Courseiva

ACE · topic practice

Configuring Access and Security practice questions

This domain covers Google Cloud IAM, service accounts, firewall rules, CMEK, VPC Service Controls, and audit logging. Questions present concrete scenarios—folder-level bindings, log retention, key rotation, rule priority conflicts—and ask you to pick the least-privilege, most correct configuration or predict the resulting behavior.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Configuring Access and Security

What the exam tests

What to know about Configuring Access and Security

Be able to choose the correct IAM binding scope, enable and export Data Access logs with Bucket Lock, predict firewall rule outcomes from priority and ranges, and explain CMEK key rotation effects. The single most important thing: apply least privilege at the right resource hierarchy level.

IAM policy bindings at organization, folder, project, and resource levels using predefined and custom roles

Cloud Audit Logs: Admin Activity, Data Access, and immutable retention via Cloud Storage buckets with Bucket Lock

VPC firewall rule evaluation by priority, direction, and source ranges with implied deny rules

Cloud KMS CMEK configuration and key rotation impact on Cloud SQL and other CMEK-integrated services

Watch out for

Common Configuring Access and Security exam traps

  • ▸Granting roles at project level when a folder-level binding would satisfy the requirement with less administrative overhead and broader consistent coverage.
  • ▸Assuming Data Access logs are enabled by default; they must be explicitly enabled per service and exported for long-term immutable retention.
  • ▸Forgetting that firewall rules are evaluated by priority number, where lower numbers win, and that a matching deny overrides a matching allow.

Practice set

Configuring Access and Security questions

20 questions · select your answer, then reveal the explanation

An engineer needs to grant an external auditor read-only access to a subset of Cloud Storage buckets in a project. The auditor's identity is a Google account. Which IAM approach should the engineer use?

An engineer created a firewall rule to allow inbound HTTP traffic on port 80 from the internet to instances with the tag 'web-server'. However, after applying the rule, a test instance with the tag 'web-server' is still not reachable on port 80. What is a likely cause?

Question 3mediummultiple choice
Read the full NAT/PAT explanation →

A company wants to use Cloud NAT to allow private instances in a VPC to send outbound traffic to the internet and to receive inbound responses. Which two resources must be configured to set up Cloud NAT?

Question 4hardmultiple choice
Review the full subnetting walkthrough →

A company has a VPC with two subnets: subnet-a (10.0.1.0/24) and subnet-b (10.0.2.0/24). They want to allow traffic from instances in subnet-a to reach a specific instance in subnet-b only on TCP port 443. What is the most specific firewall rule to achieve this?

A team needs to create a new service account and grant it the roles/storage.objectViewer role on a project. Which two gcloud commands are required?

A company wants to ensure that a Compute Engine instance can access only a specific Cloud Storage bucket and no other resources in the project. Which TWO steps should the engineer take? (Select 2 correct answers)

Which TWO of the following are valid ways to grant IAM roles to a service account for accessing a Cloud Storage bucket? (Select 2 correct answers)

An engineer needs to grant a user the ability to create and manage service accounts in a project, but not delete them. Which predefined IAM role should be assigned?

You want to allow HTTP traffic from the internet to a set of Compute Engine instances tagged 'web-server'. Which gcloud command creates the appropriate firewall rule?

A security engineer needs to ensure that Compute Engine instances in a VPC can only communicate with each other on port 443 and cannot receive traffic from the internet. The VPC has a default network with default firewall rules. What should the engineer do?

A security team wants to ensure that all new projects in an organization automatically have Data Access audit logs enabled for all services. What is the most efficient way to achieve this?

A security team wants to ensure that all Compute Engine instances in a project are created with a specific custom service account attached. What is the most effective way to enforce this?

You are creating a new service account for an application that needs to read from a Cloud Storage bucket and write to Cloud Pub/Sub. What is the most secure way to grant these permissions?

An organization wants to enforce encryption at rest for all data in Cloud Storage using Customer-Managed Encryption Keys (CMEK). They have created a Cloud KMS key ring and key. What additional step is required when creating a new bucket to use CMEK?

An organization is designing a VPC with multiple subnets. They want instances in a private subnet to access the internet for updates. They also need to allow SSH access from a bastion host. Which THREE components must they configure? (Choose 3 answers.)

An engineer needs to grant a service account the ability to impersonate another service account when making API calls. Which IAM role should be assigned to the impersonating service account?

A security team wants to enable audit logging for all Data Access (ADMIN_READ, DATA_READ, DATA_WRITE) on a specific Google Cloud project. They plan to use gcloud commands to configure this. What is the correct approach?

A company wants to use Customer-Managed Encryption Keys (CMEK) for encrypting data in a Cloud Storage bucket. They have created a key in Cloud KMS. Which step is required when creating the bucket to use CMEK?

A developer created a service account for an application running on a Compute Engine instance. The instance was started without specifying the service account. What must the developer do to make the application use the service account?

An organization requires that all Compute Engine instances be created with a specific service account. Which organization policy can enforce this?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Configuring Access and Security sessions

Start a Configuring Access and Security only practice session

Every question in these sessions is drawn from the Configuring Access and Security domain — nothing else.

Related practice questions

Related ACE topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the ACE exam test about Configuring Access and Security?
Be able to choose the correct IAM binding scope, enable and export Data Access logs with Bucket Lock, predict firewall rule outcomes from priority and ranges, and explain CMEK key rotation effects. The single most important thing: apply least privilege at the right resource hierarchy level.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Configuring Access and Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Configuring Access and Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other ACE topics?
Use the topic links above to move to related areas, or go back to the ACE question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the ACE exam covers. They are not copied from any real exam or dump site.