Courseiva
hardMultiple Select

Google ACE Practice Question: Which THREE are best practices for monitoring and…

Which THREE are best practices for monitoring and alerting in Google Cloud?

⚠ Common exam trap

Google Cloud often tests the distinction between cost management (budget alerts) and operational monitoring (Cloud Monitoring, log-based metrics, uptime checks), leading candidates to incorrectly include budget alerts as a monitoring best practice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Cloud Audit Logs to monitor administrative actions and data access.

Option B is correct because Cloud Audit Logs (Admin Activity, Data Access, System Event, and Policy Denied logs) provide an immutable record of administrative actions and data access, which is essential for security monitoring, compliance, and detecting suspicious activity in Google Cloud. Option D is correct because log-based metrics let you turn specific log entries (for example, matching a severity or a regex pattern) into a metric that Cloud Monitoring can alert on, enabling detection of application-specific error patterns that generic infrastructure metrics would miss. Option E is correct because Cloud Monitoring uptime checks probe external-facing services from multiple global locations and can trigger alerting policies when availability or latency degrades, directly protecting the user-facing SLA. Option A is not a monitoring/alerting best practice in this context because budget alerts in Cloud Billing only notify about cost thresholds and do not monitor service health, performance, or security. Option C is not universally a best practice because VPC Flow Logs generate substantial volume and cost, so they should be enabled selectively on subnets where traffic metadata is actually needed rather than on all subnets by default.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure budget alerts in Cloud Billing to notify when costs exceed a threshold.

    Why it's wrong here

    Budget alerts in Cloud Billing only track spending against a monetary threshold and send notifications when costs are forecast to exceed or actually exceed that amount. They are financial guardrails, not operational monitoring signals, because they cannot detect error rates, latency, or service availability. Thus they fail to help troubleshoot or proactively manage the health of your workloads, making them incorrect for a monitoring and alerting best-practice question.

  • ✓

    Use Cloud Audit Logs to monitor administrative actions and data access.

    Why this is correct

    Cloud Audit Logs are the authoritative record of who did what, when, and from where across your GCP resources. Admin Activity logs capture control-plane operations like creating or deleting resources, while Data Access logs capture reads and writes to user data, enabling security and compliance monitoring. Reviewing these logs and setting alerts for suspicious administrative actions or unusual data access is a core security monitoring best practice, because it provides the forensic detail needed to detect misuse or external attacks.

  • ✗

    Enable VPC Flow Logs for all subnets to capture all network traffic metadata.

    Why it's wrong here

    Enabling VPC Flow Logs for all subnets generates enormous volumes of metadata and can lead to significant logging and storage costs, especially in high-traffic networks. Best practice is to enable flow logs selectively on critical subnets or VMs, and to tune sampling rate and aggregation interval to balance visibility against cost. Additionally, VPC Flow Logs only capture connection metadata, not full packet payloads, so they are a network diagnostics tool, not a comprehensive monitoring solution for every environment.

  • ✓

    Set up alerts based on log-based metrics to detect specific error patterns.

    Why this is correct

    Log-based metrics let you derive counters, distributions, and Boolean metrics from Cloud Logging data, such as the count of a specific error string or the distribution of request latencies parsed from logs. By creating an alert policy on a log-based metric, you can detect specific error patterns in near-real time, such as a sudden spike in 500 responses or repeated authentication failures. This is a best practice because it turns raw logs into actionable operational signals and enables proactive incident response.

  • ✓

    Use Cloud Monitoring to create uptime checks for external-facing services.

    Why this is correct

    Uptime checks in Cloud Monitoring periodically probe your external-facing HTTP/HTTPS endpoints from multiple global locations and verify that they respond with the expected status code and within a configured timeout. These checks track availability and latency over time, and alerting on them helps you detect service outages before users complain. This is a best practice for externally visible services because it is simple to set up and directly measures the user-facing health of your application.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.