Courseiva

CCNA Setting Up a Cloud Solution Environment Questions

66 questions · Setting Up a Cloud Solution Environment · All types, answers revealed

1
MCQmedium

A company wants to manage multiple GCP projects with different configurations (e.g., different regions and accounts) on the same workstation. Which gcloud feature should they use to switch between these configurations?

A.Environment variables
B.gcloud init each time
C.Configuration profiles
D.Multiple gcloud installations
AnswerC

gcloud config configurations (also called profiles) let you create and store named sets of properties including project, account, and region, then switch between them instantly with 'gcloud config configurations activate PROFILE'. Each profile can have its own authenticated credentials because 'gcloud auth login' can be run while a profile is active, so you can maintain distinct identities and project scopes simultaneously — this is the built-in, designed mechanism for multi-project management.

Why this answer

gcloud configurations (configuration profiles) are named sets of properties such as account, project, region, and zone that can be activated with `gcloud config configurations activate <name>`. This lets one workstation cleanly switch between projects and accounts without re-running setup. It is the intended mechanism for managing multiple GCP contexts.

Exam trap

The trap here is confusing per-property overrides (environment variables or `gcloud config set`) with the named configuration feature that bundles account, project, region, and zone into a switchable profile.

How to eliminate wrong answers

Option A is wrong because environment variables like `CLOUDSDK_CORE_PROJECT` can override individual settings but do not provide a managed, switchable set of account/project/region/zone values. Option B is wrong because re-running `gcloud init` each time is manual, error-prone, and overwrites the active configuration rather than letting you switch between saved ones. Option D is wrong because installing multiple gcloud SDKs is unnecessary, wastes disk space, and creates PATH/version conflicts; a single SDK supports many configurations.

2
MCQeasy

What is the basic role that grants full control over all resources in a GCP project?

A.Editor
B.Owner
C.Viewer
D.Admin
AnswerB

The Owner basic role is the highest-level predefined role in Cloud IAM, encompassing all Editor permissions plus the ability to manage IAM policies, set billing accounts, and configure organization-level settings when applied at the project or organization level. An Owner can grant any role to any principal, including making another user an Owner, and can view or change the project's billing account and payment details. This role is typically reserved for a small number of administrators because it provides unrestricted management of the project and its entire resource hierarchy.

Why this answer

The Owner role (roles/owner) in Google Cloud Platform includes all Editor permissions plus the ability to manage roles and permissions for a project, and to set up billing. It provides full control over all resources in the project, including the ability to grant access to others. This is the most powerful basic role available at the project level.

Exam trap

ACE often tests the distinction between basic roles and their permissions, and candidates may confuse 'Editor' with 'Owner' because both allow resource modification, but only Owner can manage IAM and billing.

How to eliminate wrong answers

Option A is wrong because the Editor role (roles/editor) grants permissions to create, modify, and delete most resources but does not include permissions to manage access control (IAM) or billing, so it lacks full control. Option C is wrong because the Viewer role (roles/viewer) only provides read-only access to resources and cannot make any changes. Option D is wrong because 'Admin' is not a basic role in GCP; while there are predefined roles with 'Admin' in the name (e.g., Compute Admin), they are scoped to specific services and do not grant full control over all resources in a project.

3
MCQmedium

An organization needs to separate development, staging, and production environments using the GCP resource hierarchy. Which approach is most effective?

A.Create folders for dev, staging, and prod under the organization, then place projects in each folder
B.Use labels on projects to denote environment, but keep all in one folder
C.Create separate projects for each environment without folders
D.Create a single project and use separate VPC networks per environment
AnswerA

Folders in the Google Cloud resource hierarchy allow you to organize projects under the organization node, and you can apply IAM policies and organization policies at the folder level, which are inherited by all projects within. This gives you a natural separation between dev, staging, and prod while enabling consistent controls, e.g., different approval workflows or network configurations. Placing projects in environment-specific folders is the standard best practice for multi-environment governance.

Why this answer

Folders under the organization node allow you to group projects by environment and apply IAM policies and organizational policies at the folder level, which are inherited by all projects within. This creates a clean separation of dev, staging, and prod while enabling centralized governance. It is the most effective use of the GCP resource hierarchy for environment isolation.

Exam trap

ACE often tests the misconception that labels or separate projects alone provide sufficient environment isolation, but the key is that folders enable policy inheritance and centralized control, which is the most effective approach.

How to eliminate wrong answers

Option B is wrong because labels are only for metadata and cannot enforce IAM or organizational policies; they do not provide access separation or policy inheritance. Option C is wrong because without folders, projects are directly under the organization, making it harder to apply environment-specific policies at scale and losing the hierarchical grouping. Option D is wrong because a single project cannot provide the strong isolation required for separate environments; VPC networks alone do not isolate IAM, billing, or quotas, and all resources share the same project-level policies.

4
MCQhard

An organization has multiple Google Cloud projects and wants to enforce a policy that all Compute Engine instances must use a specific set of approved machine types. Which tool should be used to implement this constraint?

A.Organization policies
B.IAM custom roles
C.VPC Service Controls
D.Cloud Scheduler
AnswerA

Organization policies apply constraints across all projects in a Google Cloud organisation hierarchy, restricting Compute Engine machine types centrally. This enforces the approved machine-type list across multiple projects, satisfying the stem's requirement for organisation-wide policy enforcement.

Why this answer

Organization policies in Google Cloud are constraints applied at the organization, folder, or project level that restrict how resources can be configured—including which machine types Compute Engine instances may use. The constraints/compute.restrictMachineTypes constraint directly enforces an approved machine-type list across all projects in scope. This is the purpose-built governance tool for the requirement.

Exam trap

ACE often tests the distinction between identity-based controls (IAM) and configuration-based controls (organization policies)—candidates pick IAM custom roles because they think restricting machine types is an access-control problem, when it is actually a resource-configuration constraint.

How to eliminate wrong answers

Option B is wrong because IAM custom roles control who can perform actions (permissions), not what configurations are allowed—they cannot restrict machine types. Option C is wrong because VPC Service Controls create security perimeters around Google Cloud services to prevent data exfiltration, not to constrain resource configuration attributes like machine types. Option D is wrong because Cloud Scheduler is a cron-style job scheduling service and has no policy enforcement capability whatsoever.

5
MCQeasy

An engineer needs to create a new GCP project using the Cloud SDK. They have already installed and initialized gcloud with a user account that has Billing Account Administrator and Project Creator roles. Which command creates the project 'my-new-project'?

A.gcloud config set project my-new-project
B.gcloud projects create my-new-project
C.gcloud alpha projects create my-new-project
D.gcloud init my-new-project
AnswerB

This is the canonical command for creating a new Google Cloud project via the CLI. It calls the Cloud Resource Manager projects.create API method, and requires the resourcemanager.projects.create permission (provided by the Project Creator IAM role). The command returns a project ID and number, and initially places the project in the 'ACTIVE' lifecycle state unless an organization policy restricts it. Use `--organization` or `--folder` flags to specify the parent resource.

Why this answer

The correct command is 'gcloud projects create my-new-project', which creates a new GCP project under the currently authenticated account. Since the user already has Project Creator and Billing Account Administrator roles, they have the necessary permissions to create the project and associate billing. The command is part of the stable gcloud projects command group.

Exam trap

ACE often tests whether candidates confuse configuration commands (gcloud config set project) with resource-creation commands (gcloud projects create), and whether they know that alpha/beta tracks are not required for standard project creation.

How to eliminate wrong answers

Option A is wrong because 'gcloud config set project' only changes the active project in the local configuration; it does not create a project and will fail if the project does not already exist. Option C is wrong because 'gcloud alpha projects create' is an alpha-track command that is not required for basic project creation and may have different or unstable behavior. Option D is wrong because 'gcloud init' is used to initialize the SDK configuration and authenticate, not to create a project with a specified name.

6
MCQmedium

An organization wants to manage GCP resources for multiple teams using a hierarchy of folders and projects. They need to apply a uniform policy that restricts the regions where VM instances can be created across all projects in a folder. Which approach should they use?

A.Apply an organization policy with the `compute.allowedExternalIpAccess` constraint
B.Apply an organization policy with the `compute.restrictResourceCreation` constraint
C.Set an IAM policy on the folder that denies compute.instances.create permission in disallowed regions
D.Use gcloud config set compute/region and enforce with a script
AnswerC

Applying a folder-level IAM deny policy that denies compute.instances.create with a condition on resource.location is the correct approach because IAM conditions are evaluated at access time against the requested resource's attributes. You can specify that the request is denied unless resource.location is one of the allowed regions, and this applies to all projects in the folder. Deny policies override any allow bindings chain-wide, providing deterministic enforcement that works for Console, CLI, and API calls.

Why this answer

The correct approach uses IAM conditions to restrict resource creation based on location. While organization policies with the 'gcp.resource-locations' constraint are the recommended method, option C is the only valid choice among the given options. IAM policies on the folder with conditions can effectively deny compute.instances.create permission in disallowed regions, enforcing uniform control across all projects in the folder.

Exam trap

Candidates may confuse organization policy constraints with IAM policies. While organization policies are designed for such restrictions, IAM conditions can also achieve the same result.

7
MCQmedium

You need to list all projects in your organization using the gcloud CLI. Which command is correct?

A.gcloud compute projects list
B.gcloud config list
C.gcloud projects list
D.gcloud resource-manager projects list
AnswerC

gcloud projects list is correct: it calls the Cloud Resource Manager API (projects.list) and returns all projects that your authenticated account has permission to view, including those from your organization if you have the appropriate IAM roles. It supports flags like --filter, --limit, and --format to narrow and shape the output. This is the standard, documented command for enumerating projects.

Why this answer

The correct command to list all projects in an organization is gcloud projects list. This command queries the Cloud Resource Manager API and returns projects the user has access to, optionally filtered by organization or folder. It is the standard way to enumerate projects via the gcloud CLI.

Exam trap

The trap is confusing the command groups: candidates might think 'compute' or 'resource-manager' prefixes are needed, but the correct top-level command is simply 'gcloud projects list'.

How to eliminate wrong answers

Option A is wrong because gcloud compute projects list is not a valid command; compute commands are for Compute Engine resources, not project listing. Option B is wrong because gcloud config list displays the current gcloud configuration (e.g., active account, project, region), not a list of projects. Option D is wrong because gcloud resource-manager projects list is not a valid command; the resource-manager command group does not have a 'projects list' subcommand.

8
Multi-Selectmedium

A developer wants to use Cloud Shell for managing GCP resources. Which three statements about Cloud Shell are true? (Choose THREE.)

Select 3 answers
A.It allows unlimited session duration without any timeout
B.It can be used only for projects that have billing enabled
C.It provides a web-based terminal in the GCP Console
D.It provides 5 GB of persistent disk storage in the user's home directory
E.It has gcloud, kubectl, and terraform pre-installed
AnswersC, D, E

Cloud Shell is a web-based terminal that launches directly from the Google Cloud Console, giving you authenticated command-line access to your GCP environment without needing to install the Google Cloud SDK locally. It automatically authenticates you using the same credentials as the console, and it also sets the current project so you can immediately run gcloud commands. This integration makes it the quickest way to test API calls, run kubectl against GKE clusters, or inspect resources while staying in the browser.

Why this answer

Option C is correct because Cloud Shell is a web-based terminal accessible directly from the Google Cloud Console, allowing users to run commands and manage GCP resources without installing local tools. Option D is correct because Cloud Shell provides 5 GB of persistent disk storage mounted at $HOME, which persists across sessions and is tied to the user, not the VM instance. Option E is correct because Cloud Shell images come pre-installed with common tools including gcloud CLI, kubectl, and terraform, so developers can immediately manage GCP resources and Kubernetes clusters.

Option A is not correct because Cloud Shell sessions have a timeout (typically 20 minutes of inactivity and a maximum session duration of 12 hours), so sessions are not unlimited. Option B is not correct because Cloud Shell can be used in projects without billing enabled, though some operations may require billing; Cloud Shell itself is free and available to any authenticated user.

Exam trap

The trap here is assuming Cloud Shell is a full VM with unlimited uptime and billing dependency — candidates often confuse its free, ephemeral nature with a persistent Compute Engine instance.

9
MCQmedium

A developer wants to authenticate to GCP from their local machine using their own user account to run gcloud commands that interact with a project. They have already installed the Cloud SDK. Which command should they use to authenticate with their Google account?

A.gcloud init
B.gcloud auth activate-service-account
C.gcloud auth login
D.gcloud auth application-default login
AnswerC

gcloud auth login is the correct command because it launches an OAuth 2.0 authorization flow, typically opening a browser where the developer signs in with their Google account and grants consent to GCP scopes. Upon successful authentication, it saves the resulting user credentials in the credentials directory and sets them as the active account for subsequent gcloud CLI operations. This is the standard, direct way for a human developer to authenticate the gcloud command-line tool with their personal or Google Workspace user identity from a local machine.

Why this answer

The 'gcloud auth login' command authenticates a user account with Google and stores credentials for use by gcloud CLI commands. It opens a browser window for OAuth 2.0 consent, and after successful authentication, the user's credentials are cached locally and used for subsequent gcloud commands that interact with GCP projects. This is the correct command for a developer authenticating with their own Google account from a local machine.

Exam trap

ACE often tests the distinction between user authentication for gcloud CLI and Application Default Credentials for code; the trap is selecting 'gcloud auth application-default login' because it sounds more 'correct' for development, when the question specifically asks about running gcloud commands.

How to eliminate wrong answers

Option A is wrong because 'gcloud init' initializes the Cloud SDK configuration — it sets up a configuration, selects a project, and may prompt for authentication, but it is not the dedicated authentication command and is used for initial setup rather than authenticating an existing installation. Option B is wrong because 'gcloud auth activate-service-account' authenticates using a service account key file, not a user's Google account, and is used for non-interactive automation. Option D is wrong because 'gcloud auth application-default login' sets up Application Default Credentials (ADC) for client libraries and code, not for gcloud CLI commands themselves — it is used when applications need to authenticate, not when the user runs gcloud commands.

10
Multi-Selectmedium

You are setting up a new GCP project for a microservices application. You need to select which APIs to enable. Which THREE APIs are likely required? (Choose 3)

Select 3 answers
A.storage.googleapis.com
B.cloudbuild.googleapis.com
C.container.googleapis.com
D.compute.googleapis.com
E.bigquery.googleapis.com
AnswersB, C, D

Cloud Build (cloudbuild.googleapis.com) is the managed CI/CD service used to compile source code and build container images. For microservices, each service is typically packaged as a separate container, and Cloud Build provides a reliable, serverless way to automate those builds via triggers and build steps. It integrates with Artifact Registry to store the resulting images, which are then deployed to GKE, making it a common and often essential part of a microservices deployment pipeline.

Why this answer

For a microservices application on Kubernetes, you need the Kubernetes Engine API (container.googleapis.com), and often the Cloud Build API (cloudbuild.googleapis.com) for CI/CD and Compute Engine API (compute.googleapis.com) as a dependency for GKE. Cloud Storage API is not necessarily required unless using Cloud Storage. BigQuery is for analytics.

11
MCQmedium

A company wants to set up a budget alert at 50% and 90% of their projected monthly spending. Which service should they use?

A.Cloud Billing budgets
B.Cost breakdown reports
C.Cloud Scheduler
D.Cloud Monitoring alerts
AnswerA

Cloud Billing budgets let you define a monthly amount and set threshold rules at percentages such as 50% and 90%, triggering email or Pub/Sub alerts. It is the only service that natively tracks projected spend against a budget.

Why this answer

Cloud Billing budgets allow you to set budget amounts and configure alert thresholds at specific percentages (e.g., 50% and 90%) of your projected or actual spending. When spending exceeds these thresholds, alerts are triggered via email or Pub/Sub notifications. This is the native service for budget monitoring and alerting in Google Cloud.

Exam trap

ACE often tests the difference between monitoring and alerting services; candidates may confuse Cloud Monitoring with Cloud Billing budgets, forgetting that budget alerts are a billing-specific feature.

How to eliminate wrong answers

Option B is wrong because cost breakdown reports provide visibility into spending but do not send proactive alerts at defined thresholds. Option C is wrong because Cloud Scheduler is a cron job service for scheduling tasks, not for monitoring budgets. Option D is wrong because Cloud Monitoring alerts are for system and application metrics, not for billing budgets; while you can create custom metrics for costs, it is not the intended or straightforward service for budget alerts.

12
MCQeasy

A new engineer needs to set up the gcloud CLI on their local machine and authenticate with a user account. Which command should they run after installing the SDK?

A.gcloud init
B.gcloud auth application-default login
C.gcloud config set account
D.gcloud auth login
AnswerA

gcloud init is the intended bootstrap command for a new user because it performs the entire initial setup in one interactive flow: authenticating your Google account via the browser, then prompting you to choose or create a default project and set a default compute region/zone. It writes the resulting credentials and configuration properties into the active gcloud configuration file, leaving your environment ready for immediate use. This one-command workflow is exactly why it's the recommended starting point on a fresh workstation.

Why this answer

The 'gcloud init' command is the standard way to initialize the gcloud CLI, authenticate with a user account, set the default project, and configure other initial settings. It walks the user through the authentication flow and sets up the local configuration for subsequent gcloud commands.

Exam trap

ACE often tests the confusion between 'gcloud init' (full initialization) and 'gcloud auth login' (authentication only) — candidates must know that 'gcloud init' is the correct first step after installation for interactive user setup.

How to eliminate wrong answers

Option B is wrong because 'gcloud auth application-default login' is used to obtain application default credentials for use by client libraries and applications, not for interactive user authentication of the gcloud CLI itself. Option C is wrong because 'gcloud config set account' only changes the active account in an already-initialized configuration — it does not perform authentication or initial setup. Option D is wrong because 'gcloud auth login' authenticates a user account but does not perform the full initialization (project selection, region/zone defaults) that 'gcloud init' provides.

13
MCQeasy

You are using Cloud Shell and need to access a file you created two weeks ago. What is the persistence behavior of Cloud Shell home directories?

A.Cloud Shell home directories are stored in Cloud Storage and are always available.
B.Cloud Shell home directories persist for 30 days after last use.
C.Cloud Shell home directories are temporary and are deleted after each session.
D.Cloud Shell home directories persist across sessions, with 5 GB of storage.
AnswerD

Cloud Shell provides each user with a persistent 5 GB home directory stored on a zonal persistent disk that is independent of the underlying compute instance. Because it is not tied to the VM's lifecycle, files you create remain available across all future Cloud Shell sessions, making it a reliable place to keep small scripts or configuration files.

Why this answer

Cloud Shell home directories are persistent across sessions and provide 5 GB of storage per user. This means files created in the home directory remain available even after the session ends, as long as the user's Cloud Shell environment is not deleted. The 5 GB limit is a key characteristic of Cloud Shell's persistent storage.

Exam trap

ACE often tests the specific persistence duration and storage limit of Cloud Shell home directories, and candidates may incorrectly assume they are temporary or have a different retention period.

How to eliminate wrong answers

Option A is wrong because while Cloud Shell home directories are backed by Cloud Storage, they are not 'always available' in the sense of being accessible without a Cloud Shell session; they are tied to the user's Cloud Shell environment. Option B is wrong because the persistence is not limited to 30 days after last use; the home directory persists until the user deletes it or the environment is reset. Option C is wrong because home directories are not temporary and are not deleted after each session; they persist across sessions.

14
MCQmedium

A company has multiple Google Cloud projects and wants to track costs by department. They have already applied labels to resources with key 'department'. What is the next step to view costs grouped by department?

A.Run gcloud billing accounts list and parse the output
B.Set up a budget alert with department labels
C.Enable billing export to BigQuery and run a query
D.Go to Billing > Reports and filter by 'department' label
AnswerD

The Cloud Billing Reports page provides a native console view of cost data and includes filtering by labels such as 'department'. Once you select the appropriate time range and filter by the 'department' label, the report dynamically groups costs by that label, giving you the required department-level breakdown instantly and without any additional configuration. This is the correct and most direct tool for this task.

Why this answer

Google Cloud Billing Reports natively supports grouping and filtering by resource labels, so once resources are labeled with the 'department' key, the next step is simply to open Billing > Reports and filter/group by that label. This provides an immediate, no-setup way to view cost breakdowns by department. No export or CLI parsing is required for this basic reporting need.

Exam trap

The trap here is assuming that viewing costs by label requires BigQuery export or a budget alert, when the built-in Billing Reports UI already supports label-based grouping with zero configuration.

How to eliminate wrong answers

Option A is wrong because 'gcloud billing accounts list' only enumerates billing accounts associated with the user — it returns account IDs and names, not cost data, and cannot group costs by label. Option B is wrong because budget alerts only notify when spending crosses thresholds; they do not produce grouped cost views by department. Option C is wrong because BigQuery billing export is an advanced analytics path that requires setup and is unnecessary when the built-in Reports UI already supports label filtering.

15
MCQmedium

You are a new associate cloud engineer at a company that uses Google Cloud. You have been asked to set up a new project for a development team. Your manager wants you to ensure that the project is created under the correct organization node and that the team can immediately start using Compute Engine. You have been granted the Project Creator role at the organization level. What should you do first?

A.Run `gcloud projects create PROJECT_ID --organization=ORGANIZATION_ID`.
B.Run `gcloud projects create PROJECT_ID` without specifying an organization.
C.Run `gcloud beta projects create PROJECT_ID --organization=ORGANIZATION_ID`.
D.Run `gcloud projects create PROJECT_ID --folder=FOLDER_ID`.
AnswerA

This command creates a new project under the specified organization. The Project Creator role allows you to create projects, and specifying the organization ensures it is placed correctly. After creation, you can grant the team the necessary IAM roles and enable the Compute Engine API.

Why this answer

The correct command is `gcloud projects create` with the `--organization` flag to ensure the project is created under the correct organization. This satisfies the manager's requirement. After creation, you would need to enable the Compute Engine API and grant appropriate IAM roles to the team.

Exam trap

The trap here is assuming that creating a project without specifying an organization will automatically place it correctly, but it may default to a different organization or fail if multiple exist.

16
MCQhard

Your organization wants to enforce that all Compute Engine instances are created only in us-central1 and europe-west1. You need to implement this constraint across all projects in the organization. What should you do?

A.Apply an organization policy with constraint gcp.resourceLocations to allow only us-central1 and europe-west1.
B.Use VPC Service Controls to restrict access to Compute Engine API from other regions.
C.Use labels to tag instances and run a script to delete non-compliant ones.
D.Create an IAM policy denying the compute.instances.create permission in all other regions.
AnswerA

The gcp.resourceLocations organization policy constraint is a list constraint that defines the exact set of Google Cloud locations where new resources, including Compute Engine instances, may be created. Setting it to allow only us-central1 and europe-west1 at the organization or folder level makes non-compliance impossible at creation time, since the API call itself is rejected. This is a preventive, centralized governance mechanism that is inheritable across projects, making it the correct solution for enforcing geographic restrictions.

Why this answer

The correct approach is to apply an organization policy with the constraint gcp.resourceLocations (also known as Location Restriction) at the organization level, specifying allowed locations us-central1 and europe-west1. This constraint is enforced by the Organization Policy Service and prevents the creation of Compute Engine instances (and other resources) outside the allowed regions, regardless of IAM permissions. It provides centralized, preventive control across all projects in the organization.

Exam trap

ACE often tests the misconception that IAM policies can enforce regional restrictions, but IAM does not support conditions based on the region of a resource being created; the correct tool is Organization Policy constraints like gcp.resourceLocations.

How to eliminate wrong answers

Option B is wrong because VPC Service Controls are designed to mitigate data exfiltration risks by defining service perimeters around resources, not to restrict the regions where Compute Engine instances can be created; they control API access based on network context, not resource location. Option C is wrong because using labels and a script to delete non-compliant instances is a reactive, detective control that does not prevent creation and can lead to unintended deletions; it also requires custom automation and is not enforced by GCP natively. Option D is wrong because IAM policies do not support conditions based on region for the compute.instances.create permission; IAM conditions can use resource attributes but not the region of the instance being created, so this approach is not feasible.

17
Multi-Selecthard

A startup wants to control costs across multiple GCP projects. They want to track spending by department and set budget alerts. Which THREE actions should they take?

Select 3 answers
A.Assign labels to resources indicating department
B.Use Cloud Monitoring to track costs
C.Enable billing export to BigQuery
D.Create separate billing accounts for each department
E.Set up a budget with threshold alerts in the billing account
AnswersA, C, E

Labels attach department metadata directly to resources, and GCP propagates them into billing exports, enabling cost breakdown by department. This satisfies the stem's requirement to track spending per department, forming the foundation for budget alerts filtered on that label dimension.

Why this answer

Option A is correct because labels (key/value pairs such as department:finance) applied to resources are propagated into billing data, allowing spend to be broken down and filtered by department in cost reports and exports. Option C is correct because enabling billing export to BigQuery writes detailed Cloud Billing data (including labels, project, service, and SKU) to a dataset, enabling granular, queryable cost analysis across multiple projects. Option E is correct because budgets are created at the billing-account level and can trigger threshold-based alerts (e.g., at 50%, 90%, 100% of a specified amount) via Cloud Monitoring notification channels, which is exactly how the startup would monitor spending.

Option B is not appropriate because Cloud Monitoring tracks metrics, logs, and uptime for resources, not billing costs; cost visibility comes from Cloud Billing reports, budgets, and BigQuery export. Option D is not appropriate because creating separate billing accounts per department adds administrative overhead and fragments payment and reporting rather than enabling cost tracking by department within a shared account.

Exam trap

The trap is selecting Cloud Monitoring for cost tracking because the name sounds cost-adjacent — candidates must remember GCP separates operational monitoring (Cloud Monitoring) from cost monitoring (Cloud Billing).

18
MCQhard

A company wants to grant a contractor read-only access to all Compute Engine instances in a specific project, but no other resources. Which IAM role should be assigned?

A.roles/compute.instanceAdmin.v1
B.roles/viewer
C.roles/compute.viewer
D.roles/iam.securityReviewer
AnswerC

This predefined role contains only read permissions for Compute Engine resources, including instances, disks, images, snapshots, instance templates, and usage metrics, and it allows you to see them in the Cloud Console without any write or administrative actions. It precisely matches the contractor's access need and nothing more, upholding the principle of least privilege. As the correct answer, it is the best fit for granting read-only access to Compute Engine resources only.

Why this answer

roles/compute.viewer is the correct choice because it grants read-only access to all Compute Engine resources, including instances, disks, and snapshots, within the project. It does not include permissions for other services like Cloud Storage or IAM, aligning with the principle of least privilege. This role is predefined by Google Cloud and is specifically designed for viewing Compute Engine resources without modification rights.

Exam trap

ACE often tests the distinction between project-level and service-specific roles, and candidates may incorrectly choose roles/viewer for its broad read-only access, forgetting that it grants access to all resources, not just Compute Engine.

How to eliminate wrong answers

Option A is wrong because roles/compute.instanceAdmin.v1 grants full control over Compute Engine instances, including create, delete, and modify permissions, which violates the read-only requirement. Option B is wrong because roles/viewer provides read-only access to all resources in the project, not just Compute Engine, thus granting excessive permissions. Option D is wrong because roles/iam.securityReviewer is for viewing IAM policies and audit logs, not for accessing Compute Engine instances.

19
MCQeasy

A new engineer wants to set up their local environment to interact with Google Cloud. Which command initializes the gcloud CLI and configures the project, region, and zone?

A.gcloud auth login
B.gcloud auth application-default login
C.gcloud init
D.gcloud config set project my-project
AnswerC

gcloud init is the correct command because it performs a complete guided initialization of the local gcloud environment: it authenticates using either a user account or service account, sets a default project, and optionally configures compute/region and compute/zone properties in a new or existing configuration. It also runs an initial diagnostic to verify the installation and, if needed, can re-initialize an existing configuration. This one command provides the foundational project and location context that other gcloud commands depend on.

Why this answer

The `gcloud init` command is the interactive setup wizard that authenticates the user, lets them select or create a Cloud project, and sets default compute region and zone in one flow. It writes these values into the active gcloud configuration so subsequent commands use them automatically. This is the canonical first-run command for a new engineer's workstation.

Exam trap

ACE often tests the distinction between authentication commands (`gcloud auth login`, `gcloud auth application-default login`) and the full initialization command (`gcloud init`), so candidates who see 'configure project, region, and zone' may wrongly pick an auth-only command.

How to eliminate wrong answers

Option A is wrong because `gcloud auth login` only obtains user credentials for the gcloud CLI and does not configure project, region, or zone. Option B is wrong because `gcloud auth application-default login` sets up Application Default Credentials for client libraries/SDKs, not the gcloud CLI's project/region/zone defaults. Option D is wrong because `gcloud config set project my-project` only sets a single property (the project) and does not authenticate or set region/zone, so it is a partial configuration step rather than initialization.

20
MCQhard

After creating a new GCP project, an engineer attempts to delete it using `gcloud projects delete PROJECT_ID` but receives an error. What is the most likely cause?

A.The project still has running resources (e.g., VM instances)
B.The IAM policy prevents deletion
C.The project ID is invalid
D.The project is linked to a billing account that must be disabled first
AnswerD

Before a GCP project can be deleted, its billing account attachment must be removed by disabling billing or unlinking the billing account. GCP will reject the deletion if the project is still linked to an active Cloud Billing account, returning an error such as 'Project is linked to a billing account'. You must disable the project's billing association first, then retry the deletion. This is the typical failure after creating a new project because billing is enabled by default.

Why this answer

A project cannot be deleted if it has a billing account attached. The billing account must be disabled (disassociated) first.

21
MCQmedium

You need to delete a GCP project, but the deletion fails with an error. What is the most likely cause?

A.The project has IAM policies attached
B.The project still has active resources such as Compute Engine instances
C.The project is in a folder
D.The project's billing account is still linked
AnswerD

The correct answer is that a linked billing account prevents project deletion. Google Cloud requires you to disable billing for a project before it can be deleted, because deletion finalizes cost responsibility and prevents accidental ongoing charges. The console will display an error such as 'Billing must be disabled' if the project is still linked to a billing account. You must detach the billing account or disable the project's billing, then initiate the deletion process.

Why this answer

GCP requires that billing be disabled before a project can be deleted. If billing is still active, deletion will fail.

22
MCQeasy

You need to install the Google Cloud SDK on a Linux machine. Which command should you use to add the Cloud SDK distribution URI as a package source?

A.curl https://sdk.cloud.google.com | bash
B.gcloud init
C.sudo apt-get install google-cloud-sdk
D.echo 'deb [signed-by=/usr/share/keyrings/cloud.google.gpg] https://packages.cloud.google.com/apt cloud-sdk main' | sudo tee -a /etc/apt/sources.list.d/google-cloud-sdk.list
AnswerD

This command correctly configures the official Cloud SDK apt repository on a Debian or Ubuntu system by appending a sources.list entry with the signed-by parameter pointing to the imported Google signing key at /usr/share/keyrings/cloud.google.gpg. Using signed-by binds the repository to that specific key instead of trusting the global apt keyring, which is the recommended security practice. After running this, you still need to run sudo apt-get update and sudo apt-get install google-cloud-sdk, but this repository definition is the essential correct foundation for the package-manager installation method.

Why this answer

The Cloud SDK installation guide for Linux uses echo to add the URI to /etc/apt/sources.list.d/google-cloud-sdk.list.

23
MCQmedium

An engineer needs to enable the Compute Engine API for a project using the gcloud command line. Which command should they run?

A.gcloud compute instances enable-api
B.gcloud services list --enabled
C.gcloud api enable compute
D.gcloud services enable compute.googleapis.com
AnswerD

This is the correct command to enable the Compute Engine API. `gcloud services enable compute.googleapis.com` tells the Service Usage API to enable the service in the current project. It uses the fully-qualified service name and is the standard gcloud method for this operation. After running it, you can create and manage Compute Engine instances via gcloud or the Console.

Why this answer

The `gcloud services enable` command is the correct way to enable APIs for a project, and `compute.googleapis.com` is the service name for the Compute Engine API. The full command `gcloud services enable compute.googleapis.com` enables the API at the project level, which is required before creating Compute Engine resources.

Exam trap

ACE often tests the exact gcloud command syntax, tempting candidates to invent plausible-sounding but invalid commands like `gcloud api enable` or `gcloud compute instances enable-api`.

How to eliminate wrong answers

Option A is wrong because `gcloud compute instances enable-api` is not a valid gcloud command — `gcloud compute instances` only supports subcommands like create, delete, list, and start/stop, not enable-api. Option B is wrong because `gcloud services list --enabled` lists currently enabled services but does not enable anything. Option C is wrong because `gcloud api enable compute` is not valid syntax — the correct command group is `gcloud services`, not `gcloud api`, and the service name must be the full API identifier (compute.googleapis.com).

24
Multi-Selectmedium

An engineer needs to enable the Cloud Build API and the Kubernetes Engine API for a project. Which TWO commands should they run?

Select 2 answers
A.gcloud services enable cloudbuild.googleapis.com
B.gcloud services enable container.googleapis.com
C.gcloud services enable compute.googleapis.com
D.gcloud services enable kubernetes-engine.googleapis.com
E.gcloud services enable cloudbuild.googleapis.com --project=my-project
AnswersA, B

Enabling cloudbuild.googleapis.com activates the Cloud Build service for the project, satisfying the requirement to enable the Cloud Build API. The paired command must enable container.googleapis.com for Kubernetes Engine, since each Google Cloud API is enabled individually by its own service name.

Why this answer

Option A is correct because `gcloud services enable cloudbuild.googleapis.com` enables the Cloud Build API using the configured project. Option B is correct because `gcloud services enable container.googleapis.com` enables the Kubernetes Engine API (service name `container.googleapis.com`). Option C is wrong because `compute.googleapis.com` is the Compute Engine API.

Option D is wrong because `kubernetes-engine.googleapis.com` is not the correct service name. Option E is wrong because `--project=my-project` targets a specific project named `my-project`, but the question does not provide that project ID; without this flag the command applies to the default configured project. Therefore E is not one of the two required commands.

Exam trap

ACE often tests exact service names and project scoping. Candidates may incorrectly choose kubernetes-engine.googleapis.com or a command with an explicit --project flag that assumes a specific project ID not given in the question.

25
MCQmedium

An engineer needs to enable the Compute Engine API for a project using the CLI. Which command should they run?

A.gcloud compute enable
B.gcloud services enable compute
C.gcloud api enable compute.googleapis.com
D.gcloud services enable compute.googleapis.com
AnswerD

'gcloud services enable compute.googleapis.com' is the correct command to enable the Compute Engine API for the active project. The 'gcloud services' command group interacts with the Service Usage API to manage service availability. This command uses the fully qualified service name 'compute.googleapis.com', which is required for successful enablement. You can also specify a project with the '--project' flag if the API should be enabled for a different project than the current one.

Why this answer

The correct command to enable a Google Cloud API for a project using the CLI is 'gcloud services enable compute.googleapis.com'. This command uses the 'gcloud services' command group, which manages API enablement, and requires the full service name (e.g., compute.googleapis.com). This is the standard and documented way to enable APIs.

Exam trap

ACE often tests the exact syntax of gcloud commands, and candidates may forget the '.googleapis.com' suffix or confuse 'gcloud services' with 'gcloud compute' or 'gcloud api'.

How to eliminate wrong answers

Option A is wrong because 'gcloud compute enable' is not a valid command; 'gcloud compute' manages Compute Engine resources, not API enablement. Option B is wrong because 'gcloud services enable compute' is missing the domain suffix '.googleapis.com', which is required to identify the service. Option C is wrong because 'gcloud api enable' is not a valid command group; the correct group is 'gcloud services'.

26
MCQeasy

Your organization has multiple Google Cloud projects. You want to separate development and production environments. Which resource hierarchy structure is recommended?

A.Create two separate organizations.
B.Use labels on projects to differentiate environments.
C.Use a single project with separate VPC networks.
D.Use folders under the organization node to separate dev and prod projects.
AnswerD

Folders sit beneath the organisation node and group projects, letting you apply separate IAM policies and billing to dev and prod. This isolates environments while retaining centralised organisation-level control, which placing projects directly under the organisation or in separate organisations would not achieve as cleanly.

Why this answer

Using folders under the organization node to separate dev and prod projects is the recommended approach because it aligns with Google Cloud's resource hierarchy, allowing centralized policy management and inheritance. Folders enable logical separation of environments while maintaining a single organization, which simplifies billing and IAM. This structure supports least privilege and environment isolation.

Exam trap

ACE often tests the misconception that labels or separate VPCs provide sufficient environment separation, when the correct answer is using folders for hierarchical policy inheritance.

How to eliminate wrong answers

Option A is wrong because creating two separate organizations is not recommended; it complicates management and billing, and is typically not feasible for a single company. Option B is wrong because labels are for metadata and cannot enforce separation or policy inheritance like folders. Option C is wrong because using a single project with separate VPC networks does not provide sufficient isolation for dev and prod environments, as projects are the primary boundary for resources and IAM.

27
Multi-Selectmedium

An administrator needs to create a custom IAM role that allows listing projects and viewing billing accounts. Which TWO permissions should be included?

Select 2 answers
A.billing.accounts.list
B.billing.accounts.create
C.resourcemanager.projects.create
D.resourcemanager.projects.list
E.resourcemanager.projects.delete
AnswersA, D

Correct. The billing.accounts.list permission is the specific IAM permission that allows a principal to enumerate the billing accounts they can access. Including this permission in the custom role is essential and sufficient for the read-only task of listing billing accounts; without it, any API call or console view that attempts to list billing accounts will fail with a permission denied error.

Why this answer

Option A, billing.accounts.list, is correct because viewing billing accounts requires the Cloud Billing permission billing.accounts.list, which allows the role to enumerate the billing accounts the principal has access to. Option D, resourcemanager.projects.list, is correct because listing projects is governed by the Resource Manager permission resourcemanager.projects.list, which permits reading the set of projects visible to the caller. Option B, billing.accounts.create, is not needed since the task only requires viewing, not creating, billing accounts.

Option C, resourcemanager.projects.create, and Option E, resourcemanager.projects.delete, are also unnecessary because creating or deleting projects is outside the stated scope of listing projects and viewing billing accounts.

Exam trap

ACE often tests least-privilege permission selection — the trap is including create or delete permissions because they share the same resource prefix (billing.accounts.* or resourcemanager.projects.*), when only the .list verb matches the stated read-only requirement.

28
MCQmedium

An administrator wants to set up a budget alert that triggers at 50%, 90%, and 100% of the monthly spending limit. What is the correct way to configure this?

A.Create a budget with a single threshold of 100% and rely on Cloud Monitoring
B.Use Cloud Billing reports to manually track
C.Create three separate budgets, each with a single threshold
D.Create one budget with three threshold rules: 50%, 90%, 100%
AnswerD

Creating one budget with three threshold rules is the recommended and most efficient approach because Cloud Billing budgets natively support multiple thresholds—each can be a percentage of the budget amount and trigger an alert independently. For example, you can set actual-cost thresholds at 50%, 90%, and 100%, and optionally add forecasted-cost thresholds as well. This gives you the desired notification at each stage without duplicating budget resources.

Why this answer

Budget alerts can have multiple threshold rules with different percentages. You can create a single budget with three threshold rules.

29
Multi-Selecthard

An engineer needs to choose a location for a new GCP project's resources to maximize availability and minimize latency for users in Europe and Asia. Which three actions should they take? (Choose THREE)

Select 3 answers
A.Use a global load balancer to distribute traffic
B.Set the project default region to us-central1
C.Deploy resources in europe-west1 and asia-east1
D.Use a single zone in europe-west1 for simplicity
E.Enable Cloud CDN to cache content at edge locations
AnswersA, C, E

Global external HTTPS load balancing leverages a single anycast IP address and Google's global backbone to forward each user request to the optimal backend based on latency and health. It performs traffic distribution at L7 to the nearest available region, allowing active/active serving across multiple regions without DNS round-robin. This is the standard control plane that unifies multi-region deployments into one global endpoint.

Why this answer

Option A is correct because a global external Application Load Balancer (or global external proxy Network Load Balancer) uses Google's global anycast edge network to route users to the closest healthy backend, reducing latency and improving availability across Europe and Asia. Option C is correct because deploying resources in multiple regions such as europe-west1 and asia-east1 places compute and data physically near European and Asian users, and multi-region deployment protects against regional failures. Option E is correct because Cloud CDN caches content at Google edge points of presence (over 100+ locations), serving cached responses from the nearest edge to further cut latency for static and cacheable content.

Option B is not appropriate because setting the default region to us-central1 would place resources in North America, far from the target European and Asian users, increasing latency. Option D is not appropriate because a single zone in europe-west1 creates a single point of failure and does not serve Asian users with low latency, contradicting the availability and latency goals.

Exam trap

The trap is choosing a single region or single zone for 'simplicity' — the exam rewards multi-region design for global user bases, and single-zone answers are almost always wrong when availability is a stated goal.

30
MCQeasy

An organization wants to separate its development and production environments using Google Cloud resource hierarchy. What is the recommended approach?

A.Create a single project and use separate VPC networks for dev and prod.
B.Create two separate organizations, one for dev and one for prod.
C.Create two projects under the same folder and use labels to differentiate dev and prod.
D.Create two folders under the organization node, one for dev and one for prod.
AnswerD

Folders beneath the organisation node let you apply separate IAM policies, quotas and billing controls to dev and prod, with projects nested inside each. This isolates environments while retaining centralised organisation-level governance, which is Google's recommended hierarchy for environment separation.

Why this answer

Google Cloud resource hierarchy is Organization > Folders > Projects > Resources. Creating two folders under the organization node — one for dev and one for prod — is the recommended way to separate environments because IAM policies and organization policies applied at the folder level are inherited by all projects beneath them. This provides clean isolation and centralized governance without duplicating the organization.

Exam trap

ACE often tests whether candidates know that folders — not projects, VPCs, or labels — are the recommended resource-hierarchy boundary for separating environments.

How to eliminate wrong answers

Option A is wrong because a single project with separate VPCs does not provide billing, IAM, or policy isolation between environments and is not a recommended separation boundary. Option B is wrong because an organization maps to a single identity domain (Cloud Identity/Workspace), so creating two organizations is impractical and breaks centralized administration. Option C is wrong because two projects under the same folder share inherited policies and using labels for environment separation is a tagging convention, not a security boundary.

31
Multi-Selectmedium

A DevOps engineer wants to set up budget alerts for a GCP project so that the finance team is notified when costs reach 50% and 90% of the budget. Which two configurations are required? (Choose TWO.)

Select 2 answers
A.Enable billing export to BigQuery
B.Create a budget in the Cloud Billing console
C.Set up a Cloud Function to monitor billing
D.Configure alert thresholds at 50% and 90%
E.Assign the roles/billing.admin IAM role to the finance team
AnswersB, D

Creating a budget in the Cloud Billing console is the foundational action that enables all budget alerting. You define the total budget amount, optionally scope it to specific projects, folders, or billing accounts, and then attach alert threshold rules. Without an actual budget object, there is nothing to trigger a notification, so this is the non-negotiable first step in the workflow.

Why this answer

Option B is correct because a Cloud Billing budget must first be created in the Cloud Billing console (or via the Billing Budgets API) before any cost-based notifications can be triggered; the budget defines the scope (project, folder, or billing account) and the amount against which spend is measured. Option D is correct because within that budget you must configure alert thresholds — setting them at 50% and 90% of the budget amount — which causes GCP to send email notifications (to billing admins and users, or to a Pub/Sub topic) when actual or forecasted spend crosses those percentages. Option A is not required: BigQuery billing export is only needed for detailed cost analysis and custom reporting, not for standard budget alerts.

Option C is not required because budget alerts are a native Cloud Billing feature and do not need a Cloud Function to poll or monitor costs. Option E is not required because the roles/billing.admin role grants broad billing account administration, whereas budget alert recipients are configured through the budget's notification settings rather than by granting that IAM role.

Exam trap

ACE often tests whether candidates over-engineer the solution by adding BigQuery export or Cloud Functions, when the question only requires the two native steps: create the budget and set the thresholds.

32
MCQeasy

Which gcloud command is used to set the default project for a configuration profile?

A.gcloud init
B.gcloud config set project
C.gcloud projects set
D.gcloud projects list
AnswerB

gcloud config set project PROJECT_ID is the correct command because it updates the core/project property in the active gcloud configuration. This directly sets the default project used by subsequent gcloud commands when no --project flag or CLOUDSDK_CORE_PROJECT environment variable is provided. It is the standard, non-interactive method to change the current default project within a given configuration.

Why this answer

The command `gcloud config set project` is used to set the default project for the active configuration profile. It updates the `core/project` property in the active configuration, so subsequent gcloud commands use that project unless overridden. This is the standard way to change the default project without reinitializing the entire configuration.

Exam trap

ACE often tests the distinction between commands that initialize or list resources versus those that set configuration properties, causing candidates to confuse `gcloud init` with `gcloud config set project`.

How to eliminate wrong answers

Option A is wrong because `gcloud init` is an interactive command that initializes or reinitializes a configuration, and while it can set a default project, it is not the specific command used solely to set the default project. Option C is wrong because `gcloud projects set` does not exist; the correct command structure is `gcloud config set project`. Option D is wrong because `gcloud projects list` lists projects but does not set a default project.

33
MCQmedium

An organization wants to enforce a policy that disables the creation of VMs with external IPs across all projects. Which resource hierarchy level should the policy be attached to for maximum coverage?

A.Project
B.Resource (VM)
C.Organization
D.Folder
AnswerC

The organization node is the root of the GCP resource hierarchy, and it is the correct place to attach an organization-wide policy. Any IAM role binding or organization policy constraint set at this level is inherited by every folder, project, and resource in the hierarchy, thereby ensuring the policy is enforced across all projects while also applying automatically to any future projects created under the organization.

Why this answer

To enforce a policy across all projects, the policy must be attached at the highest level in the resource hierarchy: the organization. Organization policies are inherited by all descendant resources (folders, projects, and VMs), ensuring uniform enforcement. Attaching at lower levels would not cover all projects unless applied individually, which is inefficient and error-prone.

Exam trap

ACE often tests the resource hierarchy and policy inheritance, and candidates may incorrectly choose folder or project level, forgetting that only organization-level ensures maximum coverage.

How to eliminate wrong answers

Option A is wrong because a project-level policy only applies to that specific project, not all projects in the organization. Option B is wrong because attaching a policy to a resource (VM) is not supported for organization policies; policies are set at organization, folder, or project levels. Option D is wrong because a folder-level policy only applies to projects within that folder, not to all projects across the organization, leaving other folders unaffected.

34
Multi-Selectmedium

Your company has a production project and a development project. You want to ensure that no one can delete the production project accidentally. Which TWO actions should you take? (Choose 2)

Select 2 answers
A.Apply an organization policy constraint that blocks project deletion.
B.Set a deletion protection policy on the project.
C.Set a budget alert at 100% of projected spend.
D.Remove the Owner role from all users and grant only Editor.
E.Add a label to the project indicating it is production.
AnswersA, B

Organization policy constraints are centralized guardrails evaluated by Google Cloud Resource Manager before IAM. Applying a boolean constraint such as `constraints/resourcemanager.projectDelete` at the organization or folder level explicitly denies the `resourcemanager.projects.delete` action for every principal, overriding project-level IAM roles. This makes it an authoritative, non-bypassable control that prevents a production project from being deleted from any console or API path.

Why this answer

To prevent accidental deletion, you can set a deletion protection policy at the project level. Additionally, using an organization policy constraint 'constraints/resourcemanager.projectDelete' at the folder or organization level can block deletion. Labels don't prevent deletion.

Removing the Owner role from all users would break management. Budget alerts don't prevent deletion.

35
Multi-Selectmedium

An engineer is setting up a new GCP project for a containerized application. They need to enable the required APIs. Which TWO APIs must be enabled to deploy and manage a Kubernetes cluster and build container images?

Select 2 answers
A.compute.googleapis.com
B.bigquery.googleapis.com
C.cloudbuild.googleapis.com
D.container.googleapis.com
E.cloudfunctions.googleapis.com
AnswersC, D

Cloud Build is Google Cloud's CI/CD service that can compile source code and build Docker container images. If the engineer's containerized application is built from a repository, enabling cloudbuild.googleapis.com is required before Cloud Build can push built images to Container Registry or Artifact Registry. Thus, for a project that automates image creation for GKE, this API is a correct and necessary dependency.

Why this answer

Kubernetes Engine API and Cloud Build API are needed for cluster management and building images.

36
Multi-Selectmedium

You need to view the current gcloud configuration settings, including the active account, project, and compute region. Which TWO commands can you use? (Choose two.)

Select 2 answers
A.gcloud config list
B.gcloud config describe
C.gcloud projects list
D.gcloud auth list
E.gcloud info
AnswersA, E

Running `gcloud config list` displays all the active property settings in your current gcloud configuration, such as account, project, and compute region/zone, in a clean key=value format. You can use `gcloud config list --all` to view every settable property, including those with unset defaults. This is the standard, most direct way to inspect your working configuration.

Why this answer

gcloud config list displays all configuration properties. gcloud info provides detailed information, including configuration.

37
MCQeasy

Which of the following is true about Cloud Shell?

A.Cloud Shell has 5 GB of persistent home directory storage.
B.Cloud Shell requires installation of gcloud and kubectl manually.
C.Cloud Shell only supports the gcloud CLI, not kubectl.
D.Cloud Shell provides a persistent VM that can run for hours.
AnswerA

Cloud Shell provides a temporary, ephemeral VM, but your home directory is backed by a persistent 5 GB disk in Google-managed storage. That 5 GB is the permanent part of the environment — it survives session restarts, VM recycling, and timeouts. This means any files you save under $HOME, including SSH keys, configuration files, and scripts, remain available across all future Cloud Shell sessions, while the compute instance itself is recreated as needed.

Why this answer

Cloud Shell provides a persistent 5 GB home directory ($HOME) that survives across sessions, so files stored there are retained even after the VM is recycled. This is a core feature of Cloud Shell that distinguishes it from a purely ephemeral terminal. The gcloud CLI, kubectl, and many other tools are pre-installed and pre-authenticated, so no manual setup is required.

Exam trap

The trap here is confusing Cloud Shell's persistent home directory storage with a persistent VM — candidates often assume the whole environment is durable, when only the 5 GB $HOME is.

How to eliminate wrong answers

Option B is wrong because Cloud Shell comes with gcloud, kubectl, and other tools pre-installed and pre-authenticated — no manual installation is needed. Option C is wrong because Cloud Shell supports kubectl (and many other CLIs) out of the box, not just gcloud. Option D is wrong because Cloud Shell is an ephemeral VM that is terminated after a period of inactivity (typically 20 minutes of no use, with a maximum session of 12 hours), not a persistent long-running VM.

38
MCQmedium

A company wants to track and forecast GCP spending across different departments. They have already set up labels on resources to indicate the department. Which additional step should they take to analyze costs by department in BigQuery?

A.Enable billing export to BigQuery in the Cloud Billing console
B.Use the Cloud Billing API to programmatically fetch cost data and write it to BigQuery
C.Run a scheduled query in BigQuery that calls the Cloud Billing API
D.Create a Cloud Function that captures billing events and inserts them into BigQuery
AnswerA

Enabling billing export to BigQuery in the Cloud Billing console is the native, fully managed integration for this use case. It automatically creates a set of BigQuery tables (e.g., gcp_billing_export_resource_v1) that contain detailed line items including cost, usage, labels, and resource hierarchy, updated on an ongoing basis. This export requires no custom code and provides the historical, labelled data needed to track and forecast GCP spending across departments using standard SQL and BI tools.

Why this answer

Enabling billing export to BigQuery in the Cloud Billing console is the native, supported mechanism that streams detailed cost and usage data — including labels — into a BigQuery dataset. Once enabled, department labels are available as columns, allowing cost analysis and forecasting by department. This is the standard first step before any BigQuery-based cost reporting.

Exam trap

ACE often tests whether candidates know the native billing export feature versus building custom pipelines, so the trap is selecting API-based or Cloud Function approaches when the console export is the correct, supported method.

How to eliminate wrong answers

Option B is wrong because the Cloud Billing API does not provide a direct write-to-BigQuery path; it returns cost data that you would have to transform and load yourself, which is unnecessary when native export exists. Option C is wrong because BigQuery scheduled queries cannot call the Cloud Billing API to ingest data; they only query existing datasets. Option D is wrong because Cloud Functions cannot capture billing events in real time for cost data; billing data is not event-streamed in that manner.

39
MCQmedium

You are managing a project and need to create a custom IAM role that allows only the permissions compute.instances.list and compute.instances.get. What is the correct way to create this role using gcloud?

A.gcloud iam service-accounts create viewer --permissions="compute.instances.list,compute.instances.get"
B.gcloud iam roles create viewer --organization=123456 --permissions="compute.instances.*"
C.gcloud iam roles create viewer --project=my-project --permissions="compute.instances.list,compute.instances.get"
D.gcloud iam custom-roles create viewer --project=my-project --permissions='compute.instances.list,compute.instances.get'
AnswerC

This is the correct command: `gcloud iam roles create` creates a custom role scoped to the specified project, and the `--permissions` flag explicitly lists the two required read-only permissions. Using specific permission names without wildcards enforces least privilege and aligns with IAM's requirement for fully qualified permission identifiers. The resulting role can then be bound to users or groups with `gcloud projects add-iam-policy-binding`.

Why this answer

The correct command to create a custom IAM role with specific permissions is 'gcloud iam roles create' with the --project flag and a comma-separated list of permissions. This creates a project-level custom role with exactly the permissions specified. The syntax matches the gcloud iam roles create command structure.

Exam trap

ACE often tests the exact gcloud command syntax for creating custom roles, and candidates may confuse it with service account creation or use incorrect command names like 'custom-roles'.

How to eliminate wrong answers

Option A is wrong because 'gcloud iam service-accounts create' creates a service account, not a custom role, and does not accept a --permissions flag. Option B is wrong because it uses a wildcard 'compute.instances.*' which grants more permissions than intended, and it specifies an organization instead of a project, which is not required for a project-level custom role. Option D is wrong because the command 'gcloud iam custom-roles create' does not exist; the correct command is 'gcloud iam roles create'.

40
MCQmedium

An engineer is setting up Cloud Shell for the first time. They notice that their home directory persists across sessions. How much storage is allocated to the home directory in Cloud Shell?

A.10 GB
B.1 GB
C.20 GB
D.5 GB
AnswerD

Correct. Cloud Shell provisions a 5 GB persistent home directory, mounted at $HOME, that survives between sessions. This is the documented, fixed quota for free Cloud Shell usage, regardless of session time or usage patterns.

Why this answer

Google Cloud Shell provides 5 GB of persistent storage for the home directory, which is mounted across sessions so files survive VM recycling. This persistent disk is separate from the ephemeral boot disk that hosts the Cloud Shell VM itself. The 5 GB limit is the documented allocation for the $HOME directory.

Exam trap

ACE often tests exact quota values, and candidates frequently guess a larger round number (10 or 20 GB) instead of the documented 5 GB Cloud Shell home directory allocation.

How to eliminate wrong answers

Option A is wrong because 10 GB is not the documented Cloud Shell home directory allocation; it may be confused with other GCP free-tier storage quotas. Option B is wrong because 1 GB is far too small and does not match the Cloud Shell persistent disk size. Option C is wrong because 20 GB exceeds the documented Cloud Shell home directory quota and may be confused with persistent disk sizes on Compute Engine.

41
MCQmedium

An engineer wants to authenticate to Google Cloud using their own user credentials and also set up application default credentials for a local development environment. Which sequence of gcloud auth commands should they use?

A.gcloud auth login then gcloud auth application-default login
B.gcloud auth application-default login then gcloud auth login
C.gcloud init then gcloud auth login
D.gcloud auth configure-docker then gcloud auth login
AnswerA

This is the correct setup sequence for local development. First, `gcloud auth login` authenticates your user account and stores credentials for gcloud CLI commands in the user's config directory. Then, `gcloud auth application-default login` creates the `application_default_credentials.json` file, which allows Google Cloud client libraries to discover credentials via Application Default Credentials. Having both ensures gcloud and code-based SDKs use the same identity.

Why this answer

The correct sequence is `gcloud auth login` first to authenticate the user's own credentials for gcloud CLI operations, then `gcloud auth application-default login` to set up Application Default Credentials (ADC) that client libraries and local apps use. This order ensures the user identity is established before ADC is configured.

Exam trap

ACE often tests the distinction between user authentication (gcloud auth login) and application default credentials (gcloud auth application-default login) — candidates assume they are the same or that order doesn't matter, but the question specifically tests the correct sequence and purpose.

How to eliminate wrong answers

Option B is wrong because reversing the order does not break anything functionally, but the question asks for the sequence that authenticates user credentials first and then sets up ADC — the standard documented order is login then ADC. Option C is wrong because `gcloud init` is for initializing a configuration (project, region, account) and does not set up ADC. Option D is wrong because `gcloud auth configure-docker` configures Docker credential helpers for Artifact Registry, unrelated to ADC.

42
MCQhard

A team is using gcloud configurations to manage multiple projects. They want to create a new configuration for a production project. How can they achieve this?

A.Run 'gcloud init' and select 'Create a new configuration'
B.Run 'gcloud config configurations create prod' then 'gcloud config set project prod-project'
C.Run 'gcloud config set project prod-project' with a flag to create new config
D.Edit the gcloud config file manually
AnswerB

The correct method is to first run gcloud config configurations create prod, which generates a new empty named configuration and automatically activates it. With the prod configuration active, gcloud config set project prod-project then sets the project property for that configuration, providing a clean, isolated environment for managing the prod project.

Why this answer

The correct command sequence is 'gcloud config configurations create prod' followed by 'gcloud config set project prod-project'. This creates a new named configuration and sets the active project within it. The 'gcloud config configurations create' command is specifically designed for this purpose.

Exam trap

ACE often tests the exact syntax for creating and managing gcloud configurations, and candidates may confuse 'gcloud init' with 'gcloud config configurations create' or assume that setting a project automatically creates a new configuration.

How to eliminate wrong answers

Option A is wrong because 'gcloud init' is an interactive command that initializes the gcloud CLI and can create a new configuration, but it is not the explicit command to create a named configuration for a specific project; it is more for initial setup. Option C is wrong because 'gcloud config set project' does not have a flag to create a new configuration; it only sets the project property in the current configuration. Option D is wrong because manually editing the gcloud config file is not recommended and error-prone; the CLI provides commands for configuration management.

43
MCQeasy

A developer wants to use gcloud CLI with application default credentials (ADC) to authenticate to Google APIs from their local machine. Which command should they run first?

A.gcloud auth login
B.gcloud init
C.gcloud auth application-default login
D.gcloud config set auth/application_default true
AnswerC

gcloud auth application-default login is the correct command because it explicitly generates Application Default Credentials, storing them in the standard location (typically ~/.config/gcloud/application_default_credentials.json). These credentials are then picked up automatically by Google Cloud client libraries when no explicit service account key is supplied, enabling local development to use your user account's permissions as ADC.

Why this answer

Application Default Credentials (ADC) are separate from the user credentials stored by 'gcloud auth login'. To set up ADC for local development, the developer must run 'gcloud auth application-default login', which writes credentials to a well-known location (e.g., ~/.config/gcloud/application_default_credentials.json) that client libraries automatically discover. This is the first step required before using ADC with Google APIs locally.

Exam trap

The trap is confusing 'gcloud auth login' (CLI user auth) with 'gcloud auth application-default login' (ADC for client libraries) — candidates pick the more familiar 'gcloud auth login' and wonder why their code cannot authenticate.

How to eliminate wrong answers

Option A is wrong because 'gcloud auth login' authenticates the gcloud CLI itself for interactive commands, but it does not create ADC — client libraries using ADC will not find those credentials. Option B is wrong because 'gcloud init' is a setup wizard that configures gcloud (account, project, region), but it does not generate ADC files for application code. Option D is wrong because 'gcloud config set auth/application_default true' is not a real configuration property — there is no such flag; ADC is established by running the login command, not by setting a config value.

44
MCQhard

A team is using Cloud Shell to manage resources. They notice that their home directory is persistent across sessions, but they want to ensure that configuration files and scripts are also available after they stop and restart Cloud Shell. What should they do?

A.Use gcloud config configurations and save scripts in a Cloud Storage bucket
B.Create a startup script that runs every time Cloud Shell starts
C.Store files in /tmp
D.Store files in the home directory (~)
AnswerD

Cloud Shell automatically mounts a persistent home directory at ~ on a small but durable disk that is attached to your user profile across sessions. Any files, Bash scripts, or gcloud configuration files you place in ~ remain available even when the underlying VM is replaced. This is the intended and simplest way to preserve your work in Cloud Shell, and it also houses the .config directories used by gcloud.

Why this answer

Cloud Shell provides a persistent 5 GB home directory ($HOME) that survives across sessions, so storing configuration files and scripts in ~ ensures they are available after stopping and restarting Cloud Shell. The home directory is backed by a persistent disk that is reattached to each new ephemeral VM instance. This is the simplest and intended mechanism for persistence.

Exam trap

ACE often tests the misconception that Cloud Shell is fully ephemeral, causing candidates to overlook that the home directory is persistent and to choose unnecessary workarounds like startup scripts or buckets.

How to eliminate wrong answers

Option A is wrong because while gcloud config configurations and Cloud Storage buckets are valid for managing configs and storing scripts, they require extra steps to sync and are not the direct answer to 'ensure files are available' — the home directory already provides this natively. Option B is wrong because a startup script runs on each boot but does not itself persist files; it would need a source of truth (like a bucket) to restore them, which is more complex than just using ~. Option C is wrong because /tmp is ephemeral and is wiped when the Cloud Shell instance is recycled, so files there will not survive a restart.

45
MCQhard

An organization has multiple GCP projects and wants to centralize billing analysis across all projects. They need to export detailed billing data (e.g., cost per SKU per project) to a BigQuery dataset. Which billing export option should they configure?

A.Export to CSV to Cloud Storage
B.Export to Cloud Billing report
C.Export to a Pub/Sub topic
D.Export detailed billing data to BigQuery
AnswerD

Exporting detailed billing data to BigQuery is the correct approach because it automatically creates and maintains tables like `gcp_billing_export_v1` within your project's BigQuery dataset. Every project that shares the billing account is included, and you can immediately run SQL queries to analyze costs by project, service, SKU, or label, as well as build dashboards and scheduled queries. This export is the official Google-recommended method for centrally managing and analyzing billing information across an organization.

Why this answer

To centralize billing analysis across multiple projects with detailed cost-per-SKU-per-project data, you configure the detailed billing data export to BigQuery. This export writes granular cost and usage data (including SKU, project, labels, and credits) into a BigQuery dataset that can be queried with SQL for cross-project analysis.

Exam trap

ACE often tests whether candidates confuse the BigQuery detailed billing export (for granular cost analysis) with Pub/Sub budget alerts (for real-time notifications) or CSV exports (which are not the native detailed billing export).

How to eliminate wrong answers

Option A is wrong because CSV export to Cloud Storage is not a native detailed billing export option and does not provide the queryable, granular dataset needed for centralized analysis. Option B is wrong because the Cloud Billing report is a console visualization, not an export mechanism, and cannot be queried across projects programmatically. Option C is wrong because exporting to Pub/Sub is for real-time budget alert notifications, not for detailed cost-per-SKU data analysis.

46
Multi-Selecthard

An engineer needs to create a new project and set up the environment. They are using the gcloud command-line tool. Which two commands are required to create a project and link it to a billing account? (Choose TWO.)

Select 2 answers
A.gcloud billing projects link PROJECT_ID --billing-account=BILLING_ACCOUNT_ID
B.gcloud projects create PROJECT_ID
C.gcloud alpha billing accounts create
D.gcloud services enable cloudbilling.googleapis.com
E.gcloud config set project PROJECT_ID
AnswersA, B

This command explicitly associates a specified project with a specified billing account. It is the standard gcloud operation for setting up the billing relationship after project creation, enabling the project to consume paid services. The command requires both the project ID and the billing account ID as arguments, and it performs an API call to the Cloud Billing API. Once run, the project's billing is active and can be used for resource consumption.

Why this answer

Option B, `gcloud projects create PROJECT_ID`, is correct because it is the gcloud command that actually creates a new Google Cloud project under the current account or specified organization/folder, returning the new PROJECT_ID. Option A, `gcloud billing projects link PROJECT_ID --billing-account=BILLING_ACCOUNT_ID`, is correct because it is the command that associates an existing billing account with the newly created project, which is required to enable billing for that project. Option C, `gcloud alpha billing accounts create`, is not needed here because it creates a brand-new billing account rather than linking an existing one to a project.

Option D, `gcloud services enable cloudbilling.googleapis.com`, is unnecessary since the Cloud Billing API is enabled by default and enabling it is not part of the create-and-link workflow. Option E, `gcloud config set project PROJECT_ID`, only sets the default project for the current gcloud configuration and does not create a project or link billing.

Exam trap

The trap is confusing project context-setting ('gcloud config set project') with project creation and billing linkage — candidates pick the config command thinking it creates the project.

47
Multi-Selectmedium

A company wants to manage multiple Google Cloud projects and enforce consistent security policies across all of them. Which TWO resources should they use? (Choose two.)

Select 2 answers
A.Cloud Audit Logs
B.Organization policies
C.Shared VPC
D.Folders
E.Labels
AnswersB, D

Organization policies — The Organization Policy service is the correct mechanism for centrally governing multiple projects. It applies constraints like `compute.vmExternalIpAccess` or `iam.disableServiceAccountKeyCreation` at the organization, folder, or project level, and these constraints are inherited by all descendant resources. This provides a hierarchy-wide, enforceable governance layer that either permits or denies certain API calls before they execute. It directly meets the requirement to manage and enforce rules across all projects in the organization.

Why this answer

Organization policies (B) are correct because they let you centrally define and enforce constraints on GCP resources—such as restricting allowed locations, disabling service account key creation, or enforcing uniform bucket-level access—and these constraints are inherited down the resource hierarchy, giving consistent security policy across many projects. Folders (D) are correct because they provide the hierarchical grouping layer beneath the organization and above projects, so you can organize projects into logical groups and apply IAM and organization policies at the folder level, with inheritance ensuring every project under the folder receives the same controls. Together, folders supply the grouping structure and organization policies supply the enforced constraints, which is exactly what managing multiple projects with consistent security requires.

Cloud Audit Logs (A) only record and surface activity for auditing and monitoring; they do not enforce policy. Shared VPC (C) centralizes network administration by letting projects share subnets, but it addresses network topology rather than broad security policy enforcement. Labels (E) are metadata for organizing, filtering, and billing reporting, and they carry no enforcement or policy capability.

Exam trap

The trap is confusing visibility tools (Audit Logs) or networking tools (Shared VPC) with governance mechanisms — candidates pick Shared VPC thinking 'shared' means centralized control, but it's about network sharing, not policy.

48
MCQhard

Your company wants to track costs per department. Each department has its own project. You need to set up a budget alert in the billing account for each project. What is the most efficient approach?

A.Use Billing Export to BigQuery and create custom alerts using Cloud Monitoring.
B.Create one budget per project by selecting the project in the 'Scoped to' field.
C.Create a budget for each project by manually enabling billing for each project.
D.Create a single budget for the entire billing account and rely on labels.
AnswerB

Creating one budget per project and setting the 'Scoped to' field to that project is the correct, efficient approach. In the Google Cloud console, budgets are created at the billing account level but can be scoped to a specific project, which allows the budget amount and alert thresholds to apply exclusively to that project's costs. This directly enables per-department tracking if each department maps to a project, and it provides native budget alert notifications, exactly as required.

Why this answer

In GCP, a Cloud Billing budget can be scoped to a specific project using the 'Scoped to' field, allowing you to create one budget per project directly from the billing account without needing to enable billing separately or export data. This is the most efficient native approach because budgets support project-level scoping out of the box. It avoids the overhead of BigQuery export and custom monitoring setup.

Exam trap

ACE often tests the misconception that a single billing-account budget with labels is equivalent to per-project budgets, when in fact scoped budgets give cleaner per-project alerting.

How to eliminate wrong answers

Option A is wrong because Billing Export to BigQuery plus Cloud Monitoring is a heavier, custom-built solution requiring data pipeline setup and alert configuration, not the most efficient native approach. Option C is wrong because enabling billing per project is a prerequisite, not a budgeting mechanism, and it does not create budget alerts. Option D is wrong because a single billing-account-wide budget with labels cannot enforce per-project thresholds or send project-specific alerts as cleanly as scoped budgets.

49
MCQhard

An organization wants to enforce that all projects under a specific folder have a set of constraints, such as disabling default network creation and requiring shielded VMs. What is the most efficient way to achieve this?

A.Use Cloud Shell to run scripts in each project.
B.Create IAM roles to restrict default network creation.
C.Use a service account to enforce policies.
D.Apply organization policies at the folder level.
AnswerD

Applying organization policies at the folder level is correct because constraints are inherited by all projects and subfolders under that folder. For example, the compute.skipDefaultNetworkCreation constraint can be set at a folder to prevent any project inside it from creating the default VPC network at project creation time. This ensures consistent, centrally managed governance across an entire team or environment without needing to configure each project individually.

Why this answer

Organization policies in Google Cloud can be applied at the folder level, and they are inherited by all projects within that folder. This allows enforcing constraints like disabling default network creation and requiring shielded VMs across all projects efficiently. Applying at the folder level ensures consistent enforcement without per-project configuration.

Exam trap

ACE often tests the misconception that IAM roles or service accounts can enforce resource constraints, when organization policies are the correct tool.

How to eliminate wrong answers

Option A is wrong because running scripts in each project is manual, error-prone, and not efficient for ongoing enforcement. Option B is wrong because IAM roles control access, not resource configurations like default network creation; they cannot enforce constraints. Option C is wrong because a service account is an identity, not a policy enforcement mechanism; it cannot enforce organization policies.

50
MCQeasy

A startup wants to create a new GCP project for development. They've already created a billing account. Which command can they use to create the project?

A.gcloud config set project PROJECT_ID
B.gcloud projects create PROJECT_ID
C.gcloud alpha projects create
D.gcloud resource-manager projects create
AnswerB

gcloud projects create PROJECT_ID is the correct command because it sends a create request to the Cloud Resource Manager API, which provisions a new project with the specified ID. This command requires the resourcemanager.projects.create permission and the PROJECT_ID must be globally unique across all Google Cloud projects. Once created, the project can be used for development and managed via gcloud.

Why this answer

The 'gcloud projects create' command creates a new project. The billing association is separate, but the project can be created without billing immediately.

51
MCQmedium

You create a new Google Cloud project using the Cloud Console. After creating the project, you need to enable the Compute Engine API. What is the correct command to do this using the Cloud Shell?

A.gcloud projects enable compute.googleapis.com
B.gcloud compute enable compute.googleapis.com
C.gcloud api enable compute
D.gcloud services enable compute.googleapis.com
AnswerD

gcloud services enable compute.googleapis.com is the correct command to enable the Compute Engine API in the current project. It interacts with the Service Usage API to set the service's enabled state for the active project. After running this command, you can start using Compute Engine features, assuming a billing account is linked and the IAM permission serviceusage.services.enable is granted. The full service name compute.googleapis.com uniquely identifies the API.

Why this answer

The correct command to enable an API in a Google Cloud project is 'gcloud services enable <API_NAME>'. For Compute Engine, the API name is compute.googleapis.com, so the full command is 'gcloud services enable compute.googleapis.com'. This uses the Service Usage API under the hood to enable the specified service for the active project.

Exam trap

The trap is mixing up command groups — candidates pick 'gcloud projects enable' or 'gcloud compute enable' because those groups sound plausible, but the correct group is 'gcloud services' with the full API name.

How to eliminate wrong answers

Option A is wrong because 'gcloud projects enable' is not a valid gcloud command group — project management uses 'gcloud projects' for create/delete/describe, not for enabling APIs. Option B is wrong because 'gcloud compute enable' is not a valid subcommand; 'gcloud compute' manages Compute Engine resources (instances, disks, etc.), not API enablement. Option C is wrong because 'gcloud api enable' is not a valid command group — the correct group is 'gcloud services', and the API identifier must be the full service name (compute.googleapis.com), not the short name 'compute'.

52
MCQhard

A developer is using Cloud Shell and wants to ensure that their gcloud configuration persists after the Cloud Shell session ends. They have set the compute and access settings using `gcloud config set`. What should they do to keep these settings for future sessions?

A.They need to create a startup script to apply the settings each time
B.The settings are automatically preserved because Cloud Shell's home directory persists
C.They must run `gcloud config configurations save default` before ending the session
D.They must use `gcloud config set --persist` flag
AnswerB

Cloud Shell provisions an ephemeral VM but attaches a persistent 5 GB home directory for each user. gcloud configurations are stored as files under ~/.config/gcloud, so whenever the developer runs `gcloud config set project`, the value is written to disk and remains available in future sessions. When the session ends, any new VM in a future session mounts the same home directory, preserving the settings automatically.

Why this answer

Cloud Shell provides a persistent $HOME directory backed by a 5 GB persistent disk that survives across sessions. Because gcloud configuration is stored in $HOME/.config/gcloud, any `gcloud config set` changes are written there and automatically restored when the user reconnects. No additional action is required.

Exam trap

ACE often tests the misconception that Cloud Shell is fully ephemeral, leading candidates to invent persistence flags or startup scripts when the home directory already persists by default.

How to eliminate wrong answers

Option A is wrong because a startup script is unnecessary — the home directory already persists, so re-applying settings would be redundant. Option C is wrong because `gcloud config configurations save` is not a valid gcloud subcommand; configurations are created with `gcloud config configurations create` and activated with `activate`. Option D is wrong because `--persist` is not a valid flag for `gcloud config set`; persistence is inherent to the home directory.

53
MCQhard

You are setting up a new organization in Google Cloud. You want to restrict the regions where resources can be created to comply with data residency requirements. What should you do?

A.Set an organization policy with a constraint on allowed resource locations
B.Create a service account with limited permissions
C.Set a budget alert that notifies when resources are created outside allowed regions
D.Use IAM roles to restrict which users can create resources in specific regions
AnswerA

An organization policy with the constraints/gcp-resource-locations constraint defines an explicit allowlist of regions where resources can be created. When set at the organization, folder, or project level, it is enforced synchronously at resource creation time, and any API request targeting a location outside the allowlist is rejected with an error. This is the intended, preventative control for enforcing data residency or regulatory location requirements across Google Cloud.

Why this answer

Organization policies in Google Cloud are the native mechanism for enforcing constraints across all projects in an organization, including resource location restrictions. The `constraints/gcp.resourceLocations` constraint (part of the Location Restriction constraint family) lets you define an allowlist of regions/zones where resources can be created, and it is enforced at the org, folder, or project level regardless of a user's IAM permissions. This directly satisfies data residency requirements because it blocks resource creation outside approved locations even for project owners.

Exam trap

ACE often tests the misconception that IAM roles can restrict where resources are created, when in fact only Organization Policies provide location-based enforcement.

How to eliminate wrong answers

Option B is wrong because a service account with limited permissions controls what identities can do, not where resources can be created — it cannot enforce geographic restrictions. Option C is wrong because a budget alert is a monitoring/notification tool for spend, not a preventive control; it would only tell you after a resource was already created outside the allowed region. Option D is wrong because IAM roles grant or deny actions (like compute.instances.create) but have no concept of region-level granularity for most services, so they cannot enforce data residency.

54
MCQeasy

What is the purpose of the gcloud init command?

A.To create a billing account.
B.To initialize a new project in Google Cloud.
C.To enable APIs for a project.
D.To set up a new gcloud configuration and authenticate.
AnswerD

The primary purpose of gcloud init is to bootstrap the gcloud command-line tool by creating a new configuration, authenticating with your Google account or service account, and setting properties like the default project, region, and zone. It is the standard first step when installing or reinstalling the gcloud SDK on a new machine or for setting up an isolated environment.

Why this answer

The gcloud init command is the primary setup utility for the Google Cloud CLI. It performs two core tasks: it creates a new named configuration (or reinitializes an existing one) and then walks the user through authentication via gcloud auth login, followed by selecting a default project and optionally a default Compute Engine zone/region. This ensures the CLI is ready for use with the correct credentials and project context.

Exam trap

ACE often tests the confusion between gcloud init and other gcloud commands like gcloud projects create or gcloud services enable, tricking candidates into thinking gcloud init performs project creation or API enablement rather than just setting up CLI configuration and authentication.

How to eliminate wrong answers

Option A is wrong because billing accounts are created and managed via the Cloud Console or the Cloud Billing API, not through gcloud init; gcloud init does not handle billing account creation. Option B is wrong because initializing a new project means creating a project resource, which is done with gcloud projects create, not gcloud init; gcloud init only sets a default project for the configuration. Option C is wrong because enabling APIs is performed with gcloud services enable, not gcloud init; gcloud init does not enable any APIs by default.

55
MCQeasy

You want to switch between multiple GCP projects frequently using the gcloud CLI. What is the recommended approach?

A.Open separate terminal windows for each project.
B.Run gcloud init every time you switch projects.
C.Use gcloud config set project each time you switch.
D.Create multiple configuration profiles and activate them as needed.
AnswerD

Creating multiple named configurations with gcloud config configurations create and activating them via gcloud config configurations activate is the officially recommended pattern for frequent context switching. Each configuration stores its own project, account, region, and other properties, so you can define a distinct environment for every GCP project or workflow. Activation is instantaneous and deterministic, and you can even use the --configuration flag to run a single command in a non-default configuration without changing your active context, enabling safe automation and parallel work.

Why this answer

gcloud supports named configuration profiles, each holding its own project, account, region, and zone settings. Creating multiple configurations and activating the relevant one with 'gcloud config configurations activate <name>' lets you switch contexts instantly without re-authenticating or re-initializing. This is the officially recommended approach for developers who work across many projects.

Exam trap

ACE often tests whether candidates know that 'gcloud config set project' only changes one property of the current config, whereas named configurations preserve a full context (account, project, region, zone) — the trap is picking the quick-fix command over the scalable profile approach.

How to eliminate wrong answers

Option A is wrong because opening separate terminal windows does not change the underlying gcloud configuration — each shell still uses the same active config unless you manually override it, and it does not scale. Option B is wrong because 'gcloud init' is a full re-initialization that re-runs authentication and setup, which is slow and disruptive for routine project switching. Option C is wrong because 'gcloud config set project' only changes the project property of the current configuration; it does not switch accounts, regions, or zones, and it mutates the active config rather than preserving distinct profiles.

56
MCQmedium

A team wants to enable Compute Engine API in their project using gcloud. Which command should they run?

A.gcloud compute enable api
B.gcloud services list --enabled
C.gcloud api enable compute
D.gcloud services enable compute.googleapis.com
AnswerD

gcloud services enable compute.googleapis.com is the correct command to enable the Compute Engine API for a project. The gcloud services enable command accepts the fully qualified service name (compute.googleapis.com) and provisions access for the project, making it available for use with gcloud compute commands, API calls, and console operations. This is the standard, documented way to turn on a Google API in a project.

Why this answer

The correct gcloud syntax for enabling an API is 'gcloud services enable <service-name>', and the Compute Engine API's service name is compute.googleapis.com. So 'gcloud services enable compute.googleapis.com' is the only syntactically valid command that enables the Compute Engine API.

Exam trap

The trap is guessing at command syntax — candidates pick plausible-looking commands like 'gcloud compute enable api' instead of remembering that API management lives under 'gcloud services' with the fully qualified service name.

How to eliminate wrong answers

Option A is wrong because 'gcloud compute enable api' is not a valid gcloud command — 'compute' is a command group for managing instances, not for enabling APIs. Option B is wrong because 'gcloud services list --enabled' only lists currently enabled services; it does not enable anything. Option C is wrong because 'gcloud api enable compute' uses the wrong command group ('api' is not a gcloud top-level group) and the wrong service identifier format.

57
MCQmedium

You want to enable the Kubernetes Engine API for your project using the command line. Which gcloud command should you use?

A.gcloud services enable container.googleapis.com
B.gcloud container clusters create my-cluster
C.gcloud config set project my-project
D.gcloud auth login
AnswerA

The correct command to enable the Kubernetes Engine API is `gcloud services enable container.googleapis.com`. This calls the Service Usage API to activate the service in the current Google Cloud project, making it possible to later create and manage GKE clusters. Enabling the API is a prerequisite that also links the service to the project's billing account; until this is done, any GKE resource creation will fail with an error indicating the API is disabled.

Why this answer

The `gcloud services enable container.googleapis.com` command enables the Kubernetes Engine API for the active project. Service enablement is done through the Service Usage API, and `gcloud services enable` is the correct CLI wrapper. Creating a cluster or setting a project does not enable the API.

Exam trap

ACE often tests whether candidates know that creating a resource does not implicitly enable its API; the trap is picking the cluster creation command when the question explicitly asks to enable the API.

How to eliminate wrong answers

Option B is wrong because `gcloud container clusters create my-cluster` attempts to create a GKE cluster and will fail if the API is not already enabled; it does not enable the API. Option C is wrong because `gcloud config set project my-project` only changes the active project property and does not enable any API. Option D is wrong because `gcloud auth login` only authenticates the user and has no effect on API enablement.

58
MCQmedium

A company wants to track costs by department and project. They have multiple GCP projects used by different teams. Which feature should they use to categorize costs?

A.Budgets and alerts
B.Labels
C.Billing export to BigQuery
D.Custom IAM roles
AnswerB

Labels are key-value pairs applied to GCP resources, letting you attribute spend to both department and project dimensions and filter billing reports accordingly. They satisfy the requirement to categorise costs across multiple projects, unlike billing accounts or folders, which cannot carry arbitrary cost-tracking metadata.

Why this answer

Labels are key-value pairs that can be attached to resources to organize and track costs by department or project. Budgets and alerts notify when spending exceeds thresholds but do not categorize costs. Billing export to BigQuery is for exporting billing data for analysis, not for direct categorization.

Custom IAM roles are for managing permissions, not cost tracking.

59
MCQhard

An engineer needs to give a data analyst access to run BigQuery queries but prevent them from viewing or modifying data in Cloud Storage. The analyst should be able to create new datasets. Which IAM role should the engineer assign at the project level?

A.roles/storage.objectViewer
B.roles/bigquery.dataEditor
C.roles/bigquery.dataOwner
D.roles/bigquery.user
AnswerB

roles/bigquery.dataEditor is the correct choice because it provides the necessary permissions for a data analyst to run queries, including bigquery.jobs.create to execute query jobs and bigquery.tables.getData to read table contents. It also allows creating and updating tables within datasets, striking the right balance between access and control. Unlike broader roles, it does not grant dataset-level deletion or permission management, aligning with the principle of least privilege for a typical analyst use case.

Why this answer

The role roles/bigquery.dataEditor allows creating datasets and querying data, but does not grant any Cloud Storage permissions.

60
Multi-Selecteasy

A Cloud Architect needs to understand the GCP resource hierarchy to set up proper access control. Which three resources are part of the GCP resource hierarchy? (Choose THREE.)

Select 3 answers
A.Billing Account
B.Folder
C.Project
D.Organization
E.Cloud Identity
AnswersB, C, D

Folders are correct because they serve as intermediate grouping nodes within the resource hierarchy, sitting directly below an Organization and above Projects. They allow you to group teams, products, or departments and apply IAM policies and organization policies at that group level, which are inherited by all contained projects. Folders can also nest other folders, enabling multi-level administrative boundaries that align with corporate structure.

Why this answer

The GCP resource hierarchy is Organization → Folder → Project → Resources, so the three hierarchy nodes among the options are Organization (D), Folder (B), and Project (C). Organization (D) is the root node of the hierarchy and is tied to a Cloud Identity or Workspace domain, serving as the top-level container where organization-wide IAM policies and org policies are applied. Folder (B) sits between the organization and projects, allowing hierarchical grouping of projects so that IAM and org policies inherit down to everything beneath them.

Project (C) is the fundamental resource container that holds actual GCP services and resources (VMs, buckets, datasets) and is the level at which APIs are enabled and billing is linked. Billing Account (A) is not part of the resource hierarchy; it is a separate billing construct that can be linked to one or more projects but does not participate in IAM policy inheritance. Cloud Identity (E) is an identity management service/domain that underpins the organization node, not a node in the resource hierarchy itself.

Exam trap

ACE often tests the distinction between the resource hierarchy and other GCP constructs like Billing Accounts and Cloud Identity, causing candidates to incorrectly include them as part of the hierarchy.

61
Multi-Selectmedium

A company wants to set up a new GCP project and ensure that only approved APIs can be used. Which two steps should they take? (Choose TWO)

Select 2 answers
A.Create a custom role with permissions to enable APIs
B.Use an organization policy to restrict the set of allowed APIs
C.Set a budget to limit API usage costs
D.Assign the Owner role to the project
E.Disable all APIs and enable only the required ones
AnswersB, E

Use an organization policy with the constraints/serviceusage.services constraint on the organization, folder, or project to define an allowlist of Google API service names, such as compute.googleapis.com and storage.googleapis.com. This policy is enforced at access time and inherited hierarchically, so no project-level IAM change can bypass the allowed set. It is the proper guardrail to ensure that only approved APIs can be enabled across a new project, regardless of who holds IAM permissions.

Why this answer

To restrict API usage, you can disable unapproved APIs and use organization policies to enforce restrictions.

62
Multi-Selecthard

A company wants to organize their GCP resources into a hierarchy to separate development, staging, and production environments. Which THREE resources can be used to create this separation?

Select 3 answers
A.Folders
B.Organization node
C.Billing accounts
D.Projects
E.Labels
AnswersA, B, D

Folders are hierarchical containers that sit between the organization node and projects, allowing you to group projects based on business units, teams, or deployment stages (e.g., development, staging, production). As nodes in the resource hierarchy, folders inherit policies from the organization node and propagate their own IAM policies and resource constraints to all projects and folders underneath them, making them a correct and essential component for organizing GCP resources.

Why this answer

GCP resource hierarchy includes Organization, Folders, Projects, and Resources. Folders can be used to group projects (e.g., dev folder, prod folder). Projects are the containers for resources.

Labels are metadata tags but not part of the hierarchy. Billing accounts are separate from the hierarchy. IAM policy is not a resource for separation.

63
MCQeasy

A Cloud Shell user wants to persist Terraform state files across sessions. What is the best approach?

A.Store them in /tmp
B.Store them in a Cloud Storage bucket and mount via gcsfuse
C.Store them on the instance's local SSD
D.Store them in the home directory ($HOME)
AnswerD

The home directory ($HOME) in Cloud Shell is the designated persistent storage area, backed by a 5GB disk that survives across sessions and idle timeouts. Files saved there, including Terraform state files, are retained for later use and are protected from session cleanup. This makes $HOME the simplest and correct choice for persisting state in a personal Cloud Shell environment.

Why this answer

In Google Cloud Shell, the home directory ($HOME) is persistent across sessions, while other locations like /tmp are ephemeral and cleared when the session ends. Storing Terraform state files in $HOME ensures they persist and are available in subsequent Cloud Shell sessions without additional setup.

Exam trap

ACE often tests the difference between persistent and ephemeral storage in Cloud Shell, and candidates may choose Cloud Storage with gcsfuse thinking it's the 'cloud-native' answer, but the question asks for the best approach for a single user's persistence, which is $HOME.

How to eliminate wrong answers

Option A is wrong because /tmp is a temporary filesystem that is wiped when the Cloud Shell session terminates, so state files would be lost. Option B is wrong because while storing state in a Cloud Storage bucket is a best practice for team collaboration, mounting it via gcsfuse is not the recommended or simplest approach for persistence in Cloud Shell; gcsfuse has performance and consistency limitations. Option C is wrong because the instance's local SSD is ephemeral and not persistent across Cloud Shell sessions, which are themselves ephemeral VMs.

64
MCQmedium

An engineer is setting up Cloud Identity for a new domain. What is a prerequisite for creating a Cloud Identity account?

A.A G Suite account
B.A billing account
C.Domain verification
D.An existing Google Cloud project
AnswerC

Cloud Identity requires proof that you own the custom domain (e.g., @yourdomain.com) before it can create user accounts and manage access for that domain. You must add a unique verification code as a DNS TXT record, or follow the alternate HTML file method, to prove control of the domain. Without this step, Google cannot legally or technically assign identity administration to your domain.

Why this answer

Cloud Identity requires domain verification to prove ownership. This is done via DNS TXT record or other methods.

65
MCQmedium

An engineer wants to ensure that no one in their organization can create VMs with public IP addresses. Which Google Cloud tool should they use to enforce this restriction?

A.Organization policies
B.Labels
C.IAM roles
D.Quotas
AnswerA

Organization policies are the correct tool because they directly enforce restrictions on resource configurations across the entire hierarchy (folders and projects). For example, the compute.vmExternalIpAccess constraint can be set to only allow certain VMs to have external IPs, or require a dedicated VPC peering. They act as guardian rules that cannot be overridden by users without the necessary admin permissions.

Why this answer

Organization policies in Google Cloud are hierarchical constraints applied at the organization, folder, or project level that restrict what resources can be created or configured. The predefined constraint constraints/compute.vmExternalIpAccess can be set to deny, preventing any VM in the scope from receiving an external IP. This is enforced by the resource manager before the VM is created, making it the correct tool for a hard organizational restriction.

Exam trap

The trap is assuming IAM roles can enforce resource configuration restrictions — IAM controls who can act, not what configuration is allowed; that is the job of organization policies.

How to eliminate wrong answers

Option B is wrong because labels are metadata key-value pairs used for organization, billing, and filtering — they have no enforcement capability. Option C is wrong because IAM roles grant or deny permissions to identities, but they cannot express resource-level constraints like 'no external IPs'; a user with compute.instances.create could still create a VM with a public IP. Option D is wrong because quotas limit the quantity of resources (e.g., number of CPUs per region), not the configuration attributes of those resources.

66
MCQeasy

A new engineer needs to enable the Compute Engine API for a project using the gcloud command-line tool. Which command should they run?

A.gcloud compute enable-api
B.gcloud projects enable compute.googleapis.com
C.gcloud api enable compute
D.gcloud services enable compute.googleapis.com
AnswerD

The correct command is `gcloud services enable compute.googleapis.com`. The `gcloud services` group is the standard interface for enabling and disabling Google Cloud APIs, and `compute.googleapis.com` is the unique service name for Compute Engine. This command works asynchronously, so you can verify the operation with `gcloud services list --enabled` or the console. It requires the `serviceusage.services.enable` IAM permission on the project.

Why this answer

The correct command is 'gcloud services enable compute.googleapis.com' because the gcloud CLI uses the 'services' command group to manage API enablement, and the Compute Engine API is identified by its service name 'compute.googleapis.com'. This is the standard, documented syntax for enabling any Google Cloud API via gcloud.

Exam trap

ACE often tests the exact gcloud command syntax — candidates confuse the 'services' command group with 'compute' or 'api', or forget that the service name must be the full domain (compute.googleapis.com).

How to eliminate wrong answers

Option A is wrong because 'gcloud compute enable-api' is not a valid gcloud command — 'compute' is a command group for managing Compute Engine resources, not APIs. Option B is wrong because 'gcloud projects enable' is not a valid subcommand; project management uses 'gcloud projects' for create/delete/describe, not API enablement. Option C is wrong because 'gcloud api enable' is not a valid command group — the correct group is 'services'.

Ready to test yourself?

Try a timed practice session using only Setting Up a Cloud Solution Environment questions.