG automation requires the startup script to be in the instance template, not applied after the fact.

How to eliminate wrong answers

Option A is wrong because a custom image with pre-installed patches and code becomes stale — it does not fetch the latest code from Cloud Storage at boot, so new instances would run outdated code. Option B is wrong because manually SSHing into each instance is not scalable, not automated, and does not apply to instances created later by autoscaling. Option C is wrong because adding metadata to existing instances does not affect future instances created by the MIG; the metadata must be in the instance template to propagate.

27
MCQeasy

A developer needs to deploy a new version of a Cloud Run service that uses a custom container image stored in Artifact Registry. The service must be accessible only from within the same Google Cloud project and must not be reachable from the public internet. The developer wants to use the gcloud CLI to deploy. Which command should the developer use?

A.gcloud run deploy SERVICE --image=LOCATION-docker.pkg.dev/PROJECT/REPO/IMAGE:TAG --ingress=internal --allow-unauthenticated
B.gcloud run deploy SERVICE --image=LOCATION-docker.pkg.dev/PROJECT/REPO/IMAGE:TAG --ingress=all --allow-unauthenticated
C.gcloud run deploy SERVICE --image=LOCATION-docker.pkg.dev/PROJECT/REPO/IMAGE:TAG --ingress=internal --no-allow-unauthenticated
D.gcloud run deploy SERVICE --image=LOCATION-docker.pkg.dev/PROJECT/REPO/IMAGE:TAG --ingress=internal-and-cloud-load-balancing --allow-unauthenticated
AnswerC

The --ingress=internal flag restricts traffic to sources within the same project or VPC network, preventing public internet access. The --no-allow-unauthenticated flag requires authentication for all requests, ensuring the service is not publicly accessible. Deploying with the Artifact Registry image path is correct. This combination meets the requirement of internal-only access with authentication.

Why this answer

To make a Cloud Run service internal-only and require authentication, combine --ingress=internal with --no-allow-unauthenticated. The internal ingress setting ensures that only traffic from within the project or VPC network can reach the service, while disabling unauthenticated access enforces identity-based access control. This is the standard pattern for private microservices that should not be exposed to the public internet.

Exam trap

The trap here is confusing ingress control with authentication: setting --ingress=internal blocks public internet traffic but does not by itself require authentication, so --allow-unauthenticated must be replaced with --no-allow-unauthenticated to fully secure the service.

28
MCQmedium

You need to deploy a Cloud Function that is triggered by HTTP requests. You want to pass configuration parameters to the function at deployment time. Which approach should you use?

A.Store parameters in a Cloud Storage bucket and read them at runtime.
B.Edit the function code to hardcode the parameters.
C.Use the --set-env-vars flag with gcloud functions deploy.
D.Include the parameters in the HTTP request body.
AnswerC

The --set-env-vars flag injects key-value pairs as environment variables during gcloud functions deploy, making them readable by the function's runtime code. This passes configuration at deployment time without hardcoding values, satisfying the stem's requirement for supplying parameters when the HTTP-triggered function is created.

Why this answer

You can set environment variables at deployment time using the --set-env-vars flag with the gcloud functions deploy command. This allows passing configuration parameters without modifying the code. Option C is correct.

29
MCQmedium

A company wants to deploy a microservice on GKE. The deployment requires 3 replicas, and the service must be accessible via a fixed public IP address. Which Kubernetes resource should be used to expose the deployment?

A.Service of type LoadBalancer
B.Ingress resource
C.Service of type ClusterIP
D.Service of type NodePort
AnswerA

A Service of type LoadBalancer in GKE creates an external passthrough Network Load Balancer in Google Cloud, provisioning an external forwarding rule with a stable public IP address from a regional pool. This IP remains fixed for the lifetime of the Service unless the Service is deleted or a reserved static IP is explicitly configured, making it the correct choice for a microservice that needs a durable public endpoint without additional configuration.

Why this answer

A Kubernetes Service of type LoadBalancer provisions a cloud provider load balancer with an external IP that routes to the pods backing the deployment. On GKE, this creates a Google Cloud external passthrough Network Load Balancer with a stable public IP, which matches the fixed public IP requirement.

Exam trap

ACE often tests the confusion between Ingress (L7, HTTP routing, shared IP) and LoadBalancer Service (L4, dedicated external IP), causing candidates to pick Ingress when a fixed public IP for a raw service is required.

How to eliminate wrong answers

Option B is wrong because an Ingress resource requires an Ingress controller and typically provides HTTP(S) routing with a shared IP; it does not by itself guarantee a fixed public IP for a raw TCP service and adds unnecessary complexity. Option C is wrong because ClusterIP is only reachable inside the cluster and has no external IP. Option D is wrong because NodePort exposes a port on every node's IP, which is not a fixed public IP and is unsuitable for production external access.

30
MCQmedium

A company wants to store archival data that is accessed less than once a year. The data must be preserved for 10 years. Which Cloud Storage storage class is most cost-effective?

A.Archive
B.Standard
C.Nearline
D.Coldline
AnswerA

Archive is the lowest-cost Cloud Storage class, designed for data accessed less than once a year, and it supports the 10-year retention requirement. Nearline and Coldline assume more frequent access, so they cost more for this pattern.

Why this answer

Google Cloud Storage Archive storage class is the most cost-effective for data accessed less than once a year and retained for 10 years. Archive has the lowest storage cost but higher retrieval costs and a minimum storage duration of 365 days. It is designed for long-term archival of data that is rarely accessed, making it ideal for this use case.

Exam trap

ACE often tests the difference between Coldline and Archive. Candidates may choose Coldline because it is also for infrequent access, but Archive is more cost-effective for data accessed less than once a year.

How to eliminate wrong answers

Option B is wrong because Standard storage is designed for frequently accessed data and has the highest storage cost. Option C is wrong because Nearline is for data accessed less than once a month, not less than once a year; it has higher storage cost than Archive. Option D is wrong because Coldline is for data accessed less than once a year, but Archive is even more cost-effective for data accessed less than once a year, with lower storage cost (though higher retrieval costs).

31
Multi-Selecteasy

A developer is deploying a new application on GKE and needs to configure a HorizontalPodAutoscaler (HPA). Which two resources are required for HPA to work correctly?

Select 2 answers
A.CPU utilization metrics
B.A Service
C.A ConfigMap
D.A Deployment
E.A NodePort service
AnswersA, D

CPU utilization metrics drive the Horizontal Pod Autoscaler's scaling decisions. By default, HPA reads the average CPU utilization across all pods in a target Deployment, comparing it against the target percentage you set relative to each pod's CPU request. This is the most common and default metric type, requiring pods to have explicit `resources.requests.cpu` values. Custom and external metrics can be used, but CPU utilization is the built-in, standard input for autoscaling.

Why this answer

HPA requires a deployment (or other scalable resource) and a target metric, usually CPU utilization. The HPA will scale the deployment based on the metric. A ConfigMap and a service are not strictly required for HPA.

32
Multi-Selectmedium

A team is deploying a web application on Cloud Run. The application needs to be available globally with low latency, and the team wants to use a custom domain with an SSL certificate. Which TWO actions are required to achieve this?

Select 2 answers
A.Set the --ingress=all flag on the Cloud Run service
B.Use Cloud CDN to cache content
C.Configure a custom domain mapping on the Cloud Run service
D.Deploy the Cloud Run service in multiple regions and use a multi-regional load balancer
E.Deploy the service as a Cloud Run for Anthos on GKE
AnswersC, D

Custom domain mapping on Cloud Run registers the domain and provisions a Google-managed TLS certificate so the domain points to the service's default URL. This is a mandatory step to expose the application at the customer's chosen domain. While it handles the domain mapping, it does not by itself provide multi-region low latency; that requires a global load balancer with multiple regional backends.

Why this answer

Cloud Run services are regional; to serve globally, you need a global load balancer (e.g., using an external HTTPS load balancer with serverless NEG). Mapping a custom domain to the service is also required.

33
MCQeasy

A developer needs to SSH into a Compute Engine instance that has OS Login enabled. The developer's Google account is already granted the roles/compute.osLogin role. Which command should the developer use to connect?

A.ssh -i ~/.ssh/google_key user@instance-ip
B.gcloud compute ssh instance-name --zone=us-central1-a
C.gcloud compute instances get-serial-port-output instance-name --zone=us-central1-a
D.gcloud compute connect-to-serial-port instance-name --zone=us-central1-a
AnswerB

With OS Login enabled and roles/compute.osLogin granted, gcloud compute ssh authenticates using the Google account and manages SSH keys through OS Login, so no manual key setup is needed. This satisfies the scenario by connecting the developer to the instance in the specified zone.

Why this answer

With OS Login enabled and the roles/compute.osLogin role granted, the developer should connect using gcloud compute ssh, which automatically handles OS Login authentication and key management. The gcloud compute ssh command integrates with OS Login to generate short-lived SSH certificates and manage the developer's Google identity, so no manual key file is needed. Specifying the zone ensures the command targets the correct instance.

Exam trap

ACE often tests the misconception that OS Login still requires a manual SSH key file — candidates pick the ssh -i option because it looks like the 'standard' SSH command, but OS Login specifically replaces that workflow with identity-based gcloud authentication.

How to eliminate wrong answers

Option A is wrong because manually specifying a private key file bypasses OS Login's identity-based authentication and is not how OS Login connections are made. Option C is wrong because get-serial-port-output retrieves console output for troubleshooting, not an interactive SSH session. Option D is wrong because connect-to-serial-port provides serial console access for recovery, not a standard SSH login, and it does not use OS Login.

34
MCQmedium

A team is using Terraform to manage Google Cloud resources. They want to store the Terraform state file in a Cloud Storage bucket with versioning enabled. Which backend configuration should they use?

A.terraform { backend "cloud" { bucket = "my-terraform-state-bucket" prefix = "terraform/state" } }
B.terraform { backend "gcs" { bucket = "my-terraform-state-bucket" prefix = "terraform/state" } }
C.terraform { backend "gcs" { bucket = "gs://my-terraform-state-bucket" prefix = "terraform/state" } }
D.terraform { backend "remote" { hostname = "app.terraform.io" organization = "my-org" workspaces { name = "my-workspace" } } }
AnswerB

The gcs backend block points Terraform at the Cloud Storage bucket holding remote state, and the prefix namespaces the state object within that bucket. Versioning is configured on the bucket itself, so the backend only needs bucket and prefix.

Why this answer

The correct backend block for Google Cloud Storage in Terraform is backend "gcs", and the bucket argument must be the bare bucket name (e.g., "my-terraform-state-bucket") without the gs:// scheme prefix. Terraform's GCS backend automatically uses the Google Cloud Storage API and supports object versioning natively when enabled on the bucket. This configuration stores the state file at gs://my-terraform-state-bucket/terraform/state/default.tfstate.

Exam trap

The trap here is the gs:// prefix — candidates familiar with gsutil commands assume the bucket argument needs the URI scheme, but Terraform's GCS backend requires only the bare bucket name.

How to eliminate wrong answers

Option A is wrong because there is no backend type called "cloud" in Terraform — the valid GCS backend is named "gcs", so this block would fail with an unsupported backend error. Option C is wrong because although it uses the correct "gcs" backend name, the bucket argument includes the gs:// URI scheme; the GCS backend expects only the bucket name, and including the scheme causes a configuration error. Option D is wrong because the "remote" backend configures Terraform Cloud/Enterprise (app.terraform.io) as the state store, not a self-managed GCS bucket, so it does not meet the requirement of storing state in Cloud Storage with versioning.

35
MCQmedium

A company wants to deploy a containerized application on Google Cloud that automatically scales to zero when not in use, and they want to minimize operational overhead. They also need to avoid managing any underlying infrastructure such as Kubernetes clusters or VMs. Which service should they use?

A.Google Kubernetes Engine (GKE)
B.App Engine Standard Environment
C.Cloud Run
D.Compute Engine with managed instance groups
AnswerC

Cloud Run is a fully managed serverless container platform that automatically scales in response to incoming requests, including scaling to zero when idle, so you only pay for the exact compute time consumed. It doesn't require any cluster or infrastructure management, and it can be used with Knative Serving APIs, making it the most direct fit for a stateless containerized application that needs to scale to zero.

Why this answer

Cloud Run is a fully managed serverless platform that runs containerized applications and automatically scales to zero when there is no traffic, eliminating costs during idle periods. It abstracts away all infrastructure management, including Kubernetes clusters and VMs, so the company can focus solely on their container image. This directly satisfies the requirements of containerized deployment, scale-to-zero, and minimal operational overhead.

Exam trap

ACE often tests the distinction between serverless container platforms and orchestration services, trapping candidates who assume Kubernetes is required for containers or that App Engine supports arbitrary containers with scale-to-zero.

How to eliminate wrong answers

Option A is wrong because GKE requires managing a Kubernetes cluster (nodes, upgrades, networking), which adds operational overhead and does not scale to zero by default (nodes remain running). Option B is wrong because App Engine Standard runs applications in a language-specific sandbox and does not support arbitrary containerized workloads (though App Engine Flexible supports containers, it does not scale to zero and still requires some infrastructure management). Option D is wrong because Compute Engine with managed instance groups requires managing VMs and does not scale to zero (minimum instance count is typically 1), leading to higher operational overhead.

36
MCQeasy

Which gcloud command is used to deploy a Cloud Function triggered by HTTP requests?

A.gcloud functions call my-function --data '{"key":"value"}'
B.gcloud run deploy my-function --source . --platform managed
C.gcloud functions deploy my-function --runtime python39 --trigger-http
D.gcloud functions deploy my-function --runtime python39 --trigger-topic my-topic
AnswerC

This command correctly deploys an HTTP-triggered Cloud Function: `gcloud functions deploy` creates or updates a function resource, `--runtime python39` selects the Python 3.9 execution environment, and `--trigger-http` configures an HTTPS endpoint that invokes the function on web requests. No other trigger type is needed. The command will return a URL for the deployed function.

Why this answer

The command 'gcloud functions deploy' with --trigger-http creates an HTTP-triggered function. --runtime specifies the language runtime. --trigger-topic is for Pub/Sub triggers.

37
MCQmedium

An engineer needs to create a Cloud SQL MySQL instance with 4 vCPUs, 15 GB of RAM, and a root password. The instance should be in the us-east1 region. Which command should the engineer run?

A.gcloud sql instances create my-instance --database-version=MYSQL_8_0 --tier=db-custom-4-15360 --region=us-east1
B.gcloud sql instances create my-instance --database-version=MYSQL_5_7 --tier=db-n1-standard-4 --region=us-east1-a --root-password=myPassword
C.gcloud sql instances create my-instance --database-version=MYSQL_8_0 --tier=db-custom-2-7680 --region=us-east1 --root-password=myPassword
D.gcloud sql instances create my-instance --database-version=MYSQL_8_0 --tier=db-custom-4-15360 --region=us-east1 --root-password=myPassword
AnswerD

The `--tier=db-custom-4-15360` flag defines a custom machine type with exactly 4 vCPUs and 15360 MB (15 GB) of RAM, satisfying the stem's sizing constraint. Combined with `--database-version=MYSQL_8_0`, `--region=us-east1` and `--root-password`, it fulfils every stated requirement in one command.

Why this answer

The correct command must specify a custom machine type matching 4 vCPUs and 15 GB RAM, which is `db-custom-4-15360` (the format is db-custom-<vCPUs>-<memoryMB>). It must also include the root password and target the us-east1 region (not a zone). Option D is the only command that includes all required parameters: MYSQL_8_0, the correct custom tier, the region, and the root password.

Exam trap

ACE often tests whether candidates can decode the `db-custom-<vCPU>-<memoryMB>` format and distinguish `--region` from `--zone` — picking a zone value for `--region` is a classic distractor.

How to eliminate wrong answers

Option A is wrong because it omits the required `--root-password` flag, so the instance would be created without the specified root password. Option B is wrong because `db-n1-standard-4` is a predefined tier (4 vCPU, 15 GB) but the region is specified as `us-east1-a`, which is a zone, not a region — Cloud SQL instances are regional resources and `--region` expects a region name. Option C is wrong because `db-custom-2-7680` corresponds to 2 vCPUs and 7.5 GB RAM, not the required 4 vCPUs and 15 GB.

38
MCQeasy

A developer needs to create a Compute Engine VM with 4 vCPUs, 15 GB of memory, and a Debian 10 boot disk. Which gcloud compute instances create command is correct?

A.gcloud compute instances create my-vm --machine-type=n1-highmem-4 --image-family=debian-10 --image-project=debian-cloud
B.gcloud compute instances create my-vm --machine-type=n1-standard-4 --image-family=debian-10 --image-project=debian-cloud
C.gcloud compute instances create my-vm --machine-type=n1-standard-4 --image-family=ubuntu-1804 --image-project=ubuntu-os-cloud
D.gcloud compute instances create my-vm --machine-type=n1-standard-4
AnswerB

This is the correct command because n1-standard-4 is the general-purpose machine type that provides exactly 4 vCPUs and 15 GB of memory, satisfying the stated requirement. It also explicitly sets --image-family=debian-10 and --image-project=debian-cloud, which tells gcloud to use the latest active Debian 10 image from the official debian-cloud project. The command is complete and creates a reproducible Debian 10 VM with the desired vCPU count.

Why this answer

The `n1-standard-4` machine type provides exactly 4 vCPUs and 15 GB of memory, matching the requirement. Combined with `--image-family=debian-10` and `--image-project=debian-cloud`, this command creates a Debian 10 VM with the correct specs. The `n1-standard` family is the general-purpose line with a 1:3.75 vCPU-to-memory ratio.

Exam trap

ACE often tests whether candidates know the exact vCPU-to-memory ratios of GCE machine type families, especially confusing `n1-standard-4` (15 GB) with `n1-highmem-4` (26 GB).

How to eliminate wrong answers

Option A is wrong because `n1-highmem-4` provides 4 vCPUs but 26 GB of memory, not 15 GB — it belongs to the high-memory family with a 1:6.5 ratio. Option C is wrong because it specifies `ubuntu-1804` and `ubuntu-os-cloud`, which creates an Ubuntu 18.04 VM, not Debian 10 as required. Option D is wrong because it omits both the image family and image project flags, so the VM would use the default image (often Debian, but not guaranteed to be Debian 10) and lacks the explicit boot disk specification.

39
MCQhard

A team is using Terraform to manage infrastructure. They want to store the Terraform state file remotely in a GCS bucket for team collaboration. Which Terraform backend configuration is correct?

A.terraform { backend "gcs" { bucket = "my-terraform-state" } }
B.terraform { backend "gcs" { bucket = "my-terraform-state" prefix = "terraform/state" } }
C.terraform { backend "storage" { bucket = "my-terraform-state" } }
D.terraform { backend "gcloud" { bucket = "my-terraform-state" } }
AnswerA, B

Correct. The 'gcs' backend requires a 'bucket' argument. This configuration will store the state file in the root of the bucket.

Why this answer

Both options A and B are valid Terraform backend configurations for GCS. Option A uses the minimal required argument 'bucket'. Option B adds the optional 'prefix' argument to organize state files within the bucket.

The 'gcs' backend supports both. Options C and D are invalid because 'storage' and 'gcloud' are not valid backend types.

40
MCQeasy

Which kubectl command is used to view the logs of a specific pod named 'my-pod'?

A.kubectl logs my-pod
B.kubectl exec my-pod -- logs
C.kubectl get pod my-pod
D.kubectl describe pod my-pod
AnswerA

The `kubectl logs my-pod` command retrieves the logs of the primary container running inside the specified pod by reading the container's stdout/stderr streams. This is the direct, native Kubernetes approach for accessing application log output, and if the pod has multiple containers, you must append `-c <container>` to select a specific one. It does not require shell access or any extra tooling, making it the correct command for viewing logs.

Why this answer

The 'kubectl logs' command streams logs from a pod. 'kubectl describe' shows metadata, 'kubectl get' shows status, and 'kubectl exec' runs commands inside the pod.

41
Multi-Selectmedium

A company wants to set up a Cloud SQL for MySQL instance with automated backups and a read replica for disaster recovery. Which THREE features or configurations should be enabled?

Select 3 answers
A.Enable automated backups
B.Enable binary logging
C.Enable deletion protection on the primary instance
D.Configure the read replica in a different region
E.Assign a public IP address to the read replica
AnswersA, B, D

Automated backups in Cloud SQL are mandatory for point-in-time recovery (PITR) and for creating read replicas. Without them, you cannot perform a restore to a specific timestamp, and you lose the baseline backup needed for replica creation. They also provide a daily recovery point that protects against data loss or corruption.

Why this answer

Automated backups are enabled by default but must be configured. A read replica requires the binary log to be enabled on the primary. The backup location can be set to multi-regional for DR.

Cross-region replication requires a replica in another region. Point-in-time recovery uses binary logs.

42
MCQhard

A team is using Terraform to manage GCP infrastructure. They want to store the state file in a Cloud Storage bucket with versioning enabled. Which backend configuration is correct?

A.provider "google" { backend "gcs" { bucket = "my-bucket" } }
B.terraform { backend "gcs" { bucket = "my-bucket" prefix = "terraform/state" } }
C.terraform { backend "gcs" { bucket = "my-bucket" versioning = true } }
D.terraform { backend "cloud-storage" { bucket = "my-bucket" } }
AnswerB

This is the correct configuration because it uses the required `terraform` block with a `backend "gcs"` block, and includes both the `bucket` name (where the state file is stored) and a `prefix` (the object path within the bucket). The backend type is exactly `"gcs"`, and this syntax registers Google Cloud Storage as the remote state backend, enabling shared state and locking across the team.

Why this answer

To use Cloud Storage as a backend, you must specify 'bucket' and optionally 'prefix' for the state file path. The provider block is for the Google provider, not state storage.

43
MCQmedium

An organization wants to deploy a containerized web application on GKE. They need the application to be accessible from the internet via a stable IP address. Which service type should they use when exposing the deployment?

A.ClusterIP
B.LoadBalancer
C.NodePort
D.ExternalName
AnswerB

A LoadBalancer Service is the appropriate choice for a containerized web application that needs a stable external IP. When you create this Service on Google Kubernetes Engine, the cloud-controller-manager automatically provisions a Google Cloud (TCP/UDP) load balancer and assigns a regional static external IP address. This gives clients a stable, publicly reachable endpoint, which precisely matches the requirement for an internet-facing web application.

Why this answer

A LoadBalancer service type provisions a Google Cloud TCP/UDP Load Balancer and assigns a stable external IP address. NodePort exposes on a high port but requires manual setup; ClusterIP is internal only.

44
MCQeasy

A developer needs to create a zonal GKE cluster with 3 nodes of type e2-standard-4 in zone us-central1-a. Which command should they use?

A.gcloud compute instances create my-cluster --zone=us-central1-a --machine-type=e2-standard-4 --num-nodes=3
B.gcloud container clusters create my-cluster --zone=us-central1-a --num-nodes=3 --machine-type=e2-standard-4
C.gcloud container clusters create my-cluster --zone=us-central1-a --num-nodes=1 --machine-type=e2-standard-4
D.gcloud container clusters create my-cluster --region=us-central1 --num-nodes=3 --machine-type=e2-standard-4
AnswerB

This correct command creates a zonal GKE cluster because --zone targets a single zone, us-central1-a, and the cluster's control plane and nodes are both provisioned there. The --num-nodes=3 flag defines the initial size of the default node pool, and --machine-type=e2-standard-4 sets each node's VM shape. This exactly meets the requirement for a 3-node zonal cluster.

Why this answer

The correct command creates a zonal cluster (single zone) with specified node count and machine type. The --region flag creates a regional cluster, which is not required.

45
Multi-Selectmedium

A company wants to migrate an on-premises MySQL database to Cloud SQL with minimal downtime. The database is 500 GB. Which TWO steps should be taken? (Choose 2 correct answers.)

Select 2 answers
A.Create a Cloud SQL instance to serve as the target for the migration.
B.Export the database using gcloud sql export sql, then import to Cloud SQL.
C.Create a Cloud SQL instance and configure it as an external replica of the on-premises database.
D.Use mysqldump to backup the database and restore into Cloud SQL.
E.Use Database Migration Service to create a continuous migration job.
AnswersA, E

The Database Migration Service requires a pre-provisioned Cloud SQL instance as the destination, so creating one first defines the target tier, storage, and network configuration before any migration job is started. Without an existing instance, DMS has nowhere to replicate the initial snapshot or stream incoming changes. This is the necessary first step in a low-downtime migration, even though the actual data movement happens later via a DMS job.

Why this answer

To minimize downtime, you can perform a Database Migration Service (DMS) continuous migration or export/import with a consistent snapshot. DMS supports MySQL and provides continuous sync. Alternatively, you can export the database using mysqldump, then import, but this requires downtime.

However, for minimal downtime, DMS is best. Another approach is to create a read replica then promote, but Cloud SQL does not support external read replicas directly. The correct two are: use DMS for continuous migration, and optionally create a clone for testing, but the question asks for migration steps.

The best two from the options: use DMS migration job and create a Cloud SQL instance.

46
Multi-Selecthard

A DevOps engineer is responsible for deploying a new microservice to GKE. They need to expose the service externally on a static IP address and scale based on HTTP request load. Which THREE resources must be created? (Choose 3 correct answers.)

Select 3 answers
A.Ingress
B.Deployment
C.Service (type LoadBalancer)
D.ConfigMap
E.HorizontalPodAutoscaler
AnswersB, C, E

A Deployment is the core workload resource that declaratively manages a set of identical pods through a ReplicaSet. It defines the desired state—container image, replicas, and labels—and performs rolling updates and rollbacks, ensuring pods converge to that state. For a stateless microservice, a Deployment is mandatory to run the application reliably; scaling (manually or via HPA) and service selection all operate on the Deployment's pod labels. Without it, you would have no managed pod lifecycle, no self-healing, and no update strategy.

Why this answer

To expose a microservice externally with a static IP and load-based scaling, you typically create a Deployment, a Service of type LoadBalancer (which provisions a TCP load balancer with a static IP), and a HorizontalPodAutoscaler to scale based on CPU (or custom metrics). Ingress is not required if using LoadBalancer, but it's another option. ConfigMap is not needed for this.

47
Multi-Selecthard

A team is deploying a containerized microservice on GKE. They want to ensure the service is externally accessible via a stable IP address and can automatically scale the number of pods based on CPU utilization. Which TWO actions should they perform?

Select 2 answers
A.Expose the deployment using kubectl expose deployment my-service --type=LoadBalancer
B.Set the service type as ClusterIP
C.Create a Cluster Autoscaler on the GKE cluster
D.Create a HorizontalPodAutoscaler targeting the deployment with kubectl autoscale deployment my-service --cpu-percent=80 --min=1 --max=10
E.Expose the deployment using kubectl expose deployment my-service --type=NodePort
AnswersA, D

Running `kubectl expose deployment my-service --type=LoadBalancer` creates a Service of type LoadBalancer, which on GKE signals the cloud controller manager to provision a Google Cloud TCP/UDP load balancer. This load balancer receives a stable external IP address that persists for the lifetime of the Service, independent of node lifecycle. It is the standard way to expose a single deployment to the internet, as it also automatically forwards traffic to the backing pods.

Why this answer

Option A is correct because exposing the deployment with `kubectl expose deployment my-service --type=LoadBalancer` creates a Kubernetes Service of type LoadBalancer, which on GKE provisions a Google Cloud external load balancer with a stable external IP address, satisfying the requirement for external accessibility via a stable IP. Option D is correct because `kubectl autoscale deployment my-service --cpu-percent=80 --min=1 --max=10` creates a HorizontalPodAutoscaler that scales the number of pods between 1 and 10 based on a target CPU utilization of 80%, directly fulfilling the automatic scaling requirement. Option B is incorrect because a ClusterIP service only provides an internal cluster-only virtual IP and is not externally accessible.

Option C is incorrect because a Cluster Autoscaler scales the number of nodes in the node pool, not the number of pods, so it does not address pod-level scaling based on CPU. Option E is incorrect because a NodePort service exposes the service on a static port on each node's IP, which is not a stable external IP address and is not the recommended approach for external access on GKE.

Exam trap

ACE often tests the confusion between Cluster Autoscaler (scales nodes) and HorizontalPodAutoscaler (scales pods), and between Service types (LoadBalancer vs. NodePort vs. ClusterIP) for external exposure with a stable IP.

48
MCQmedium

A Cloud Function needs to be triggered whenever a message is published to a Pub/Sub topic. Which 'gcloud functions deploy' command flag is required to set the trigger?

A.--trigger-topic
B.--trigger-http
C.--trigger-event
D.--trigger-bucket
AnswerA

This flag directly associates the Cloud Function with a Pub/Sub topic. When a message is published to that topic, Pub/Sub delivers it as an event to the function, which is how you configure a message-triggered function. Unlike other triggers, this is the standard and only appropriate flag for Pub/Sub message events in the gcloud beta functions deploy command. It ensures the function is invoked asynchronously with the message payload as the event data.

Why this answer

For a Cloud Function triggered by Pub/Sub messages, the required flag is --trigger-topic, which specifies the Pub/Sub topic name. This flag automatically wires the function as a subscriber to that topic and sets the correct event type.

Exam trap

ACE often tests the difference between --trigger-topic (Pub/Sub), --trigger-bucket (Cloud Storage), and --trigger-event (generic events) — candidates who haven't deployed Pub/Sub functions may pick --trigger-event by mistake.

How to eliminate wrong answers

Option B is wrong because --trigger-http deploys an HTTP-triggered function, not a Pub/Sub-triggered one. Option C is wrong because --trigger-event is used for generic event triggers (such as Cloud Storage or Firestore) and requires a separate --trigger-resource, not a Pub/Sub topic name. Option D is wrong because --trigger-bucket is specifically for Cloud Storage object events, not Pub/Sub messages.

49
Multi-Selecthard

You are deploying a high-traffic web application on GKE. You need to automatically scale the number of pods based on CPU utilization. Which THREE steps are required to set up Horizontal Pod Autoscaling (HPA)?

Select 3 answers
A.Install the metrics-server in the cluster.
B.Enable Stackdriver Monitoring for the cluster.
C.Create a HorizontalPodAutoscaler resource (e.g., via kubectl autoscale).
D.Create a Deployment with resource requests for CPU.
E.Expose the Deployment as a Service of type LoadBalancer.
AnswersA, C, D

The metrics-server aggregates CPU and memory usage from kubelets via the Summary API and exposes them through the metrics.k8s.io API. The HorizontalPodAutoscaler (HPA) controller repeatedly queries that API to obtain current resource utilization; if no metrics-server is installed, the metrics API is unavailable and the HPA reports 'unable to retrieve metrics' and does not scale. It is the lightweight, cluster-local component that provides the raw numbers the HPA needs, whereas GCP's monitoring service is not directly consulted by the HPA.

Why this answer

To use HPA, you need a deployment (or other scalable resource), you need to apply the HPA resource (e.g., via kubectl autoscale), and you must have metrics-server installed to provide metrics. Creating a service is optional.

50
MCQmedium

An organization wants to use Cloud Storage to host a static website. The bucket name must match the domain name. They already own the domain 'example.com' and want to serve the site from 'www.example.com'. Which bucket name should they create?

A.example.com
B.www_example_com
C.example-com-bucket
D.www.example.com
AnswerD

The bucket must be named exactly www.example.com to serve content from that custom domain. When you create a bucket with this name, verify the domain in Cloud Console, and add a CNAME record from www.example.com to c.storage.googleapis.com, Cloud Storage automatically maps the bucket to the hostname. This exact match is required for HTTPS and proper static site hosting.

Why this answer

For Cloud Storage static website hosting, the bucket name must exactly match the domain used to serve the site. Since the site will be served from 'www.example.com', the bucket must be named 'www.example.com'. GCS requires globally unique bucket names, and the CNAME/A record for the domain must point to the bucket.

Exam trap

The trap here is assuming the bucket should be named after the apex domain ('example.com') rather than the exact hostname being served ('www.example.com') — candidates forget that GCS matches the Host header to the bucket name character-for-character.

How to eliminate wrong answers

Option A is wrong because 'example.com' would serve the apex domain, not the requested 'www.example.com' subdomain — the bucket name must match the hostname in the request. Option B is wrong because underscores are not valid characters in GCS bucket names (only lowercase letters, numbers, hyphens, and dots), and it does not match the domain anyway. Option C is wrong because the bucket name must exactly equal the domain name; 'example-com-bucket' does not match 'www.example.com' and would not serve the site correctly.

51
Multi-Selecthard

A data engineering team wants to create a Cloud Storage bucket for storing sensitive analytics data. They require encryption at rest with customer-managed keys (CMEK) and want to restrict access to a specific service account. Which three steps are necessary?

Select 3 answers
A.Set the bucket's default encryption to use the KMS key
B.Enable uniform bucket-level access
C.Grant the service account roles/storage.objectAdmin on the bucket
D.Create a service account and download its JSON key
E.Create a Cloud KMS key ring and key in the same region as the bucket
AnswersA, C, E

Setting the bucket's default encryption to point at the KMS key is the step that activates customer-managed encryption for Cloud Storage. All objects uploaded after this change are automatically encrypted with the selected Cloud KMS key instead of Google-owned keys. Without this configuration, the key ring and key remain unused and the bucket continues using default encryption.

Why this answer

To use CMEK, you must create a Cloud KMS key ring and key, then configure the bucket to use that key. Access is controlled via IAM; granting the service account roles/storage.objectAdmin allows full object management. Note: The KMS key must be in the same region as the bucket.

52
Multi-Selectmedium

An engineer is using gsutil to upload a large number of files to a Cloud Storage bucket. The upload is proceeding very slowly. Which two actions could improve the upload performance? (Choose two.)

Select 2 answers
A.Use the gsutil -m option to enable parallel multi-threading.
B.Increase the number of retries using gsutil -o Boto:num_retries=10.
C.Change the storage class of the bucket to Standard.
D.Set the parallel composite upload threshold to a value less than the size of the files being uploaded.
E.Set a custom ACL on the bucket to allow faster writes.
AnswersA, D

The -m flag enables gsutil's multithreaded, parallel execution mode, so many objects upload concurrently instead of sequentially. This directly addresses the stem's slow bulk upload by saturating available bandwidth across multiple threads rather than processing one file at a time.

Why this answer

Option A is correct because gsutil -m enables parallel multi-threaded/multi-processing transfers, which lets many files upload concurrently and dramatically improves throughput when uploading a large number of files. Option D is correct because enabling parallel composite uploads (by setting the threshold below the file size, e.g., gsutil -o GSUtil:parallel_composite_upload_threshold=150M) splits large files into chunks uploaded in parallel and then composed server-side, speeding up large-file uploads. Option B is incorrect because Boto:num_retries only controls how many times failed requests are retried; it does not increase throughput and can even slow things down.

Option C is incorrect because storage class affects pricing, availability, and access characteristics, not upload speed. Option E is incorrect because ACLs govern access permissions and have no effect on write performance.

Exam trap

ACE often tests the specific gsutil flags that improve performance, and candidates may confuse retry settings or storage classes with performance optimizations.

53
MCQmedium

A data scientist wants to deploy a Python function that processes messages from a Pub/Sub topic whenever a new message arrives. The function should be stateless and run in a serverless environment. Which deployment command should be used?

A.gcloud run deploy my-function --source . --region us-central1 --trigger-topic my-topic
B.gcloud functions deploy my-function --runtime python39 --trigger-topic my-topic --entry-point my_entry --region us-central1
C.gcloud pubsub subscriptions create my-sub --topic my-topic --push-endpoint https://my-function-url
D.gcloud functions deploy my-function --runtime python39 --trigger-http --entry-point my_entry --region us-central1
AnswerB

gcloud functions deploy with --trigger-topic creates an event-driven Cloud Function subscribed to a Pub/Sub topic. The --runtime python39 specifies the Python 3.9 execution environment, --entry-point my_entry identifies the function name inside main.py to invoke, and --region sets the deployment location. This is the only valid command that directly deploys the function and wires it to the specified Pub/Sub topic.

Why this answer

The correct command is 'gcloud functions deploy' with '--trigger-topic', which deploys a Cloud Function (2nd gen or 1st gen) that is invoked by Pub/Sub messages. This matches the requirement for a stateless, serverless function triggered by a Pub/Sub topic. The runtime and entry point flags are also correctly specified.

Exam trap

ACE often tests the difference between deploying a function ('gcloud functions deploy') and creating a subscription ('gcloud pubsub subscriptions create') — candidates pick the subscription command thinking it 'connects' the function to the topic, but it does not deploy the function.

How to eliminate wrong answers

Option A is wrong because 'gcloud run deploy' deploys to Cloud Run, which is container-based and does not natively support '--trigger-topic' — Cloud Run uses Eventarc for Pub/Sub triggers, not a direct topic flag. Option C is wrong because it creates a Pub/Sub push subscription pointing to an existing HTTP endpoint; it does not deploy the function itself and assumes the function already exists. Option D is wrong because '--trigger-http' deploys an HTTP-triggered function, not a Pub/Sub-triggered one, so it would not automatically process messages from the topic.

54
MCQmedium

An organization needs to deploy a regional Cloud SQL MySQL instance with 4 vCPUs and 15 GB of memory. The instance should be highly available within a single region. Which gcloud command should they use?

A.gcloud sql instances create my-instance --tier=db-n1-standard-4 --region=us-central1 --database-version=MYSQL_8_0 --root-password=password123 --availability-type=REGIONAL
B.gcloud sql instances create my-instance --tier=db-n1-highmem-4 --region=us-central1 --database-version=MYSQL_8_0
C.gcloud sql instances create my-instance --tier=db-n1-standard-4 --region=us-central1 --database-version=MYSQL_8_0 --root-password=password123
D.gcloud sql instances create my-instance --tier=db-n1-standard-4 --region=us-central1
AnswerA

The REGIONAL availability type provisions a standby instance in a second zone within the same region, satisfying the high-availability constraint. The db-n1-standard-4 tier supplies exactly 4 vCPUs and 15 GB memory, matching the required sizing.

Why this answer

A regional (highly available) Cloud SQL instance requires the `--availability-type=REGIONAL` flag, which provisions a standby in a different zone within the same region and enables automatic failover. Option A includes this flag along with the correct tier, region, database version, and root password, making it the only command that satisfies all stated requirements.

Exam trap

ACE often tests the distinction between ZONAL and REGIONAL availability — candidates assume 'highly available' is the default and forget the explicit `--availability-type=REGIONAL` flag.

How to eliminate wrong answers

Option B is wrong because it uses `db-n1-highmem-4` (4 vCPU, 26 GB RAM), which does not match the 15 GB memory requirement, and it omits both the root password and the `--availability-type=REGIONAL` flag. Option C is wrong because it omits `--availability-type=REGIONAL`, so the instance would be created as ZONAL (non-HA) by default. Option D is wrong because it omits the database version, root password, and availability type — it would create a default-version zonal instance with no root password.

55
MCQmedium

A company wants to allow unauthenticated HTTP invocations of a container deployed on Cloud Run. Which flag should be included in the 'gcloud run deploy' command?

A.--public
B.--no-authentication
C.--allow-unauthenticated
D.--auth-type public
AnswerC

The --allow-unauthenticated flag is the correct option because it explicitly grants the role roles/run.invoker to allUsers, enabling public access to the Cloud Run service. This flag is a required parameter when deploying a service that must respond to HTTP requests without any authentication, such as a public API or webhook. It overrides the default behavior, which denies access to unauthenticated users.

Why this answer

The '--allow-unauthenticated' flag allows unauthenticated invocations. By default, Cloud Run requires authentication.

56
MCQhard

A Cloud SQL for MySQL instance needs to be created with the following requirements: MySQL 8.0, db-n1-standard-2 tier, in us-central1, with root password 'secret'. Which command meets these requirements?

A.gcloud compute instances create my-instance --database-version MYSQL_8_0 --tier db-n1-standard-2 --region us-central1 --root-password secret
B.gcloud sql instances create my-instance --database-version MYSQL8 --tier n1-standard-2 --region us-central1 --password secret
C.gcloud sql instances create my-instance --database-version MYSQL_8_0 --tier db-n1-standard-2 --region us-central1 --root-password secret
D.gcloud sql instances create my-instance --database-version MYSQL_8_0 --machine-type db-n1-standard-2 --region us-central1 --root-password secret
AnswerC

This command correctly uses gcloud sql instances create with the supported database version MYSQL_8_0, the properly prefixed tier db-n1-standard-2, the target region us-central1, and the --root-password flag to set the initial root password. These are all valid and required parameters for provisioning a Cloud SQL for MySQL 8.0 instance from the command line.

Why this answer

The 'gcloud sql instances create' command with --database-version, --tier, --region, and --root-password correctly creates the instance.

57
MCQeasy

A developer wants to deploy a containerized application to Cloud Run that should be publicly accessible over the internet. The container image is stored in Container Registry. Which gcloud command should they use?

A.gcloud run deploy my-service --image gcr.io/my-project/my-image --region us-central1 --platform cloud-run --allow-unauthenticated
B.gcloud run deploy my-service --image gcr.io/my-project/my-image --region us-central1 --platform managed --allow-unauthenticated
C.gcloud run deploy my-service --image gcr.io/my-project/my-image --region us-central1 --platform gke --allow-unauthenticated
D.gcloud run deploy my-service --image gcr.io/my-project/my-image --region us-central1 --platform managed
AnswerB

The --allow-unauthenticated flag grants the allUsers IAM binding, satisfying the public internet access requirement, while --platform managed and --region target the fully managed Cloud Run service. The --image flag correctly references the Container Registry path.

Why this answer

The correct gcloud command uses --platform managed, which is the required value for Cloud Run (fully managed). The --allow-unauthenticated flag makes the service publicly accessible. Option B includes both correct flags.

Option A uses --platform cloud-run, which is invalid; the accepted values are managed or gke. Option C uses --platform gke, which would deploy to a GKE cluster, not Cloud Run. Option D omits --allow-unauthenticated, so the service would require authentication, not public.

Exam trap

ACE often tests the exact syntax of gcloud commands, especially the --platform value and the --allow-unauthenticated flag, tempting candidates to confuse Cloud Run with GKE or forget public access.

How to eliminate wrong answers

Option A is wrong because --platform cloud-run is not a valid value; the correct value is managed. Option C is wrong because --platform gke deploys to Google Kubernetes Engine, not Cloud Run, and would not be publicly accessible by default. Option D is wrong because it lacks --allow-unauthenticated, so the service would not be publicly accessible, contradicting the requirement.

58
Multi-Selectmedium

A company is deploying a microservice on Cloud Run. They want to ensure that the service can handle high traffic spikes by allowing multiple concurrent requests per container instance. They also want to minimize cold starts. Which two settings should they configure? (Choose two.)

Select 2 answers
A.Set the timeout to 900 seconds
B.Set CPU always on to true
C.Set min-instances to a value greater than 0 (e.g., 1)
D.Set max-instances to a high value
E.Set concurrency to a value higher than 1 (e.g., 80)
AnswersC, E

Setting min-instances to a value greater than 0, such as 1, instructs Cloud Run to keep at least one instance always running and fully initialized, so baseline traffic never experiences the latency penalty of a cold start. This pre-warmed instance is ready to serve immediately, eliminating the delay caused by pulling a container image and booting the runtime. Note that this approach incurs billing even when there is no traffic, and it only removes cold starts for the first instance; a sudden burst beyond that instance's concurrency can still trigger new cold starts.

Why this answer

Setting concurrency to a higher value (e.g., 80) allows each container instance to handle multiple requests simultaneously, improving throughput. Setting min-instances to a value greater than 0 keeps instances warm to reduce cold starts. Max-instances limits scaling but does not help with cold starts.

CPU always on keeps CPU allocated but does not directly affect cold starts. Timeout affects request duration, not concurrency or cold starts.

59
Multi-Selecthard

A DevOps engineer is creating a GKE cluster for a production workload that requires high availability and resilience to zone failures. They also need to deploy a stateless application that can scale based on CPU usage. Which two actions should they take? (Choose two.)

Select 2 answers
A.Enable node auto-repair on the node pool
B.Create a zonal cluster in a single zone
C.Set the deployment replicas to 1
D.Enable horizontal pod autoscaling on the deployment with CPU target utilization
E.Create a regional cluster with nodes in multiple zones
AnswersD, E

Horizontal Pod Autoscaler (HPA) continuously observes the average CPU utilization of the pods in a Deployment (via metrics-server) and automatically adjusts the `replicas` field to keep utilization near the configured target, e.g., 70%. This directly fulfills the stated need to scale the application based on load — when CPU usage rises, HPA adds pods; when it drops, HPA removes excess pods. Note that HPA is about pod-level elasticity and does not by itself provide zone resilience; to meet the production requirement fully, you would combine HPA with a regional multi-zone cluster so that scaled-out pods can be scheduled across failure domains.

Why this answer

Option E is correct because a regional GKE cluster spreads its control plane and node pools across multiple zones within a region, which provides resilience to zone failures and satisfies the high-availability requirement. Option D is correct because a Horizontal Pod Autoscaler (HPA) targeting CPU utilization automatically adjusts the number of pod replicas based on observed CPU usage, which is exactly what the stateless application needs to scale. Option A is not required for the stated goals: node auto-repair only restarts unhealthy nodes and does not by itself provide zone-failure resilience or CPU-based scaling.

Option B is wrong because a zonal cluster in a single zone is a single point of failure and cannot survive a zone outage. Option C is wrong because setting replicas to 1 prevents scaling and creates a single point of failure for the stateless workload.

Exam trap

ACE often tests the confusion between node-level resilience (auto-repair, auto-upgrade) and cluster-level zone resilience (regional vs zonal), tricking candidates into picking node auto-repair as an HA solution.

60
MCQhard

You are managing a Cloud SQL for PostgreSQL instance. You need to import a SQL dump file stored in a Cloud Storage bucket. The file is 10GB. Which command should you use?

A.Use psql command from a Compute Engine instance to connect and import the file.
B.gcloud sql import sql my-instance gs://bucket/file.sql --database=db
C.gcloud sql instances import my-instance gs://bucket/file.sql --database=db
D.gcloud sql import csv my-instance gs://bucket/file.sql --database=db
AnswerB

The gcloud sql import sql command streams the SQL dump from the Cloud Storage bucket directly into the specified database on the instance, handling the 10GB file without local download. It satisfies the stem's requirement to import a SQL dump from Cloud Storage into Cloud SQL for PostgreSQL.

Why this answer

The correct command to import a SQL dump from Cloud Storage into a Cloud SQL instance is `gcloud sql import sql <instance> <gs://path> --database=<db>`. The `sql` subcommand specifies the file format, and the instance name and GCS URI are positional arguments. Option B matches this exact syntax.

Exam trap

ACE often tests the exact gcloud subcommand hierarchy — candidates confuse `gcloud sql import sql` with `gcloud sql instances import` or pick the wrong format flag (csv vs sql).

How to eliminate wrong answers

Option A is wrong because using psql from a Compute Engine instance is a manual workaround that requires network access, authentication, and streaming a 10 GB file — it is not the recommended or scalable approach for large imports. Option C is wrong because the subcommand is `gcloud sql import sql`, not `gcloud sql instances import` — the latter is not a valid gcloud command. Option D is wrong because `import csv` is for CSV files, not SQL dump files; using it on a .sql file would fail parsing.

61
MCQmedium

A developer wants to run a one-time query on a large dataset stored in Cloud Storage using BigQuery without loading the data into a table. Which feature should they use?

A.Use a BigQuery federated query with an external table definition
B.Create a permanent table and load the data using gcloud bq load
C.Use Cloud SQL to query the data via federated query
D.Use gcloud sql import to load data into BigQuery
AnswerA

A BigQuery federated query with an external table definition lets you query data that remains in Cloud Storage without loading it into BigQuery's managed storage. You define an external table pointing at files in GCS (CSV, JSON, Avro, Parquet, etc.) with optional schema auto-detection, and the query engine reads the source natively at query time. This matches a one-time analysis by eliminating the load job, copying no data, and charging only for the bytes scanned during execution.

Why this answer

BigQuery federated queries (external tables) let you query data stored outside BigQuery — such as CSV, JSON, Avro, or Parquet files in Cloud Storage — without loading it into a native BigQuery table. This is exactly the one-time query use case described. The external table definition points at the GCS URI, and BigQuery reads the data at query time.

Exam trap

The trap here is confusing BigQuery federated/external tables with Cloud SQL federated queries, or assuming data must always be loaded before it can be queried.

How to eliminate wrong answers

Option B is wrong because creating a permanent table and loading data with `bq load` (or `gcloud bq load`) is the opposite of the requirement — it persists and duplicates the data rather than querying it in place. Option C is wrong because Cloud SQL is a relational database service and does not support federated queries against Cloud Storage data; BigQuery is the correct analytics engine. Option D is wrong because `gcloud sql import` imports data into Cloud SQL, not BigQuery, and does not enable querying GCS data directly.

62
MCQeasy

An engineer needs to create a GKE cluster with 3 nodes of machine type e2-medium in the us-central1 region. Which command should they use?

A.gcloud container clusters create my-cluster --num-nodes=3 --machine-type=e2-medium --region=us-central1
B.gcloud container clusters create my-cluster --num-nodes=3 --machine-type=e2-medium
C.gcloud container clusters create my-cluster --num-nodes=3 --machine-type=e2-medium --region=us-central1-a
D.gcloud container clusters create my-cluster --num-nodes=3 --machine-type=e2-medium --zone=us-central1-a
AnswerA

This command creates a regional GKE cluster in the us-central1 region, using --region rather than --zone. The --num-nodes=3 flag sets three e2-medium nodes in the cluster, and the regional scope means the control plane is replicated across the zones in us-central1, providing higher availability. This is the only option that correctly combines the required node specification with a regional location.

Why this answer

The correct command is 'gcloud container clusters create my-cluster --num-nodes=3 --machine-type=e2-medium --region=us-central1'. The --zone flag is for zonal clusters, not regional. The other options either use wrong zone or wrong flags.

63
Multi-Selectmedium

A company wants to deploy a new application on Google Cloud that requires a regional managed instance group with automatic scaling based on HTTP load. Which two resources must they create? (Choose TWO.)

Select 2 answers
A.Cloud Run service
B.GKE cluster
C.HTTP(S) Load Balancer
D.Instance template
E.Cloud Function
AnswersC, D

The HTTP(S) Load Balancer is a correct component because it provides a single anycast IP address that distributes incoming traffic across the backend Compute Engine instances in the managed instance group. It also performs health checks on those instances and automatically routes traffic only to healthy VMs, which is essential for a highly available application and is the standard external entry point for a MIG-based deployment.

Why this answer

To deploy a regional managed instance group (MIG) with autoscaling based on HTTP load, you need an instance template to define the VM configuration for the MIG, and an HTTP(S) Load Balancer to distribute traffic and provide the load metrics for autoscaling. Options C (HTTP(S) Load Balancer) and D (Instance template) are correct. Option A (Cloud Run) is for serverless containers, not for MIGs.

Option B (GKE cluster) is for Kubernetes. Option E (Cloud Function) is for serverless functions.

64
MCQeasy

You need to allow SSH access to a Compute Engine instance. Which method is the recommended way to manage SSH keys for multiple users?

A.Add SSH keys to the instance metadata.
B.Use gcloud compute ssh with the --ssh-key-file flag.
C.Enable OS Login and assign IAM roles to users.
D.Create a custom image with preconfigured SSH keys.
AnswerC

Enabling OS Login at the project or instance level, then assigning IAM roles such as roles/compute.osLogin or roles/compute.osAdminLogin to users, is the recommended pattern for SSH access. OS Login links the Linux account on the instance to the user's Google identity, automatically provisions a temporary SSH key when the user runs gcloud compute ssh, and allows instant revocation simply by removing the IAM policy binding.

Why this answer

OS Login is the recommended method for managing SSH access to Compute Engine instances, as it links SSH keys to user accounts and integrates with IAM.

65
MCQmedium

A developer wants to deploy a containerized application on Cloud Run from a source code repository, without building a container image manually. The application is written in Node.js and includes a Dockerfile. Which command should the developer use to deploy directly from source?

A.gcloud run deploy --image=gcr.io/my-project/my-image --region=us-central1
B.gcloud app deploy --source .
C.gcloud run deploy my-service --source . --region=us-central1 --platform managed
D.gcloud functions deploy my-function --runtime nodejs14 --trigger-http --source .
AnswerC

The --source flag makes Cloud Run build the image from the local directory using Buildpacks or the supplied Dockerfile, removing manual image construction. --platform managed and --region satisfy the fully managed regional deployment the stem requires.

Why this answer

The `gcloud run deploy` command with the `--source .` flag instructs Cloud Run to build the container image automatically using Cloud Build (via Buildpacks or the provided Dockerfile) and then deploy it. This is the only option that deploys directly from source to Cloud Run without requiring a pre-built image. The `--platform managed` flag confirms a fully managed Cloud Run service.

Exam trap

ACE often tests the distinction between deployment targets — candidates confuse `gcloud run deploy`, `gcloud app deploy`, and `gcloud functions deploy`, assuming any `--source` flag works across services, when each command is tied to a specific Google Cloud compute platform.

How to eliminate wrong answers

Option A is wrong because `--image=gcr.io/my-project/my-image` requires a pre-built container image already pushed to a registry, which contradicts the requirement to deploy without building manually. Option B is wrong because `gcloud app deploy` targets App Engine, not Cloud Run, and does not deploy containerized workloads to Cloud Run. Option D is wrong because `gcloud functions deploy` deploys to Cloud Functions (a serverless function service), not Cloud Run, and is not appropriate for a containerized Node.js application.

66
MCQmedium

A team is creating a managed instance group (MIG) for a stateless web application. They need to ensure that instances are automatically replaced if they become unhealthy and that new instances are rolled out gradually with no downtime during updates. Which set of configurations should they use?

A.Create a MIG without health check; set rolling update with maxSurge=1 and maxUnavailable=0.
B.Create a MIG with a health check for autohealing; set rolling update with maxSurge=0 and maxUnavailable=1.
C.Create a MIG with a health check configured for autohealing; set rolling update with maxSurge=1 and maxUnavailable=0.
D.Create a MIG without health check; set rolling update with maxSurge=0 and maxUnavailable=1.
AnswerC

The health check drives autohealing, replacing unhealthy instances automatically. maxSurge=1 with maxUnavailable=0 keeps capacity at or above target throughout the rolling update, so no instance is removed before a replacement is ready, satisfying the no-downtime constraint.

Why this answer

A health check is required for autohealing — without it, the MIG cannot detect unhealthy instances and replace them. For zero-downtime rolling updates, maxSurge=1 allows a new instance to be created before an old one is removed, while maxUnavailable=0 guarantees the desired capacity is never reduced during the update. This combination satisfies both requirements.

Exam trap

ACE often tests the pairing of health checks with autohealing and the maxSurge/maxUnavailable semantics, trapping candidates who assume any rolling update configuration provides zero downtime.

How to eliminate wrong answers

Option A is wrong because a MIG without a health check cannot perform autohealing — it will only replace instances based on the instance template, not on application health. Option B is wrong because maxSurge=0 and maxUnavailable=1 means an instance is taken down before a replacement is ready, causing a temporary capacity reduction and potential downtime. Option D is wrong on both counts: no health check means no autohealing, and maxUnavailable=1 permits downtime during updates.

67
MCQhard

A company wants to deploy a containerized application on Cloud Run that is built from source code in a local directory. They want Cloud Run to automatically build the container image using Cloud Build. Which command should be used?

A.gcloud run deploy my-service --source . --region us-central1
B.gcloud app deploy --source .
C.gcloud run deploy my-service --image . --region us-central1
D.gcloud builds submit --tag gcr.io/my-project/my-image . && gcloud run deploy my-service --image gcr.io/my-project/my-image
AnswerA

The --source flag tells gcloud to treat the current directory as source code, automatically invoking Cloud Build to containerize it using buildpacks before deploying to Cloud Run in the specified region. This single command combines the build and deploy steps, which is exactly what the requirement of a one-command deployment asks for. The service name 'my-service' is provided, and the region ensures the service is created in us-central1.

Why this answer

The command gcloud run deploy my-service --source . --region us-central1 uses the --source flag to indicate that Cloud Run should build the container image from the local source code using Cloud Build, then deploy it. This is the correct way to deploy from source.

Exam trap

ACE often tests the difference between deploying from source (--source) and deploying from an image (--image); candidates may choose the manual build option because it also works, but the question specifies automatic build.

How to eliminate wrong answers

Option B is wrong because gcloud app deploy is for App Engine, not Cloud Run. Option C is wrong because --image expects a container image URL, not a local directory. Option D is wrong because it manually builds and pushes the image with gcloud builds submit, then deploys; while this works, it does not use the automatic build from source that the question asks for.

68
MCQmedium

An engineer needs to view the logs generated by a Cloud Run service to troubleshoot a recent deployment. Which service should they use?

A.Cloud Monitoring
B.Cloud Logging
C.Error Reporting
D.Cloud Trace
AnswerB

Cloud Logging is the correct choice because it is the native, centralized log storage and retrieval service for Google Cloud, and Cloud Run automatically sends both request logs and platform logs to it. Application output written to stdout/stderr is also captured as structured logs. You can view these logs immediately in the Logs Explorer and filter them by resource type, severity, or labels.

Why this answer

Cloud Logging (formerly Stackdriver Logging) is the unified logging service for Google Cloud. Cloud Run logs are automatically sent to Cloud Logging.

69
MCQeasy

An engineer wants to create a regional GKE cluster with 3 nodes by default. Which command should be used?

A.gcloud container clusters create my-cluster --zone us-central1-a --num-nodes 3
B.gcloud container clusters create my-cluster --region us-central1 --num-nodes 3
C.gcloud container clusters create my-cluster --region us-central1 --nodes 3
D.gcloud compute clusters create my-cluster --region us-central1 --size 3
AnswerB

This is the standard way to create a regional GKE cluster. The --region flag designates a regional cluster where the control plane is replicated across three zones in that region, and nodes are spread across those zones (3 nodes per zone by default with --num-nodes 3). This provides higher availability and is exactly what the engineer needs.

Why this answer

The 'gcloud container clusters create' command with --region (not --zone) creates a regional cluster. --num-nodes specifies the number of nodes per zone.

70
MCQmedium

A data analyst wants to import a SQL dump file from a Cloud Storage bucket into an existing Cloud SQL database. Which command should they use?

A.gcloud sql instances import my-instance gs://my-bucket/dump.sql --database=mydb
B.gcloud sql import sql my-instance gs://my-bucket/dump.sql --database=mydb
C.gcloud sql import csv my-instance gs://my-bucket/dump.sql --database=mydb
D.gcloud sql databases import my-instance gs://my-bucket/dump.sql
AnswerB

This is the correct command. 'gcloud sql import sql' explicitly tells the Cloud SQL API that the source file is a SQL dump (typically generated by mysqldump or pg_dump). The arguments specify the instance name, the Cloud Storage URI of the dump file, and the target database using the --database flag. This syntax works for both MySQL and PostgreSQL instances and is the standard way to import SQL dump files.

Why this answer

The correct command is 'gcloud sql import sql <instance> gs://<bucket>/<file> --database=<db>'. This imports a SQL dump file. The other commands either use wrong syntax or wrong import type (csv for CSV files).

71
MCQhard

A DevOps engineer needs to deploy a containerized microservice to Cloud Run that processes messages from Pub/Sub. The service must authenticate to Google Cloud APIs using a service account. Which Cloud Run deployment command should they use to ensure the service uses a specific service account?

A.gcloud run deploy my-service --image gcr.io/my-project/my-image --service-account my-sa@my-project.iam.gserviceaccount.com --platform managed
B.gcloud run deploy my-service --image gcr.io/my-project/my-image --account my-sa@my-project.iam.gserviceaccount.com
C.gcloud run deploy my-service --image gcr.io/my-project/my-image --impersonate-service-account my-sa@my-project.iam.gserviceaccount.com
D.gcloud run deploy my-service --image gcr.io/my-project/my-image
AnswerA

Using the `--service-account` flag with `gcloud run deploy` explicitly assigns the specified IAM service account as the runtime identity for the Cloud Run service. This is the correct syntax because the flag is designed to set the service account that the container will run as, and `--platform managed` ensures the command targets Cloud Run (fully managed) rather than other platforms. The deployed service will inherit the IAM permissions of `my-sa@my-project.iam.gserviceaccount.com`, which is exactly what the DevOps engineer needs.

Why this answer

Cloud Run supports the --service-account flag to attach a specific service account. The --image flag specifies the container image. The other options either use incorrect flags (--account is for gcloud CLI user, not service account) or miss required flags.

72
MCQmedium

A company has a Cloud Run service that needs to access a Cloud SQL database. What is the recommended way to connect securely?

A.Use Cloud SQL Proxy by adding the Cloud SQL instance connection name to the Cloud Run service
B.Use a public IP for the Cloud SQL instance and whitelist the Cloud Run service's IP
C.Store database credentials in environment variables
D.Use VPC peering to connect Cloud Run to Cloud SQL
AnswerA

When you bind a Cloud Run service to a Cloud SQL instance by its connection name, the platform automatically injects and runs the Cloud SQL Auth Proxy as a sidecar container. The proxy connects to the database over an encrypted channel using either a private IP or a Unix socket, and it leverages IAM permissions to authorize the connection. This pattern avoids static IP management, network whitelisting, and manual secret handling, making it the officially recommended integration.

Why this answer

The recommended way for Cloud Run to connect to Cloud SQL is to use the Cloud SQL Auth Proxy (or the built-in Cloud SQL connector) by specifying the instance connection name in the Cloud Run service configuration. This provides secure, IAM-authenticated, encrypted connectivity without exposing the database to the public internet. It is the Google-recommended pattern for serverless-to-Cloud SQL connectivity.

Exam trap

ACE often tests the misconception that VPC peering or public IP whitelisting is the way to connect Cloud Run to Cloud SQL; the correct answer is the Cloud SQL Auth Proxy with the instance connection name, which candidates overlook in favor of network-level solutions.

How to eliminate wrong answers

Option B is wrong because using a public IP and whitelisting the Cloud Run service's IP is unreliable — Cloud Run instances have dynamic egress IPs unless you configure Serverless VPC Access with a static IP, and exposing the database publicly increases attack surface. Option C is wrong because storing credentials in environment variables is a security anti-pattern; it does not address secure connectivity and risks credential leakage. Option D is wrong because VPC peering connects VPC networks, but Cloud Run is a serverless platform that requires Serverless VPC Access (not direct peering) to reach a VPC, and Cloud SQL Proxy is still the recommended secure connection method.

73
MCQmedium

A developer is deploying a containerized application on Cloud Run. The application needs to be invoked by external HTTPS requests without requiring authentication. Which flag should be included in the 'gcloud run deploy' command?

A.--invoker=public
B.--allow-unauthenticated
C.--ingress=internal
D.--no-allow-unauthenticated
AnswerB

The `--allow-unauthenticated` flag is the correct way to enable public HTTPS access to a Cloud Run service. When set at deploy time, Cloud Run binds the IAM role `roles/run.invoker` to the special `allUsers` principal, allowing any client to invoke the service without providing credentials. This directly satisfies the requirement of making the containerized app reachable from the internet.

Why this answer

The `--allow-unauthenticated` flag on `gcloud run deploy` grants the Cloud Run Invoker IAM role to `allUsers`, making the service publicly callable over HTTPS without an identity token. This is the documented way to expose a Cloud Run service to unauthenticated external traffic.

Exam trap

ACE often tests the confusion between ingress control (network reachability) and authentication (identity), leading candidates to pick `--ingress=internal` when the question is about public unauthenticated access.

How to eliminate wrong answers

Option A is wrong because `--invoker=public` is not a valid gcloud flag; invoker permissions are managed via IAM, not a deploy flag. Option C is wrong because `--ingress=internal` restricts traffic to internal sources (VPC or internal load balancer), the opposite of what is needed. Option D is wrong because `--no-allow-unauthenticated` explicitly requires authentication, which contradicts the requirement.

74
MCQmedium

An engineer wants to deploy a Python function that processes messages from a Pub/Sub topic. The function should be triggered whenever a message is published to the topic. Which command should the engineer use to deploy the function?

A.gcloud functions deploy my-function --runtime python39 --trigger-http --entry-point main --region=us-central1
B.gcloud functions deploy my-function --runtime python39 --trigger-topic my-topic --entry-points main --region=us-central1
C.gcloud functions deploy my-function --runtime python39 --trigger-topic my-topic --entry-point main --region=us-central1
D.gcloud functions deploy my-function --runtime python39 --trigger-bucket my-bucket --entry-point main --region=us-central1
AnswerC

This is the correct command because --trigger-topic my-topic binds the function to Pub/Sub, causing it to be invoked every time a message is published to that topic. The --entry-point main identifies the Python callable in the code, while --runtime python39 specifies the runtime. It correctly deploys a background Cloud Function without exposing an HTTP endpoint.

Why this answer

The correct command uses --trigger-topic my-topic to bind the function to a Pub/Sub topic, and --entry-point main (singular) to name the function entry point. This deploys a background function that Cloud Functions invokes whenever a message is published to the topic. The runtime and region flags are also correctly specified.

Exam trap

ACE often tests the exact flag spelling and trigger type — candidates confuse --entry-point with --entry-points, or pick --trigger-http/--trigger-bucket when the scenario explicitly requires Pub/Sub topic triggering.

How to eliminate wrong answers

Option A is wrong because --trigger-http creates an HTTP-triggered function, not a Pub/Sub-triggered one, so it would not fire on topic messages. Option B is wrong because the flag is --entry-point (singular), not --entry-points; the plural form is invalid and the deployment would fail. Option D is wrong because --trigger-bucket binds the function to Cloud Storage object events, not Pub/Sub messages, so it would not respond to topic publishes.

75
MCQmedium

An organization needs to import a SQL dump file from a Cloud Storage bucket into an existing Cloud SQL for PostgreSQL instance. Which command should they use?

A.gcloud sql export sql my-instance gs://bucket/dump.sql
B.gcloud sql import sql my-instance gs://bucket/dump.sql --database=mydb
C.gcloud sql instances import my-instance gs://bucket/dump.sql
D.gcloud sql import csv my-instance gs://bucket/dump.sql --database=mydb
AnswerB

The gcloud sql import sql command imports a SQL dump from a Cloud Storage URI into an existing instance, and --database=mydb directs the dump into the named database. This matches the stem's requirement to load a dump into Cloud SQL for PostgreSQL.

Why this answer

The correct command is 'gcloud sql import sql my-instance gs://bucket/dump.sql --database=mydb', which imports a SQL dump file from a Cloud Storage bucket into an existing Cloud SQL instance and specifies the target database. The 'gcloud sql import sql' subcommand is designed for importing SQL dump files, and the --database flag is required when the dump does not specify the database. This matches the requirement to import into an existing PostgreSQL instance.

Exam trap

The trap is reversing import and export commands, or using the wrong file format flag (csv vs sql); candidates must remember that 'gcloud sql import sql' is for SQL dumps and 'export sql' is for exporting.

How to eliminate wrong answers

Option A is wrong because 'gcloud sql export sql' exports data from Cloud SQL to a bucket, which is the opposite operation. Option C is wrong because 'gcloud sql instances import' is not a valid gcloud command; the correct subcommand is 'gcloud sql import sql'. Option D is wrong because 'gcloud sql import csv' imports CSV files, not SQL dump files, and would fail with a .sql file.

Page 1 of 2 · 78 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Deploying and Implementing a Cloud Solution questions.