Courseiva

ACE · topic practice

Configuring Access and Security practice questions

Practise Google Associate Cloud Engineer Configuring Access and Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Configuring Access and Security

What the exam tests

What to know about Configuring Access and Security

Configuring Access and Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Configuring Access and Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Configuring Access and Security questions

20 questions · select your answer, then reveal the explanation

An engineer created a firewall rule to allow inbound HTTP traffic on port 80 from the internet to instances with the tag 'web-server'. However, after applying the rule, a test instance with the tag 'web-server' is still not reachable on port 80. What is a likely cause?

An engineer needs to grant a user the ability to create and manage service accounts in a project, but not delete them. Which predefined IAM role should be assigned?

You want to allow HTTP traffic from the internet to a set of Compute Engine instances tagged 'web-server'. Which gcloud command creates the appropriate firewall rule?

A security team wants to ensure that all new projects in an organization automatically have Data Access audit logs enabled for all services. What is the most efficient way to achieve this?

A security team wants to ensure that all Compute Engine instances in a project are created with a specific custom service account attached. What is the most effective way to enforce this?

You are creating a new service account for an application that needs to read from a Cloud Storage bucket and write to Cloud Pub/Sub. What is the most secure way to grant these permissions?

You need to allow a Compute Engine instance to securely access a Cloud Storage bucket without managing service account keys. The instance already has a service account attached. What is the best practice to grant access?

An organization is designing a VPC with multiple subnets. They want instances in a private subnet to access the internet for updates. They also need to allow SSH access from a bastion host. Which THREE components must they configure? (Choose 3 answers.)

A company wants to use Customer-Managed Encryption Keys (CMEK) for encrypting data in a Cloud Storage bucket. They have created a key in Cloud KMS. Which step is required when creating the bucket to use CMEK?

Question 10mediummulti select
Review the full subnetting walkthrough →

A company needs to enable Private Google Access for a subnet in a VPC so that Compute Engine instances without external IPs can access Google APIs and services. Which two steps are required? (Choose TWO.)

A security engineer wants to audit all actions that modify VPC firewall rules in their project. They need to enable the appropriate audit logs. Which three steps should they take? (Choose THREE.)

A company needs to allow a group of external auditors to view Cloud Audit Logs for a project but not modify any resources. Which two steps should be taken? (Choose 2)

An engineer needs to create a service account and grant it the ability to impersonate other service accounts. Which two permissions are required? (Choose 2)

An engineer wants to allow HTTP traffic from the internet to a set of Compute Engine instances that have the network tag 'web-server'. Which firewall rule should they create?

A company is migrating a legacy application to Compute Engine. The application requires access to a Cloud Storage bucket for storing logs. The application runs on a VM with a service account attached. Which TWO steps should the engineer take to grant the application access to the bucket?

An organization has a VPC with several subnets. They want Compute Engine instances in one subnet to have outbound internet access for updates but not be reachable from the internet. The instances have no external IP addresses. Which THREE components must be configured?

A security engineer needs to ensure that all secrets stored in Secret Manager are encrypted with a customer-managed encryption key (CMEK). Which TWO actions are required?

An engineer needs to grant an external auditor read-only access to a subset of Cloud Storage buckets in a project. The auditor's identity is a Google account. Which IAM approach should the engineer use?

A security team wants to ensure that all Compute Engine instances in a project automatically use a custom service account with minimal permissions. What must the engineer do when creating new instances?

Question 20mediummultiple choice
Read the full NAT/PAT explanation →

A company wants to use Cloud NAT to allow private instances in a VPC to send outbound traffic to the internet and to receive inbound responses. Which two resources must be configured to set up Cloud NAT?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Configuring Access and Security sessions

Start a Configuring Access and Security only practice session

Every question in these sessions is drawn from the Configuring Access and Security domain — nothing else.

Related practice questions

Related ACE topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the ACE exam test about Configuring Access and Security?
Configuring Access and Security questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Configuring Access and Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Configuring Access and Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other ACE topics?
Use the topic links above to move to related areas, or go back to the ACE question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the ACE exam covers. They are not copied from any real exam or dump site.