Courseiva

CCNA Cdl Resource Management Questions

66 questions · Cdl Resource Management topic · All types, answers revealed

1
MCQmedium

A startup wants to estimate the monthly cost of running a managed Kubernetes cluster with specific node configurations before deploying. Which GCP tool should they use?

A.Active Assist recommendations
B.Cost Management dashboard
C.Google Cloud Pricing Calculator
D.Billing export to BigQuery
AnswerC

The Google Cloud Pricing Calculator is the correct tool because it enables users to select specific Google Cloud products, configure their parameters (e.g., machine type, region, storage class, network egress), and immediately see a detailed monthly cost estimate. It also incorporates pricing tiers, custom machine types, and can account for committed use discounts or sole-tenant nodes, giving a flexible and reasonably accurate projection for a planned workload. This makes it ideal for a startup that needs to budget before any actual infrastructure is created, as it translates desired resource specifications into an estimated monthly bill.

Why this answer

The Google Cloud Pricing Calculator is the purpose-built tool for estimating costs of GCP resources—including GKE clusters with specified node machine types, counts, and regions—before any resources are deployed. It lets users model workloads (e.g., GKE Standard vs Autopilot, node vCPU/memory, committed use discounts) and produces a forward-looking monthly cost estimate. Because the startup wants a pre-deployment estimate, the calculator is the correct choice.

Exam trap

GCDL often tests the distinction between forward-looking estimation (Pricing Calculator) and backward-looking analysis (Cost Management, Billing export), so candidates who see 'cost' and reflexively pick the billing dashboard fall into the trap.

How to eliminate wrong answers

Option A is wrong because Active Assist recommendations analyze already-deployed resources to surface cost, security, and performance optimizations—it cannot estimate costs for infrastructure that does not yet exist. Option B is wrong because the Cost Management dashboard (Cloud Billing reports) shows historical and current actual spend, not projected costs for unbuilt configurations. Option D is wrong because Billing export to BigQuery is a data pipeline for granular historical billing analysis and custom reporting, not a pre-deployment estimation tool.

2
MCQmedium

A company wants to analyze their GCP spending trends by service and project over the past year. They need to export detailed billing data to a BigQuery dataset for custom queries. Which feature should they use?

A.Billing export to BigQuery
B.Cloud Pricing Calculator
C.Active Assist rightsizing recommendations
D.Cloud Billing budget alerts
AnswerA

Billing export to BigQuery is the correct choice because it lets you continuously export detailed GCP billing data—including cost, usage, SKU, project, and labels—into BigQuery. This data can then be queried with SQL and visualized to identify monthly or daily spending trends by service. The export is set up at the billing account level and supports both standard and detailed usage cost views, making it the intended tool for this analysis.

Why this answer

Billing export to BigQuery automatically streams detailed Cloud Billing data — including cost by service, project, SKU, and labels — into a BigQuery dataset where you can run arbitrary SQL for trend analysis. It is the only option that provides granular, queryable historical billing data. The other options are for estimation, recommendations, or alerting, not detailed export and custom querying.

Exam trap

The trap here is confusing cost-visibility tools — candidates pick budget alerts or the Pricing Calculator thinking they 'analyze spending,' but only Billing export to BigQuery gives raw, queryable historical cost data.

How to eliminate wrong answers

Option B is wrong because the Cloud Pricing Calculator only estimates future costs based on user-entered configurations; it does not contain or export your actual historical spend. Option C is wrong because Active Assist rightsizing recommendations suggest resource changes to reduce cost — they do not export detailed billing line items to BigQuery. Option D is wrong because Cloud Billing budget alerts only notify you when spend crosses thresholds; they provide no queryable dataset of per-service/per-project costs.

3
MCQmedium

A company has a production project that requires a compute quota of 500 vCPUs, but the default limit is 200. What is the correct process to request a quota increase?

A.Shut down idle VMs to free up quota
B.Create a new support ticket with the Billing team
C.Use the gcloud compute quotas update command
D.Navigate to IAM & Admin > Quotas in Cloud Console, select the metric, and request an increase
AnswerD

This is the correct and standard procedure for requesting a quota increase. The IAM & Admin > Quotas page displays all project-level quotas, allowing you to select a specific metric (e.g., Compute Engine vCPU) and click "Edit Quotas" to submit an increase request. If the requested increase falls within the pre-approved limits, it is granted automatically; otherwise, it routes to Google Cloud support for review. This self-service workflow is the only documented way to raise quota limits and is directly accessible from the Cloud Console without opening a support ticket.

Why this answer

Quota increases can be requested through the Cloud Console under IAM & Admin > Quotas, where the engineer can select the metric (e.g., CPUs) and request a higher limit.

4
MCQeasy

An organization wants to tag resources with key-value metadata for cost allocation purposes (e.g., team: marketing, environment: prod). Which feature should be used?

A.Organization policy constraints
B.Labels
C.IAM custom roles
D.Tags (network tags)
AnswerB

Labels are the correct mechanism for key-value metadata in Google Cloud. They are explicitly designed to organize and track resources—for example, attaching entries like "cost-center: engineering" or "environment: production" to virtual machines, disks, and storage buckets. Labels integrate directly with billing export and Cloud Monitoring, enabling cost allocation and filtering, which precisely matches the stated requirement.

Why this answer

In Google Cloud, Labels are the key-value pairs attached to resources specifically for metadata such as cost allocation, ownership, and environment. They are the supported mechanism for grouping and filtering resources in billing reports (e.g., by team or environment), which matches the requirement exactly.

Exam trap

GCDL often tests the confusion between Labels (cost/metadata) and network tags (firewall/routing), so candidates pick 'Tags' thinking it covers cost allocation.

How to eliminate wrong answers

Option A is wrong because Organization Policy constraints enforce governance rules (e.g., restricting locations or services); they do not attach cost-allocation metadata. Option C is wrong because IAM custom roles define permissions, not resource metadata. Option D is wrong because network tags are used for firewall rules and routing on Compute Engine instances, not for cost allocation or general resource metadata.

5
MCQmedium

A company has applied a deny organization policy at the folder level that prevents the use of certain machine series. An IAM policy at the project level grants a user the role of compute.instanceAdmin. The user attempts to create a VM using a denied machine series. What will happen?

A.The user is prompted to request a quota increase.
B.The VM creation is blocked by the deny policy at the folder level.
C.The VM is created successfully because the IAM policy allows it.
D.The deny policy is overridden by the project-level IAM policy.
AnswerB

VM creation is blocked because organization policy constraints are evaluated as hard restrictions that take precedence over any IAM grants. When a folder-level deny policy exists, the Cloud Resource Manager component rejects the compute.instance.create call immediately, regardless of which roles the user holds. The deny is deterministic and cannot be bypassed by IAM permissions, so the only possible outcome is a failed creation request.

Why this answer

Organization policies in GCP are enforced hierarchically and act as guardrails independent of IAM. A deny policy applied at the folder level is inherited by all projects beneath it and blocks the denied action regardless of what IAM roles the user holds. Because the machine series is denied at the folder, the compute.instanceAdmin role at the project cannot override it, so VM creation fails.

Exam trap

GCDL often tests the misconception that IAM permissions can override organization policy—candidates who see 'instanceAdmin' and assume the action succeeds miss that org policy is a separate, higher-precedence enforcement layer.

How to eliminate wrong answers

Option A is wrong because quota increases are unrelated to organization policy enforcement—the request is blocked by policy, not by a resource limit. Option C is wrong because IAM grants permissions but does not override organization policy constraints; both must allow the action for it to succeed. Option D is wrong because organization policies are not overridden by IAM policies—they operate on a separate enforcement plane, and deny policies take precedence over allow grants.

6
MCQmedium

An organization wants to ensure that all projects in the organization have a specific IAM policy applied, such as restricting the use of certain machine series. They also need to enforce this policy on new projects automatically. Where should they set this policy?

A.At the organization node
B.At the project level for each project
C.Using tags on individual resources
D.At the folder level for each environment
AnswerA

The organization node is the root of the Google Cloud resource hierarchy, and an IAM policy attached there is automatically inherited by every folder and project below it, including resources that will be created in the future. This ensures uniform permission enforcement across the entire organization without needing to replicate the policy on each folder or project. It is Google Cloud's recommended pattern for establishing baseline roles that should apply to all resources, providing a single authoritative binding that simplifies audit and governance.

Why this answer

Organization policies applied at the organization node are inherited by all projects under it, ensuring uniform enforcement across the entire hierarchy.

7
MCQmedium

A company has a support plan that guarantees a 15-minute response time for P1 cases and includes a Technical Account Manager (TAM). Which support plan do they have?

A.Standard Support
B.Enhanced Support
C.Basic Support
D.Premium Support
AnswerD

Premium Support is the sole tier that guarantees a 15-minute response for P1 (critical) incidents, a hard SLA not available in any lower tier. It also assigns a dedicated Technical Account Manager (TAM) to provide proactive operational support, architecture guidance, and business alignment, exactly matching the company's support plan.

Why this answer

Premium Support is the only Google Cloud support plan that guarantees a 15-minute response time for P1 cases and includes a named Technical Account Manager (TAM). Enhanced Support offers a 1-hour P1 response and no TAM, while Standard and Basic offer progressively slower responses. The combination of 15-minute P1 SLA and TAM uniquely identifies Premium.

Exam trap

The trap is conflating Enhanced and Premium — candidates remember 'Enhanced has faster response' but forget that only Premium includes a TAM and the 15-minute P1 SLA.

How to eliminate wrong answers

Option A is wrong because Standard Support does not include a TAM and has a 4-hour P1 response target, far slower than 15 minutes. Option B is wrong because Enhanced Support has a 1-hour P1 response and does not include a TAM — it is the tier below Premium. Option C is wrong because Basic Support is for development/sandbox use with no SLA and no TAM, and is not intended for production.

8
MCQmedium

A team wants to track costs for their development and production environments separately. They have multiple projects for each environment. Which approach should they use to group projects by environment and analyze costs by environment in billing reports?

A.Create a folder for each environment and assign projects to the folders
B.Add a label like 'environment:dev' or 'environment:prod' to each project
C.Use separate billing accounts for each environment
D.Create a separate organization for each environment
AnswerB

Labeling each project with a key-value pair like `environment:dev` or `environment:prod` is the native Google Cloud approach for cost allocation. These labels are exported with every usage record in the Cloud Billing BigQuery export, enabling you to filter, group, and aggregate costs by environment in SQL queries or through cost reports. Labels are also on other resources, so you can even drill down to service-level or resource-level costs by environment, and you can attach budgets and alerts based on label filters.

Why this answer

Labels are key-value pairs that can be applied to resources or projects and used for cost allocation and filtering in billing reports. Folders are for hierarchical grouping and IAM inheritance, not direct cost tracking.

9
MCQmedium

An organization wants to allow their finance team to view billing account cost information but prevent them from making any changes to the billing account. Which IAM role should they grant?

A.Billing Account Admin
B.Project Billing Manager
C.Billing Account User
D.Billing Account Viewer
AnswerD

Billing Account Viewer is the correct role because it provides read-only access to all billing information on the billing account, including cost breakdowns, invoices, and payment history, without allowing any modifications. This aligns with the finance team's need to view billing data and perform analysis while adhering to least-privilege security principles, reducing the risk of unintended changes.

Why this answer

The Billing Account Viewer role grants read-only access to billing account cost information, including viewing budgets, costs, and billing account details, without permission to modify the billing account. This matches the requirement to let the finance team view costs while preventing changes. It is the least-privilege role for read-only billing visibility.

Exam trap

The trap is the near-identical naming of billing roles — candidates confuse Billing Account User (which only links projects) with Billing Account Viewer (which actually reads cost data), and may over-grant by choosing Admin for a read-only requirement.

How to eliminate wrong answers

Option A is wrong because Billing Account Admin grants full control over the billing account, including modifying payment methods, budgets, and IAM policies — far more than read-only. Option B is wrong because Project Billing Manager manages billing for a specific project, not the billing account, and includes write capabilities. Option C is wrong because Billing Account User is intended to associate projects with a billing account (link projects), not to view cost data, and it does not provide the read-only cost visibility the finance team needs.

10
MCQeasy

What is the primary purpose of a folder in the Google Cloud resource hierarchy?

A.To manage user identities
B.To define network topologies
C.To store billing information
D.To group projects and apply policies
AnswerD

Folders are the primary mechanism for grouping projects under an organization, enabling you to apply IAM policies, organization policies, and resource hierarchy rules at a sub-organization level. This design supports delegated management and policy inheritance, where permissions assigned to a folder flow down to all projects and resources inside it. A folder acts as a container that gives you granular control without needing to manage each project individually.

Why this answer

Folders in the Google Cloud resource hierarchy sit between the organization node and projects, letting you group related projects and attach IAM policies and organization policies that are inherited by everything beneath them. This makes folders the primary tool for delegated administration and policy scoping across project boundaries.

Exam trap

The trap is that all four options describe things that exist in Google Cloud (identities, networks, billing), so candidates pick based on keyword familiarity rather than understanding that only folders provide hierarchical grouping and policy inheritance.

How to eliminate wrong answers

Option A is wrong because user identities are managed by Cloud Identity or Google Workspace, not by folders — folders only reference identities in IAM bindings. Option B is wrong because network topologies are defined by VPC networks, subnets, and firewall rules, which are project-level resources, not hierarchy constructs. Option C is wrong because billing information is associated with the Cloud Billing account linked to projects, not stored in folders.

11
MCQeasy

A developer needs to estimate the monthly cost of running a set of Compute Engine instances with specific machine types, persistent disks, and network egress before deploying. Which tool should they use?

A.Google Cloud Pricing Calculator
B.Billing export to BigQuery
C.Active Assist Recommendations
D.Cost Management dashboard
AnswerA

The Google Cloud Pricing Calculator is the authoritative pre-deployment estimation tool, letting users select specific services (e.g., Compute Engine machine types, Cloud Storage classes) and input usage parameters like region, sustained use, and committed use discounts to generate a monthly cost projection. It pulls current, publicly listed rates and supports SKU-level customization, making it the correct choice for forecasting costs before any resource is created or consumed.

Why this answer

The Google Cloud Pricing Calculator is the tool designed to estimate costs for specific resources like Compute Engine instances, persistent disks, and network egress before deployment. It lets you configure machine types, disk sizes, and egress volumes to produce a monthly cost estimate. This is exactly the pre-deployment estimation use case described.

Exam trap

GCDL often tests the difference between forward-looking estimation (Pricing Calculator) and retrospective cost analysis (Billing export, Cost Management dashboard) — candidates may pick a reporting tool when the question asks for pre-deployment estimation.

How to eliminate wrong answers

Option B is wrong because Billing export to BigQuery is for analyzing historical actual costs, not for pre-deployment estimation. Option C is wrong because Active Assist Recommendations provides optimization suggestions based on existing usage, not forward-looking cost estimates. Option D is wrong because the Cost Management dashboard shows actual incurred costs and trends, not estimates for planned resources.

12
MCQeasy

A company needs to estimate the monthly cost of running a set of Compute Engine instances, including network egress and Cloud Storage usage, before deploying the architecture. Which tool should they use?

A.Active Assist recommendations
B.Google Cloud Pricing Calculator
C.Budget alerts
D.Cost Management dashboard
AnswerB

The Google Cloud Pricing Calculator is the correct tool for estimating monthly costs before deployment because it accepts user-defined resource specifications, including machine type, region, persistent disk size, estimated usage hours, and committed use discount terms. It references Google Cloud's current public SKU pricing to generate a detailed, line-item cost estimate for a proposed workload, enabling architects to model multi-component architectures and assess the financial impact of configuration choices before committing to them.

Why this answer

The Google Cloud Pricing Calculator is a web-based estimation tool that lets you model Compute Engine instances, Cloud Storage, and network egress charges before any resources are provisioned. It produces a shareable, itemized monthly cost estimate based on SKU-level pricing, which is exactly what pre-deployment planning requires. It is the only option designed for forward-looking cost estimation rather than monitoring actual spend.

Exam trap

GCDL often tests the distinction between pre-deployment cost estimation (Pricing Calculator) and post-deployment cost visibility (Cost Management dashboard, budgets, and alerts), so candidates who see 'cost' and reflexively pick a monitoring tool get it wrong.

How to eliminate wrong answers

Option A is wrong because Active Assist recommendations analyze already-deployed resources to surface optimization opportunities (idle VMs, unattached disks), not to estimate costs for a future architecture. Option C is wrong because Budget alerts only notify you when actual or forecasted spend crosses a threshold on an existing billing account — they cannot model a hypothetical deployment. Option D is wrong because the Cost Management dashboard (Cloud Billing reports) visualizes historical and current incurred costs, not pre-deployment estimates.

13
MCQmedium

A company wants to receive notifications when its monthly spending exceeds 80% of a $10,000 budget. Which set of steps will achieve this?

A.Create a budget alert in Cloud Monitoring with a metric threshold of 80%
B.Set up a budget in the Billing section of Cloud Console, define the amount, and add alert thresholds at 80%
C.Use the Google Cloud Pricing Calculator to set a spending limit
D.Configure a Cloud Scheduler job to check billing data in BigQuery and send a notification
AnswerB

Cloud Billing budgets, configured under the Billing section of Cloud Console, are the official service for monitoring spend against a defined amount. You set a budget amount and then add alert threshold rules, such as 80% of the budget, which trigger notifications when actual or forecasted spend crosses that threshold. These alerts are event-driven and can deliver email or Pub/Sub messages, enabling immediate reaction when spending approaches the limit. This directly satisfies the company's requirement to be notified when monthly spend reaches 80% of the planned amount.

Why this answer

To receive notifications when spending exceeds 80% of a $10,000 budget, the correct approach is to create a budget in the Billing section of Google Cloud Console, define the amount, and set alert thresholds at 80%. This directly triggers alerts based on actual or forecasted spend. Other options do not provide budget-based alerts.

Exam trap

GCDL often tests the distinction between billing budgets and other monitoring tools, and candidates may confuse Cloud Monitoring with Billing budgets or think the Pricing Calculator can set alerts.

How to eliminate wrong answers

Option A is wrong because Cloud Monitoring is for infrastructure metrics, not billing budgets. Option C is wrong because the Pricing Calculator is for estimating costs, not setting alerts. Option D is wrong because it requires custom scripting and does not natively integrate with budget alerts.

14
Multi-Selectmedium

A company is planning their resource hierarchy in Google Cloud. They need to separate environments (prod, non-prod) and teams (engineering, data science). They also need to apply common policies to all prod projects. Which TWO resources should they use?

Select 2 answers
A.Billing accounts
B.Folders
C.Organization policies
D.Labels
E.Projects
AnswersB, C

Folders are the correct hierarchical grouping node within Google Cloud's resource hierarchy, sitting between the organization node and projects. They allow you to organize projects into environments (e.g., dev, prod) or business units, and they propagate policies (IAM, Organization Policies) downward to all projects and resources inside them. This inheritance enables centralized governance and access control across multiple projects.

Why this answer

Folders (B) are the correct resource for modeling the hierarchy: you can nest folders under the organization to represent environments (prod, non-prod) and teams (engineering, data science), and IAM policies and Organization Policies inherit down through the folder tree to all contained projects. Organization policies (C) are the mechanism to apply common constraints (e.g., restrict VM external IPs, allowed locations) that inherit to every project under the prod folder, satisfying the requirement to enforce common policies across all prod projects. Billing accounts (A) only link projects to a payment method and do not model environment/team separation or policy inheritance.

Labels (D) are metadata for filtering, reporting, and billing attribution, not a policy or hierarchy boundary. Projects (E) are the leaf resources that hold workloads; they cannot themselves group other projects or enforce inherited common policies across a set.

Exam trap

GCDL often tests the distinction between resource hierarchy components and policy tools, confusing candidates into selecting labels or billing accounts for organizational purposes when folders and organization policies are the correct structural and policy enforcement mechanisms.

15
Multi-Selecteasy

An engineer needs to grant a team access to view but not edit Compute Engine instances in a project. They also need to ensure that any new instances created in a folder automatically inherit a policy that denies using certain machine types. Which TWO steps should they take? (Choose TWO.)

Select 2 answers
A.Grant the team the 'roles/iam.securityReviewer' role
B.Use a deny IAM policy at the project level to block create permissions
C.Apply an organization policy constraint to the folder to deny certain machine types
D.Set a quota for the machine type at the project level
E.Grant the team the 'roles/compute.viewer' role at the project level
AnswersC, E

An organization policy constraint applied at the folder level, such as compute.vmMachineTypeConstraints, restricts which machine types can be used to create VMs across all descendant projects. Folder-level organization policies are inherited by every project and resource within the folder, so any new project added later automatically receives the same restriction without per-project configuration. This centrally enforces the requirement to deny certain machine types while allowing the team to view but not edit.

Why this answer

IAM roles grant permissions; compute.viewer provides read-only access to Compute resources. Organization policies can be set at the folder level to restrict machine types across all projects within.

16
Multi-Selecthard

A company has a multi-project GCP environment with a single billing account. They want to receive alerts when any project's spending exceeds its allocated budget, and they want to analyze cost trends by project and service. Which THREE services should they use together?

Select 3 answers
A.Committed use discounts
B.Labels on resources
C.Active Assist idle resource recommendations
D.Cloud Billing budgets
E.Billing export to BigQuery
AnswersB, D, E

Labels are key-value metadata attached to GCP resources, such as 'team' or 'environment', and they are the primary mechanism for sorting and grouping costs within an exported billing dataset. When combined with BigQuery billing export, labels let you slice costs by project, service, team, or any custom dimension, enabling exact repartition of spend. They are the correct tool because they make cost data attributable and queryable.

Why this answer

Option B (Labels on resources) is correct because labels are the mechanism that lets you attribute and group costs by project and service dimensions in billing data, enabling the per-project and per-service cost-trend analysis the company requires. Option D (Cloud Billing budgets) is correct because budgets defined on the billing account or scoped to projects trigger alert notifications when actual or forecasted spend exceeds the allocated threshold, directly satisfying the requirement to be alerted when any project's spending exceeds its budget. Option E (Billing export to BigQuery) is correct because exporting detailed billing data to BigQuery provides the granular, queryable dataset needed to analyze cost trends by project and service over time.

Option A (Committed use discounts) is not correct because CUDs are a pricing/discount mechanism to reduce compute costs, not an alerting or cost-analysis service. Option C (Active Assist idle resource recommendations) is not correct because it only surfaces optimization suggestions for idle or underutilized resources and does not provide budget alerts or billing trend analysis.

Exam trap

GCDL often tests the confusion between cost *visibility* tools (labels, BigQuery export) and cost *control* tools (budgets, CUDs, quotas) — candidates pick CUDs or Active Assist thinking they provide alerting or analytics when they only optimize spend.

17
MCQhard

An engineer is designing a resource hierarchy for a multinational company with multiple business units. The company uses Google Workspace. What is the first step in creating the resource hierarchy?

A.Link the Google Workspace account to the organization node
B.Create a project for each business unit
C.Create a folder for each business unit
D.Enable the Cloud Resource Manager API
AnswerA

The organization node is the root of the Google Cloud resource hierarchy and is automatically provisioned when you set up Google Workspace or Cloud Identity — it is never created manually. Simply having the Workspace/Identity tenant is not enough; you must explicitly link it to the organization node in the Google Cloud console. This action establishes the trust relationship that enables organization-level IAM policies, resource constraints, and audit logging across all current and future projects. Until this link is made, you do not have an operational root node to attach folders or projects to, so this is the correct first step.

Why this answer

The first step in creating a Google Cloud resource hierarchy for a company using Google Workspace is to link the Google Workspace (or Cloud Identity) account to the organization node, which establishes the Organization resource at the root of the hierarchy. Without this link, there is no organization node to contain folders and projects, so all subsequent hierarchy steps depend on it. Once the organization node exists, folders and projects can be created beneath it.

Exam trap

The trap is jumping to folders or projects as the first step; candidates must remember that the organization node must be linked to Google Workspace/Cloud Identity before any folders or projects can be created.

How to eliminate wrong answers

Option B is wrong because creating a project for each business unit is a later step that requires the organization node and, ideally, folders to already exist for proper governance. Option C is wrong because creating folders for each business unit also presupposes the organization node exists; folders are children of the organization. Option D is wrong because enabling the Cloud Resource Manager API is a supporting action but not the first step in establishing the hierarchy; the organization node must be linked first, and the API is typically enabled as part of project setup.

18
MCQmedium

A company wants to reserve Compute Engine resources for a 3-year term to get a significant discount. Which discount type should they use?

A.Preemptible VM discount
B.Sustained use discount
C.Sole-tenant node discount
D.Committed use discount
AnswerD

Committed Use Discounts (CUDs) allow you to commit to a specific amount of vCPUs, memory, or spend for a 1- or 3-year term, in exchange for a substantially reduced price. By purchasing a commitment, you reserve capacity and pay a predictable lower rate for the entire term, making it the appropriate mechanism to reserve Compute Engine resources for a 3-year period.

Why this answer

Committed use discounts (CUDs) in Google Cloud allow you to reserve Compute Engine resources for a 1-year or 3-year term in exchange for significant discounts (up to 57% for 3-year). This is the correct discount type for a 3-year commitment. CUDs are ideal for predictable workloads.

Exam trap

The trap is confusing sustained use discounts with committed use discounts; sustained use is automatic and short-term, while committed use requires a 1- or 3-year commitment for larger discounts.

How to eliminate wrong answers

Option A is wrong because preemptible VMs are short-lived, can be terminated at any time, and offer discounts but are not for reserved capacity; they are not suitable for a 3-year term. Option B is wrong because sustained use discounts are automatic discounts for running instances for a significant portion of the month, but they do not require a commitment and are not for a 3-year term. Option C is wrong because sole-tenant nodes are physical servers dedicated to your use, but they do not inherently provide a discount for a 3-year term; you can apply CUDs to sole-tenant nodes, but the discount type itself is CUD.

19
Multi-Selecteasy

A company wants to gain visibility into their Google Cloud spending across multiple projects. Which TWO methods allow them to analyze cost data?

Select 2 answers
A.Upgrade to Premium Support.
B.Set up billing export to BigQuery.
C.Use the Google Cloud Pricing Calculator.
D.Use the Cost Management dashboard.
E.Set up budget alerts.
AnswersB, D

Set up billing export to BigQuery. This is the correct approach because it automatically exports detailed usage and cost data into BigQuery, where you can run arbitrary SQL queries to slice the data by service, project, label, or time period. It provides complete, raw billing data for every resource, enabling deep custom analysis beyond what built-in dashboards offer, and supports building unique reports, trend analysis, and anomaly detection.

Why this answer

Option B is correct because exporting billing data to BigQuery gives granular, queryable cost and usage data (via the Cloud Billing export, including detailed usage cost and pricing data) that can be analyzed with SQL across multiple projects linked to the billing account. Option D is correct because the Cost Management dashboard (Cloud Billing reports) provides built-in visibility into spend by project, service, SKU, and labels, allowing cost analysis across projects. Option A is incorrect because Premium Support is a support plan and does not itself provide cost analysis tooling.

Option C is incorrect because the Pricing Calculator only estimates future costs for planned configurations, not actual historical spending. Option E is incorrect because budget alerts only notify you when spending approaches or exceeds a threshold; they do not provide analytical breakdowns of cost data.

Exam trap

GCDL often tests the distinction between cost analysis tools and cost monitoring/estimation tools. Candidates might choose budget alerts or Pricing Calculator, but those don't provide analysis of historical spending.

20
MCQhard

A company has a fixed budget for GCP and wants to prevent any cost overrun by automatically disabling all resources when the monthly budget is exceeded. Which approach should they use?

A.Use the Cost Management dashboard to manually stop resources.
B.Create a Cloud Function triggered by a budget alert Pub/Sub message to stop resources.
C.Use Active Assist to automatically stop idle resources.
D.Set up a budget alert with the 'disable resource' action.
AnswerB

When a budget threshold is exceeded, Cloud Billing publishes a message to a specified Pub/Sub topic. A Cloud Function subscribed to that topic can be triggered to call the Compute Engine API and stop instances, or use the Resource Manager API to disable projects, enforcing the budget automatically. This serverless, event-driven pattern gives near-immediate response and can be customized to stop only tagged resources, making it the correct choice for the stated requirement.

Why this answer

GCP budget alerts only notify; they cannot directly disable resources. To automatically stop resources when a budget is exceeded, you route the budget's Pub/Sub notification to a Cloud Function that executes the shutdown logic, which is the documented pattern for automated cost control.

Exam trap

GCDL often tests the misconception that budget alerts can directly take action like disabling resources, when in reality they only publish notifications requiring a subscriber to act.

How to eliminate wrong answers

Option A is wrong because manual stopping via the Cost Management dashboard is not automatic and cannot prevent overruns in real time. Option C is wrong because Active Assist provides recommendations and insights, not automated resource shutdown based on budget thresholds. Option D is wrong because GCP budgets do not have a built-in 'disable resource' action; that capability does not exist natively, so the option describes a non-existent feature.

21
MCQmedium

A startup expects unpredictable Compute Engine usage and wants to minimize costs without manual intervention. Which discount type automatically applies to VM instances that run for more than 25% of a month?

A.Sustained use discounts
B.Committed use discounts
C.Spot VM discounts
D.Preemptible VM discounts
AnswerA

Sustained use discounts are applied automatically to Compute Engine instances that run more than 25% of a billing month; the discount ramps up from 0% to 30% as utilization increases, requiring no upfront commitment or capacity reservation. Because this is assessed monthly based on actual run time per instance and region, it directly benefits workloads with unpredictable usage patterns, making it the only one of these options that adapts to usage without requiring a forecast or accepting termination risk.

Why this answer

Sustained use discounts (SUDs) are automatically applied to Compute Engine instances that run for more than 25% of a month. They provide a discount on the incremental usage beyond that threshold, with the discount increasing the longer the instance runs. No manual action or commitment is required, making them ideal for unpredictable workloads.

Exam trap

GCDL often tests the confusion between automatic discounts (sustained use) and manual discounts (committed use, spot, preemptible), leading candidates to overlook that only SUDs apply automatically without any commitment or configuration.

How to eliminate wrong answers

Option B is wrong because committed use discounts require a manual commitment to a specific amount of resources for a 1- or 3-year term, which does not suit unpredictable usage. Option C is wrong because spot VM discounts are not a separate discount type; spot VMs are a provisioning model that offers significant discounts but can be preempted and require manual selection. Option D is wrong because preemptible VM discounts are also not a discount type; preemptible VMs are a similar provisioning model with a fixed discount but are being deprecated and require manual selection.

22
MCQhard

An organization has multiple projects with many underutilized Compute Engine instances. They want to identify idle instances and generate recommendations for downsizing or deleting them. The finance team wants to see cost savings estimates. Which tool should they use?

A.Google Cloud Pricing Calculator
B.Billing export to BigQuery
C.Active Assist
D.Cost Management dashboard
AnswerC

Active Assist, which is built on the Google Cloud Recommender, provides prescriptive recommendations specifically for underutilized resources, including idle VM and Cloud SQL instances as well as VM rightsizing recommendations. It analyzes actual utilization metrics (such as CPU and memory over a 7- or 14-day window) alongside machine type capacities, then ranks opportunities with estimated monthly cost savings. Because Active Assist is designed to identify precisely the kind of waste described in the scenario—underutilized resources across many projects—it is the correct, ready-to-use tool for this situation.

Why this answer

Active Assist is Google Cloud's portfolio of intelligent recommendations, including the VM rightsizing recommender and idle VM recommender, which analyze usage metrics and suggest downsizing or deleting underutilized instances with estimated cost savings. It surfaces these directly in the console and via API, matching the finance team's need for savings estimates.

Exam trap

GCDL often tests the boundary between cost visibility tools (Cost Management, Billing export) and cost optimization tools (Active Assist), so candidates pick a dashboard when the question asks for recommendations.

How to eliminate wrong answers

Option A is wrong because the Pricing Calculator estimates costs for planned resources, not recommendations for existing idle instances. Option B is wrong because Billing export to BigQuery provides raw cost data for custom analysis but does not generate rightsizing or idle-instance recommendations. Option D is wrong because the Cost Management dashboard visualizes spend and trends but does not analyze instance utilization or produce downsizing recommendations.

23
MCQeasy

An engineer needs to organize resources for multiple departments and enforce organization-wide policies such as restricting VM external IP addresses. Which GCP resource hierarchy level should the policy be applied at to ensure all projects inherit it?

A.Resource
B.Folder
C.Project
D.Organization node
AnswerD

The organization node is the root of the Google Cloud resource hierarchy, encompassing all folders and projects under it. IAM policies and organizational policies set at the organization node are inherited by every child folder and project, which means you can enforce uniform access controls, billing, and audit logging across multiple departments from a single central point. This allows administrators to model the entire enterprise as a single tree and apply department-specific organization policies by creating folders underneath the node, while still having a global fallback policy. Therefore, the organization node is the correct place to define high-level, cross-departmental resource organization and governance.

Why this answer

In Google Cloud's resource hierarchy, the organization node is the root and sits above folders and projects. IAM policies and organization policies applied at the organization node are inherited by all folders, projects, and resources beneath it. To enforce a policy such as restricting external IP addresses across all projects in the company, the organization node is the correct level because it guarantees universal inheritance.

Exam trap

The trap is assuming that a folder or project-level policy is sufficient for organization-wide enforcement; candidates often forget that only the organization node guarantees inheritance to every project, including future ones.

How to eliminate wrong answers

Option A is wrong because a resource (e.g., a VM instance) is the lowest level and policies applied there affect only that single resource, not the entire organization. Option B is wrong because a folder applies only to projects and subfolders within that folder, so it would not cover departments outside that folder. Option C is wrong because a project-level policy applies only to resources within that one project, not to all projects in the organization.

24
MCQmedium

A company has a folder for each department. The Finance team needs to prevent all projects under its folder from creating external IP addresses. What is the most efficient way to enforce this restriction?

A.Configure a service perimeter in VPC Service Controls
B.Use a deny IAM policy at the folder level
C.Apply an organization policy constraint at the folder level
D.Set a VPC firewall rule in each project
AnswerC

The correct answer is to apply an organization policy constraint such as constraints/compute.vmExternalIpAccess at the folder level. This list constraint denies or permits the assignment of external IP addresses to VM instances, and because organization policies are hierarchical, the folder-level setting is inherited by every project and resource within that folder, enforcing the guardrail centrally.

Why this answer

Organization policies can be defined at any level of the resource hierarchy and are inherited by child resources. Setting a constraint at the folder level applies to all projects under that folder.

25
MCQmedium

A company wants to analyze its Google Cloud spending trends by project, service, and labels. They need to run custom SQL queries on billing data and retain it for 2 years. Which approach should they use?

A.Use the Google Cloud Pricing Calculator.
B.Set up billing export to BigQuery.
C.Enable the Cost Management dashboard.
D.Configure budgets and alerts.
AnswerB

Billing export to BigQuery continuously writes detailed billing data, including usage, cost, labels, and metadata, into BigQuery tables for flexible analysis and long-term retention. This enables complex SQL queries, custom dashboards, and time-series trend analysis on actual historical spend, making it the correct and recommended method for understanding Google Cloud spending trends.

Why this answer

Billing export to BigQuery allows you to export detailed billing data into BigQuery datasets, where you can run custom SQL queries and retain data for your desired period.

26
MCQeasy

Which Google Cloud resource serves as the root node in the resource hierarchy and is linked to a Google Workspace or Cloud Identity account?

A.Organization node
B.Billing account
C.Folder
D.Project
AnswerA

The organization node is the top-level (root) node in the Google Cloud resource hierarchy. It represents the entire enterprise and is typically created automatically when a Google Cloud account is established or a domain is claimed. All other resources—folders, projects, and billing associations—are ultimately attached beneath it, allowing organization-wide IAM policies, organization policies, and access governance to be applied uniformly.

Why this answer

The Organization node is the root node in the Google Cloud resource hierarchy and is automatically created when a Google Workspace or Cloud Identity account is linked to Google Cloud. It sits above folders and projects, and serves as the root for applying organization-level IAM policies and constraints.

Exam trap

GCDL often tests the confusion between the organization node and billing account — candidates may think the billing account is the root, but it is not part of the resource hierarchy.

How to eliminate wrong answers

Option B is wrong because a billing account is used for payment and is not part of the resource hierarchy; it can be linked to multiple projects but does not serve as a root node. Option C is wrong because folders are optional containers within an organization that group projects and other folders, but they are not the root node. Option D is wrong because a project is a resource container that holds resources like VMs and buckets, but it is a child of folders or the organization, not the root.

27
MCQmedium

A company runs Compute Engine instances that experience stable, predictable usage. They want to reduce costs by committing to a 1-year term for these virtual machines. Which discount type should they use?

A.Committed use discounts
B.Preemptible VMs
C.Sole-tenant nodes
D.Sustained use discounts
AnswerA

Committed use discounts require a contractual commitment of 1 or 3 years to a specific amount of vCPUs, memory, and other resources in a region. For stable, predictable workloads that run continuously, this commitment can reduce Compute Engine costs by up to 57%, making it the most cost-effective option among the choices. Unlike sustained use discounts, CUDs lock in a lower price regardless of actual monthly usage, but only if you are willing to commit to a fixed resource level.

Why this answer

Committed use discounts (CUDs) allow customers to commit to a certain amount of resources (vCPUs, memory) for 1 or 3 years in exchange for a significant discount. This is ideal for predictable workloads.

28
MCQmedium

A user attempts to create a new Compute Engine instance in the us-central1 region and receives an error indicating that the quota for 'CPUs' has been exceeded. Where should the user go to request a quota increase?

A.Cloud Console > IAM & Admin > Quotas
B.Cloud Console > Billing > Budgets
C.Google Cloud Pricing Calculator
D.Cloud Console > Support > Cases
AnswerA

The IAM & Admin > Quotas page in Cloud Console is the centralized self-service interface for viewing all project quotas, including CPU, disk, and API rate limits. When instance creation fails with a QUOTA_EXCEEDED error, you use this page to select the specific quota, edit the limit, and submit a request that routes to the appropriate approval workflow. For many quotas, the increase is automatically applied within minutes, making this the definitive path.

Why this answer

Quota increases in Google Cloud are requested through the Cloud Console under IAM & Admin > Quotas, where you can filter by service (Compute Engine), locate the specific quota (CPUs in us-central1), and submit an increase request. This is the standard, supported workflow for adjusting project quotas. The request is then reviewed and typically approved automatically or by Google support depending on the size.

Exam trap

GCDL often tests where administrative actions live in the Console, and candidates confuse quota management with billing or support, picking Billing > Budgets or Support > Cases instead of the dedicated Quotas page.

How to eliminate wrong answers

Option B is wrong because Billing > Budgets is for setting spending alerts and budget thresholds, not for requesting quota increases. Option C is wrong because the Google Cloud Pricing Calculator is a tool for estimating costs, not for managing or increasing quotas. Option D is wrong because Support > Cases is for opening support tickets about issues, not the designated path for quota increase requests—quota adjustments are handled through the Quotas page, which may then route to support if manual review is needed.

29
Multi-Selectmedium

A developer is troubleshooting why a Compute Engine instance cannot start in a specific region. The error indicates a quota limit. Which TWO steps should the developer take?

Select 2 answers
A.Check the current quota for the resource in that region via the Quotas page in Cloud Console.
B.Delete unused resources in the same region to free up quota automatically.
C.Change the project to a different billing account.
D.Use a different machine type that uses fewer vCPUs.
E.Request a quota increase for the specific resource in that region.
AnswersA, E

The Quotas page in Cloud Console displays per-region limits and usage for each resource type, such as vCPUs, static IPs, and persistent disk capacity. When a Compute Engine instance creation fails due to a quota limit, the error message will explicitly indicate a quota exceeded error, and this page confirms the exact metric and current consumption. This is the correct first step because it isolates whether the failure is a quota issue or something else, such as network configuration or billing charges.

Why this answer

Option A is correct because the Quotas page in Cloud Console (IAM & Admin > Quotas) shows the current usage and limit for each resource per region, letting the developer confirm which quota is exhausted before acting. Option E is correct because when a quota is genuinely too low for the workload, the developer must submit a quota increase request for that specific resource and region, which is then reviewed and approved by Google Cloud support. Together these steps diagnose the exact quota and resolve it through the proper channel.

Option B is not appropriate because deleting resources is a destructive action and quota is not 'freed automatically' in a way that guarantees the instance can start; the developer should first identify the quota. Option C is wrong because changing the billing account does not alter regional resource quotas. Option D is wrong because switching to a smaller machine type is a workaround that may not address the actual quota (e.g., if the quota is for CPUs, in-use IP addresses, or persistent disk), and it does not resolve the underlying quota limit.

Exam trap

GCDL often tests the misconception that quotas are global or billing-related — candidates pick 'change billing account' or 'delete resources' instead of the correct check-and-request workflow for the specific regional quota.

30
MCQeasy

An organization wants to ensure that all projects under a specific folder inherit a policy that disables the creation of external IP addresses. Which Google Cloud resource hierarchy level should the policy be applied to enforce this requirement for all child resources?

A.Folder
B.Organization node
C.Resource (e.g., VM instance)
D.Project
AnswerA

Attaching the policy at the folder level is the most operative because IAM policies are inherited down the resource hierarchy. The folder acts as a container for all projects under it, so a policy bound at this level automatically applies to every project and resource within that subtree, including any future projects created in the folder. This provides consistent enforcement for the specific business unit or department without affecting unrelated folders or projects.

Why this answer

Organization policy constraints applied at the folder level are inherited by all projects and resources within that folder, ensuring consistent enforcement across the hierarchy.

31
MCQhard

A finance team needs to analyze detailed cost data across multiple projects, including resource-level breakdowns, labels, and cost attribution. They want to export this data to a BigQuery dataset for custom analysis. Which billing export option should they enable?

A.Use the Cloud Billing API to pull cost data programmatically
B.Set up a budget alert with notifications to Pub/Sub and ingest into BigQuery
C.Enable billing export to Cloud Storage in CSV format
D.Enable billing export to BigQuery (standard usage cost data)
AnswerD

This native integration streams detailed billing line items into a BigQuery dataset automatically, with daily and monthly tables that include metadata like resource labels, SKU, cost, and usage amount. It supports standard SQL queries for custom reports, joins with other datasets, and integrates with Looker Studio or other BI tools. The export is fully managed, eliminating custom ETL, and is the recommended approach for comprehensive cost analytics.

Why this answer

Enabling billing export to BigQuery (standard usage cost data) provides detailed, resource-level cost information including labels, projects, and SKUs, which can be queried directly in BigQuery for custom analysis. This is the only option that natively exports granular cost data to BigQuery without additional pipeline development. It supports cost attribution and detailed breakdowns required by the finance team.

Exam trap

The trap is assuming that budget alerts or Cloud Billing API can serve as a billing export to BigQuery. Candidates may think budget alerts provide detailed cost data, but they only trigger notifications based on thresholds.

How to eliminate wrong answers

Option A is wrong because the Cloud Billing API provides programmatic access to cost data but does not automatically export it to BigQuery; it would require custom code to pull and load data, adding complexity. Option B is wrong because budget alerts only notify when spending exceeds thresholds; they do not provide detailed cost data and are not a billing export mechanism. Option C is wrong because exporting to Cloud Storage in CSV format provides raw files but not the structured, queryable dataset in BigQuery that the team needs; it would require additional ETL to load into BigQuery.

32
MCQmedium

An engineer needs to increase the default limit of 24 CPUs per region for Compute Engine instances in their project. They have already consumed 20 CPUs and need to launch a new instance with 8 CPUs. What should they do?

A.Launch the instance anyway; Google Cloud will automatically increase the quota.
B.Request a quota increase in the Cloud Console Quotas page.
C.Create a new project and launch the instance there.
D.Use a different region with available quota.
AnswerB

In the Cloud Console, navigate to IAM & Admin → Quotas, select the specific CPU quota (e.g., CPUs per region), click Edit, and submit a quota increase request. The request goes through a review and approval process; once approved, the new limit becomes effective in minutes to hours. This is the correct way to raise the default 24 CPU limit so you can launch your instance in the desired project and region.

Why this answer

Service quotas are per-project and per-region limits. The engineer must request a quota increase via the Quotas page in the Cloud Console before exceeding the limit.

33
MCQmedium

A team runs a production Compute Engine instance that has been running for 15 days in a 30-day month. They also have a second instance that runs occasionally for testing. They want to maximize cost savings without committing to a 1-year or 3-year term. Which discount will apply automatically?

A.Committed use discount (CUD)
B.Sustained use discount (SUD)
C.Preemptible VM discount
D.No discount applies automatically.
AnswerB

Sustained use discounts (SUDs) are automatically applied to standard Compute Engine instances based on how long each instance runs within a billing month, with no sign-up, plan, or upfront commitment required. Once an instance exceeds 25% of the month (more than about 7.5 days in a 30-day month), the discount kicks in automatically; a production instance running 15 days clearly crosses that threshold. The discount scales with usage and can reach up to 30% off the on-demand hourly rate for the instance when it runs for the entire month, making SUD the correct fit here.

Why this answer

Sustained use discounts automatically apply to instances that run for more than 25% of a month (i.e., >7.5 days). At 15 days, the instance qualifies for sustained use discounts. Committed use discounts require a pre-purchased commitment.

34
Multi-Selectmedium

A company needs to organize their GCP resources into a hierarchy that reflects their departments: Engineering, Marketing, and Finance. Each department has multiple projects. They also want to apply common policies to all departments except Finance, which has special compliance requirements. Which TWO steps should they take?

Select 2 answers
A.Use labels to differentiate departments instead of folders.
B.Apply organization policies at the organization node and override them for the Finance folder using tags.
C.Apply separate IAM policies for each project within a folder.
D.Create a project for each department and place resources in it.
E.Create a folder for each department.
AnswersB, E

Organization policies set at the organization node are inherited by all descendants, establishing a consistent security and compliance baseline. However, using tags as condition keys in policy constraints allows you to create exceptions, such as permitting a specific resource setting only for the Finance folder. This pattern preserves centralized control while accommodating department-specific needs, aligning with the recommended practice of least privilege and scoped flexibility.

Why this answer

Option E is correct because GCP resource hierarchy uses folders to model organizational structure such as departments, so creating a folder for Engineering, Marketing, and Finance lets each department contain its multiple projects and inherit policies from above. Option B is correct because organization policies are inherited down the hierarchy, so applying common policies at the organization node enforces them across all departments, while tags on the Finance folder allow a conditional override to satisfy its special compliance requirements. Option A is not appropriate because labels are for metadata, billing, and filtering, not for building a policy-inheritance hierarchy.

Option C is wrong because setting separate IAM policies per project does not create the required departmental hierarchy or centralized policy inheritance. Option D is wrong because a single project per department cannot hold multiple projects and does not reflect the folder-based hierarchy needed for policy inheritance.

Exam trap

The trap is thinking labels can replace folders for policy inheritance; labels are for metadata and billing, not for hierarchical policy enforcement.

35
Multi-Selectmedium

A company has multiple projects and wants to organize them by environment (dev, test, prod) and by team (engineering, marketing, finance). They also need to apply IAM policies that affect all projects in a given environment. Which TWO steps should they take?

Select 2 answers
A.Create separate billing accounts for each environment
B.Use organization policies at the project level
C.Apply IAM policies at the folder level
D.Use labels to group projects by environment
E.Create folders for each environment (dev, test, prod) and place projects in the appropriate folder
AnswersC, E

Folders are hierarchical nodes in the resource hierarchy, and any IAM policy attached to a folder is inherited by all projects and resources within that folder. This lets you bind environment-wide roles, such as DevTeam or Viewer, once rather than repeating them on each project, giving consistent access across every project in the environment. It is the correct pattern because it uses native inheritance rather than per-project duplication.

Why this answer

Using folders to group projects by environment allows inheritance of IAM policies. Labels are used for cost attribution and filtering, not for policy enforcement.

36
MCQhard

A company wants to receive near-real-time notifications when spending in a project exceeds 50%, 75%, and 100% of a monthly budget of $50,000. They also want to automatically disable billing for the project if spending exceeds $60,000. Which configuration should they use?

A.Use the Cost Management dashboard to monitor spending and disable billing manually.
B.Create a budget alert at 100% only and manually disable billing when alerted.
C.Create a budget with thresholds at 50%, 75%, 100% and set the 'disable billing' action on the budget.
D.Create a budget with thresholds at 50%, 75%, 100% and set up a Cloud Function that listens to Pub/Sub messages from the budget to automatically disable billing when a 120% threshold is exceeded.
AnswerD

This is the correct architecture: Cloud Billing budgets can send threshold-alert messages to a Pub/Sub topic when spend crosses defined percentages (e.g., 50%, 75%, 100%, 120%). A Cloud Function subscribes to that topic, parses the budget notification payload, and if the cost exceeds the intended final threshold (120%), it invokes the Cloud Billing API to disable the billing account. This provides near-real-time, automated enforcement without manual steps, while the earlier thresholds serve as warnings that can trigger other notifications or actions.

Why this answer

Budgets can be set with multiple threshold rules for notifications. However, automatically disabling billing requires a separate automation (e.g., Cloud Functions triggered by Pub/Sub) because budgets do not perform actions beyond notifications and Pub/Sub messages.

37
MCQeasy

An organization wants to group related projects under a common parent for policy enforcement and cost tracking. Which GCP resource hierarchy level should be used to group several projects that belong to the same business unit?

A.Organization node
B.Folder
C.Project
D.Resource
AnswerB

Folders are hierarchical containers that live beneath an Organization node and above Projects, specifically designed to group related projects. They also support nested sub-folders, enabling you to mirror your company's structure or deployment environments (e.g., dev, staging, prod). Policies and IAM roles assigned to a folder are inherited by all projects and resources inside it, making them a first-class administrative boundary for access control and isolation. This is exactly the correct mechanism for grouping related projects while preserving policy inheritance.

Why this answer

Folders are the GCP resource hierarchy level designed to group projects under a common parent, enabling policy inheritance (IAM, Org Policy) and cost aggregation for a business unit. A folder can contain projects and other folders, forming a tree under the organization node. This makes folders the correct choice for grouping several projects belonging to the same business unit.

Exam trap

GCDL often tests the confusion between organization, folder, and project levels — candidates pick the organization node for business-unit grouping when folders are the correct scoped grouping mechanism.

How to eliminate wrong answers

Option A is wrong because the organization node is the root of the hierarchy and represents the entire company, not a single business unit — using it would apply policies to all projects company-wide. Option C is wrong because a project is the resource container itself, not a grouping mechanism for multiple projects. Option D is wrong because 'resource' is a generic term for any GCP object (VMs, buckets, etc.) and is not a hierarchy level for grouping projects.

38
MCQmedium

A company needs to set a budget for their GCP project and receive notifications when spending reaches 50%, 90%, and 100% of the budget. Which action should they take?

A.Enable Committed Use Discounts to reduce costs.
B.Set up billing export to BigQuery with scheduled queries.
C.Configure a budget alert in Cloud Billing with threshold rules at 50%, 90%, and 100%.
D.Use Active Assist to set cost thresholds.
AnswerC

Configuring a budget alert in Cloud Billing is the purpose-built and recommended way to receive spending alerts. You can define a budget amount (for example, a monthly cap) and set threshold rules at 50%, 90%, and 100% to trigger notifications via email or Pub/Sub when actual or forecasted costs hit those percentages. This causes the Cloud Billing system to automatically send alerts, addressing the company's need to be notified as costs approach the budget. It is the only option that explicitly provides the required alerting behavior.

Why this answer

The correct action is to configure a budget alert in Cloud Billing with threshold rules at 50%, 90%, and 100%. Budget alerts in GCP allow you to set multiple thresholds on a budget, and when spending reaches each threshold, notifications are sent via email or Pub/Sub. This directly meets the requirement of receiving notifications at specific percentages of the budget.

Exam trap

The trap here is confusing cost optimization tools (like Committed Use Discounts) or analysis tools (like BigQuery export) with budget alerting, when the question specifically asks for notifications at spending thresholds.

How to eliminate wrong answers

Option A is wrong because Committed Use Discounts (CUDs) are a pricing mechanism to reduce costs by committing to a certain level of usage, not a notification system for budget thresholds. Option B is wrong because billing export to BigQuery with scheduled queries is a method for detailed cost analysis and custom reporting, but it does not natively provide real-time notifications at specific budget thresholds without additional setup and code. Option D is wrong because Active Assist is a suite of tools that provides recommendations and insights for optimizing GCP resources, not a budgeting or alerting service for cost thresholds.

39
MCQhard

An organization uses labels to track cost by environment (dev, test, prod). However, the Finance team notices that some resources are missing the 'env' label. Which service can automatically suggest labeling resources that are missing required labels?

A.Cost Management dashboard
B.Active Assist Recommendations
C.Cloud Asset Inventory
D.Organization Policy Service
AnswerB

Active Assist Recommendations includes the label recommender, which leverages machine learning to analyze resource metadata, usage patterns, and existing label coverage to identify resources missing required label keys or values. It surfaces each suggestion with a rationale and one-click remediation, helping teams enforce tagging conventions without manual audits. This is exactly the kind of proactive, prescriptive guidance the organization needs.

Why this answer

Active Assist provides recommendations for various optimizations, including labeling. The Recommender can suggest labels for resources that are missing them, based on usage patterns.

40
MCQmedium

An engineer needs to analyze detailed cost data, including resource-level usage costs and labels, to create custom reports. Which approach should they use?

A.Use the Cost Management dashboard to export a CSV
B.Set up billing export to BigQuery
C.Manually review invoices
D.Use the Cloud Pricing Calculator
AnswerB

Setting up billing export to BigQuery is the correct approach because it continuously streams all billing data, including line items with resource IDs, labels, and usage metrics, into a BigQuery dataset. The exported tables offer full SQL queryability, enabling you to join cost data with other enterprise datasets, build custom dashboards, and perform granular analysis such as grouping by label or cost per resource. This is the only method that provides the flexibility and detail required for the engineer's needs.

Why this answer

Setting up billing export to BigQuery provides detailed cost data, including resource-level usage costs and labels, enabling custom analysis and reporting. BigQuery allows you to query and join billing data with other datasets, and it includes labels for cost allocation.

Exam trap

GCDL often tests the difference between the Cost Management dashboard (aggregated) and billing export to BigQuery (detailed, resource-level).

How to eliminate wrong answers

Option A is wrong because the Cost Management dashboard provides aggregated views and CSV export, but it does not include the granular resource-level data and labels needed for custom reports. Option C is wrong because manually reviewing invoices is not scalable and lacks detailed resource-level data. Option D is wrong because the Cloud Pricing Calculator estimates costs for planned usage, not actual detailed cost data.

41
MCQhard

A company wants to reserve Compute Engine instances for a 3-year term to get the maximum discount. They expect consistent usage and want the discount to apply automatically to any instance matching the configuration. Which purchasing option should they choose?

A.Sustained use discounts
B.Preemptible VM instances
C.Reserved instances (like AWS)
D.Committed use discounts with a 3-year term
AnswerD

Committed Use Discounts (CUDs) let you commit to a consistent baseline of vCPUs, memory, and other resources for a 1-year or 3-year term, and in return you receive a substantial price reduction—often up to 70% for a 3-year commitment on many machine types. For a predictable, always-on workload spanning 3 years, this offers the highest discount among all options shown, since sustained use discounts are capped at about 30% and do not require a contract, while preemptible VMs are unreliable. The trade-off is that you are financially obligated to pay for the committed resources even if you don't use them, which is acceptable for steady workloads.

Why this answer

Committed use discounts (CUDs) offer significant discounts in exchange for a commitment to use a minimum level of resources for 1 or 3 years. They apply automatically to eligible instances in the specified region and machine series.

42
MCQmedium

A company wants to reduce costs for their long-running Compute Engine instances by committing to a 1-year term. Which type of discount should they use?

A.Sole-tenant node discount
B.Preemptible VM discount
C.Sustained use discount
D.Committed use discount
AnswerD

Committed use discounts (CUDs) are ideal for predictable, long-running compute because you commit to either a 1-year or 3-year usage term in exchange for a significantly discounted price, typically up to 70% off for vCPUs and memory. This discount is resource-based, applying to specific amounts of vCPU and memory per region, and can yield substantial savings for always-on applications. For a company running long-running compute, selecting a committed use discount—especially a 3-year term—maximizes cost reduction and provides predictable pricing.

Why this answer

Committed use discounts (CUDs) are the correct choice for reducing costs on long-running Compute Engine instances by committing to a 1-year term. CUDs provide up to 57% discount for a 1-year commitment and up to 70% for a 3-year commitment, in exchange for a commitment to a certain amount of vCPU and memory usage in a specific region.

Exam trap

GCDL often tests the distinction between sustained use discounts (automatic, no commitment) and committed use discounts (requires 1- or 3-year commitment) — candidates may pick sustained use discounts for long-running instances, but the question explicitly mentions committing to a 1-year term.

How to eliminate wrong answers

Option A is wrong because sole-tenant node discounts are not a standard discount type; sole-tenant nodes are physical servers dedicated to a single tenant, and while they can be reserved, they do not offer the same commitment-based discount model as CUDs. Option B is wrong because preemptible VM discounts are not a commitment-based discount; preemptible VMs are short-lived, can be terminated at any time, and are priced lower but not through a term commitment. Option C is wrong because sustained use discounts are automatic discounts applied when you use a VM for a significant portion of the month, but they do not require a term commitment and are less predictable than CUDs for long-running instances.

43
MCQmedium

An engineer wants to analyze historical spending trends and break down costs by project, region, and service. They need to run complex SQL queries on the billing data. What is the recommended approach?

A.Enable billing export to BigQuery and query the exported tables
B.Set up a budget alert to receive cost reports daily
C.Use the Cloud Billing API to programmatically fetch cost data
D.Download the monthly invoice CSV and import it into Sheets
AnswerA

Billing export to BigQuery automatically writes detailed daily usage and cost tables into a BigQuery dataset, preserving granular fields like service SKU, project, labels, and resource-level usage. These tables support standard SQL queries, allowing you to aggregate historical spend by date, label, or service, and to join with other datasets for deeper analysis. This is the only option that gives you a full, queryable history of cost trends over time, rather than a snapshot or summary.

Why this answer

Billing export to BigQuery sends detailed billing information (e.g., usage, cost, project, labels) into BigQuery tables, enabling complex SQL analysis.

44
MCQmedium

A company wants to receive a 15-minute response time for Priority 1 production issues and have a dedicated Technical Account Manager. Which support plan should they purchase?

A.Enhanced
B.Premium
C.Basic
D.Standard
AnswerB

Premium support is the only Google Cloud tier that commits to a 15-minute response for priority 1 incidents and includes a named Technical Account Manager (TAM) for proactive operational guidance. This combination directly satisfies both conditions in the question. As such, Premium is the correct choice for a company needing rapid incident response and dedicated account coverage.

Why this answer

Google Cloud Premium support provides a 15-minute response time for Priority 1 issues and includes a dedicated Technical Account Manager (TAM). This plan is designed for enterprises with mission-critical workloads that require rapid response and personalized support. Enhanced support offers a 1-hour response for P1 and no dedicated TAM.

Exam trap

GCDL often tests the specific response times and features of each support plan, and candidates may confuse Enhanced with Premium, or forget that only Premium includes a dedicated TAM.

How to eliminate wrong answers

Option A is wrong because Enhanced support has a 1-hour response time for Priority 1 and does not include a dedicated TAM. Option C is wrong because Basic support is for development and has no response time SLA for production issues. Option D is wrong because Standard support has a 4-hour response time for P1 and no dedicated TAM.

45
MCQhard

A team notices that their Compute Engine instances are consistently running at low CPU utilization. They want to reduce costs by receiving recommendations to resize or stop idle VMs. Which service provides these recommendations?

A.Cost Management dashboard
B.Cloud Scheduler
C.Active Assist
D.Cloud Monitoring
AnswerC

Active Assist is Google Cloud's suite of intelligent tools, and its Recommender service continuously analyzes resource usage patterns using machine learning. For Compute Engine, it provides actionable recommendations such as resizing over-provisioned instances to optimally matched machine types or stopping idle and unattached instances. This prescriptive guidance directly addresses the observed high and wasteful costs, making it the correct tool for proactive cost optimization.

Why this answer

Active Assist includes Recommender, which provides cost optimization recommendations such as rightsizing VMs, identifying idle resources, and suggesting committed use discounts.

46
MCQhard

An engineer is setting up budgets and alerts to manage costs. They want to receive a notification when forecasted spend exceeds 80% of the budget amount. Which step is required to enable forecast-based alerts?

A.Enable billing export to BigQuery and set up a scheduled query
B.Select 'Forecasted spend' as the alert threshold type in the budget configuration
C.Create a Cloud Function that checks current spend every hour
D.Use the Cost Management API to query forecast data
AnswerB

Selecting 'Forecasted spend' as the alert threshold type is the correct native method for forecast-based alerts. In the Cloud Billing budget configuration, you define threshold rules that can apply to either actual spend or forecasted spend. When you choose 'Forecasted spend' and set a percentage (e.g., 90%), the alert fires when Google's forecasting model predicts that your end-of-month spend will exceed that threshold. This proactive approach uses machine learning on historical usage patterns, enabling you to act before an overrun occurs, rather than reacting after costs are already incurred.

Why this answer

In the budget alert configuration, you can set alert thresholds based on actual or forecasted spend. To alert on forecasted spend, you must select the 'Forecasted spend' option when defining the threshold rules.

47
MCQeasy

A developer wants to label resources with key-value pairs to track cost by team. Which GCP feature should they use?

A.Tags
B.Labels
C.Folders
D.Organization policy tags
AnswerB

Resource labels are key-value pairs that can be attached to nearly all Google Cloud resources, including compute instances, storage buckets, and BigQuery datasets. They are natively integrated with Cloud Billing, allowing you to generate cost reports filtered by label keys and values. This makes them the appropriate mechanism for labeling resources to track costs, organize workloads, and manage resources.

Why this answer

Labels in Google Cloud are key-value pairs that can be attached to resources for purposes like cost tracking, automation, and organization. They are specifically designed for granular, user-defined metadata and are commonly used to track cost by team, environment, or project. Labels are supported across many GCP services and can be used in billing reports to break down costs.

Exam trap

GCDL often tests the distinction between Labels and Tags, where candidates might confuse their purposes; the trap is selecting Tags for cost tracking when Labels are the correct choice.

How to eliminate wrong answers

Option A is wrong because Tags in Google Cloud are used for conditional policy enforcement and are not designed for cost tracking; they are more about IAM and organization policies. Option C is wrong because Folders are part of the resource hierarchy for organizing projects and applying policies, not for labeling individual resources. Option D is wrong because Organization policy tags are used to enforce constraints on resources, not for cost allocation or tracking.

48
MCQmedium

A company wants to assign metadata to resources for cost allocation reporting. They need to categorize resources by environment (production, staging, development) and team (engineering, marketing). They also need to use this metadata in billing exports. Which approach should they take?

A.Use folder names.
B.Use labels.
C.Use network tags.
D.Use organization policy tags.
AnswerB

Labels are the native GCP mechanism for cost allocation because they are key–value pairs attached directly to resources and are included in both BigQuery billing exports and Cloud Billing reports. By consistently applying labels like 'cost-center' or 'environment,' you can group and filter cost data across projects and resources. Unlike other options, labels are explicitly designed for this purpose and are visible in exported billing data.

Why this answer

Labels in Google Cloud are key-value pairs that can be attached to resources and are propagated to billing exports, making them ideal for cost allocation by environment and team. They are designed for organizational metadata and can be used in billing reports to break down costs. Labels are the recommended approach for this use case.

Exam trap

The trap is confusing labels with network tags or organization policy tags; candidates may think any metadata can be used for billing, but only labels are designed for cost allocation and appear in billing exports.

How to eliminate wrong answers

Option A is wrong because folder names are used for hierarchical organization and policy inheritance, not for billing metadata; they do not appear in billing exports as cost allocation tags. Option C is wrong because network tags are used for firewall rules and routing, not for cost allocation or billing metadata. Option D is wrong because organization policy tags are used for access control and policy enforcement, not for billing categorization.

49
MCQmedium

An organization wants to tag resources with environment (dev/staging/prod) and cost center (e.g., 'marketing', 'engineering') for cost allocation and filtering in billing reports. Which feature should they use?

A.Organization policy tags
B.Folders
C.Network tags
D.Labels
AnswerD

Labels are key-value pairs (e.g., environment=dev) that can be attached to Google Cloud resources like compute instances, storage buckets, and Kubernetes clusters. They are explicitly designed for organization, filtering, and cost allocation: labels appear in Cloud Billing export and BigQuery billing datasets, enabling breakdowns by dimension in Cost Management tools. Setting a label on a resource marks it as belonging to the 'dev' environment, making it the correct way to tag resources for environment cost tracking.

Why this answer

Labels are key-value pairs that can be attached to resources and are used for billing cost allocation, filtering in cost reports, and resource grouping. Tags are for organization policy enforcement and network firewall rules.

50
Multi-Selectmedium

A company needs to enforce that no project in the organization can create resources outside of the us-central1 region. They also need to allow the Finance team to manage billing for all projects. Which TWO steps should they take?

Select 2 answers
A.Create a separate billing account for each project
B.Use IAM deny policies at the organization node to block resource creation outside us-central1
C.Apply the `gcp.resourceLocations` organization policy constraint at the organization node
D.Create a folder and apply an organization policy constraint to restrict locations at the folder level
E.Grant the Finance team the Billing Account Administrator role on the billing account
AnswersC, E

The gcp.resourceLocations constraint is an organization policy that restricts where new resources can be created; setting it at the organization node applies it to all projects under the hierarchy. This constraint evaluates the location of each resource at creation time, blocking any attempt to create resources outside the allowed list (e.g., us-central1). This is the recommended way to enforce a single global location rule across the entire organization.

Why this answer

Organization policies can be applied at the organization level to restrict locations. Billing account access is controlled by IAM roles on the billing account, granting the Finance team the Billing Account Administrator role.

51
MCQmedium

A company runs Compute Engine instances for batch processing that are shut down on weekends. They want to automatically reduce costs without committing to a 1-year or 3-year term. Which discount type applies?

A.Sustained use discount
B.Sole-tenant node discounts
C.Preemptible VM discounts
D.Committed use discount
AnswerA

Sustained use discounts are applied automatically for each Compute Engine instance that runs more than 25% of a month; the discount gradually increases with usage, reaching up to 30% for a full month of use. No upfront commitment or configuration is required, making it ideal for batch processing workloads that run for substantial but indeterminate durations.

Why this answer

Sustained use discounts automatically apply for instances running more than 25% of a month, with no upfront commitment.

52
Multi-Selectmedium

A company wants to set up cost controls and analysis. They need to receive notifications when spending exceeds certain thresholds, and also be able to run custom queries on billing data. Which TWO actions should they take? (Choose 2)

Select 2 answers
A.Create a budget and set alert thresholds
B.Set up a Pub/Sub topic for billing alerts
C.Activate the Cost Management dashboard
D.Enable billing export to Cloud Storage
E.Enable billing export to BigQuery
AnswersA, E

Creating a budget with alert thresholds is a core proactive control action that uses the Cloud Budget API to set a spending limit and receive notifications when actual costs exceed defined percentages (e.g., 50%, 90%, 100%). It doesn't require any additional setup like Pub/Sub, and it directly addresses the requirement to set up cost controls and analysis by providing near-real-time spending alerts.

Why this answer

To receive notifications at thresholds, they need to create a budget and set alerts. To run custom queries, they should enable billing export to BigQuery.

53
MCQhard

An organization has multiple projects in Google Cloud. They want to enforce a policy that prevents the creation of Compute Engine instances with more than 8 vCPUs in any project under a specific folder, except for a few exempted projects. How can they achieve this with minimal overhead?

A.Use organization policy with tags: define a tag 'exempt' and attach it to exempted projects; set the policy condition to apply unless the resource has the tag.
B.Use IAM conditions with a custom role to deny creation of large instances.
C.Create a folder for exempted projects and apply a allow policy to that folder.
D.Apply a custom organization policy at the folder level without tags, and add exceptions in each project individually.
AnswerA

Organization policies support conditional enforcement through tags. By defining a tag key such as 'exempt' and attaching it to the projects that should be excluded, you can write a policy condition (e.g., resource.matchTag("exempt", "true")) that prevents the constraint from applying to those tagged resources. This allows you to enforce a global policy against large VM instances while selectively exempting specific projects without moving them in the hierarchy, preserving existing IAM and folder structure with minimal administrative overhead.

Why this answer

Using organization policy constraints with tags allows conditional enforcement. By attaching a tag to exempted projects and using conditions in the policy, they can apply the restriction to most projects while allowing exceptions.

54
Multi-Selectmedium

A company needs to reduce costs on Compute Engine instances that run batch jobs for varying durations. They can tolerate interruptions and do not require a specific uptime guarantee. Which TWO instance types or purchasing options should they consider? (Choose 2)

Select 2 answers
A.Sole-tenant nodes
B.Spot VMs
C.Preemptible VMs
D.Committed use discounts
E.Sustained use discounts
AnswersB, C

Spot VMs are the modern replacement for preemptible VMs, offering discounts of 60-91% without a maximum runtime cap. They can be terminated by Compute Engine at any time (with a 30-second warning) when capacity is needed, making them ideal for fault-tolerant and batch workloads that can be checkpointed and resumed, directly reducing costs.

Why this answer

Preemptible VMs can be terminated at any time but are significantly cheaper, suitable for fault-tolerant batch jobs. Spot VMs are similar to preemptible but with no maximum runtime and often lower price. Both are ideal for batch workloads that can handle interruptions.

55
MCQeasy

A developer wants to estimate the monthly cost of running a Kubernetes cluster with 3 nodes of n1-standard-4 in the us-central1 region before provisioning. Which tool should the developer use?

A.Billing export to BigQuery
B.Active Assist recommendations
C.Google Cloud Pricing Calculator
D.Cost Management dashboard
AnswerC

The Google Cloud Pricing Calculator lets users assemble a custom configuration of services—compute, storage, networking, and managed offerings—by selecting SKUs, regions, usage quantities, and optional commitment or sustained-use assumptions, and then outputs an itemized monthly cost estimate. It is purpose-built for pre-deployment financial planning and does not require existing billing data or live resources. This makes it the correct tool for estimating monthly cost before any cloud resources are provisioned.

Why this answer

The Google Cloud Pricing Calculator is a web-based tool that lets you estimate costs for GCP services before provisioning any resources. It supports Compute Engine instance types like n1-standard-4, allows you to specify region (us-central1), quantity (3 nodes), and even add Kubernetes Engine management fees. This is the only option designed for pre-provisioning cost estimation.

Exam trap

GCDL often tests the distinction between pre-provisioning estimation (Pricing Calculator) and post-provisioning analysis (Cost Management, Billing export, Active Assist), so candidates who focus on 'cost tools' generically pick the wrong one.

How to eliminate wrong answers

Option A is wrong because Billing export to BigQuery exports actual incurred costs after resources are running, not estimates for future deployments. Option B is wrong because Active Assist provides optimization recommendations for existing resources, not pre-deployment cost estimates. Option D is wrong because the Cost Management dashboard shows historical and current spend, not forward-looking estimates for unprovisioned infrastructure.

56
MCQmedium

A company wants to automatically receive a discount for running Compute Engine instances for more than 25% of a month without any upfront commitment. Which discount type applies?

A.Committed use discount
B.CUD (Committed Use Discount)
C.Sustained use discount
D.Preemptible VM discount
AnswerC

Sustained use discounts are automatically applied to eligible Compute Engine VM resources when you run a VM for more than 25% of a billing month. For every additional minute of usage beyond that threshold, the discount ramps up incrementally, reaching up to 30% off the base price for instance usage for the full month. No commitment or upfront action is needed, which exactly matches the company's requirement for an automatic discount based on monthly runtime.

Why this answer

Sustained use discounts (SUDs) are automatically applied to Compute Engine instances that run for a significant portion of the billing month (specifically, more than 25% of the month). They require no upfront commitment and are applied automatically to eligible instances. This matches the scenario described.

Exam trap

GCDL often tests the distinction between automatic discounts (sustained use) and commitment-based discounts (committed use), and candidates may confuse the two or overlook that sustained use discounts require no upfront commitment.

How to eliminate wrong answers

Option A is wrong because committed use discounts require an upfront commitment (1 or 3 years) in exchange for discounted rates; they are not automatic and do not apply to instances run for just over 25% of a month without commitment. Option B is wrong because CUD is the same as committed use discount, so it shares the same flaw: it requires a commitment. Option D is wrong because preemptible VM discounts are not a discount type; preemptible VMs are a separate instance type that offers lower prices but can be terminated at any time, and they are not automatically applied based on usage duration.

57
MCQhard

A developer tries to create a new Compute Engine instance in the us-central1 region but receives an error 'Quota 'CPUS' exceeded. Limit: 24.0'. What should the developer do to resolve this?

A.Wait for the quota to reset automatically
B.Use a different machine family with lower CPU count
C.Delete unused instances in other regions
D.Request a quota increase for CPUs in us-central1
AnswerD

Requesting a quota increase is the correct action because it raises the regional vCPU cap for your project. In the Google Cloud Console, navigate to IAM & Admin > Quotas, filter by the 'Compute Engine API' service and 'CPUs' metric, select the 'us-central1' region, and click 'Edit' to request a higher limit. This permanently increases the allowed number of vCPUs, and for standard adjustments it is often approved immediately or after a short review. This addresses the root cause directly and allows you to provision the instance as intended.

Why this answer

The error indicates a resource quota (CPU limit) has been reached. The correct action is to request a quota increase in the Cloud Console for the specific region and resource type (CPUs).

58
Multi-Selecthard

An organization wants to ensure that all projects in their GCP organization have consistent IAM policies. They also need to restrict the use of external IP addresses on Compute Engine instances for security. Which TWO tools should they use? (Choose TWO.)

Select 2 answers
A.Use an organization policy constraint 'compute.vmExternalIpAccess' at the organization level
B.Apply a deny IAM policy to each project individually
C.Set a quota for external IP addresses per project
D.Use network tags to block external IPs
E.Define IAM policies at the organization level
AnswersA, E

The organization policy constraint 'compute.vmExternalIpAccess' is a list constraint that can be applied at the organization, folder, or project level. When set at the organization level, it is inherited by all child resources, allowing you to centrally deny or restrict the assignment of external IP addresses to VM instances across every project. This is the correct approach because it is a hard enforcement mechanism that cannot be bypassed by project-level IAM or quota changes, and it provides a consistent, organization-wide security guardrail.

Why this answer

Organization policies can enforce restrictions like disabling external IP addresses across the entire organization. IAM policies at the organization level can set baseline access controls inherited by all projects.

59
MCQeasy

A startup wants to organize its Google Cloud resources by separating development, staging, and production environments. They also need to apply common IAM policies across all projects in each environment. Which resource hierarchy component should they use to group projects per environment?

A.Organization node
B.Tags
C.Folders
D.Labels
AnswerC

Folders are nodes in the resource hierarchy that sit between the organization node and projects, and they can contain both projects and other folders, enabling a flexible, nested structure. You can create separate folders for dev, staging, and production, and IAM policies assigned to a folder are inherited by every project inside it, which centralizes access control. This is the correct choice because it gives you a hierarchical grouping with policy inheritance, exactly what an environment-based organization needs.

Why this answer

Folders allow grouping of projects and are used to reflect organizational structure or environment separation. IAM policies applied at the folder level are inherited by all projects within that folder.

60
MCQeasy

Which tool would you use to estimate the monthly cost of running a set of Compute Engine virtual machines before deploying them?

A.Cost Management dashboard
B.Active Assist
C.Google Cloud Pricing Calculator
D.Billing export
AnswerC

The Google Cloud Pricing Calculator is an interactive, web-based tool that lets you model a wide range of GCP services—including Compute Engine, Cloud Storage, BigQuery, and networking—by specifying region, tier, and usage levels. It generates an estimated monthly cost in real time, incorporates factors like sustained use and committed use discounts, and is the intended resource for comparing configurations and estimating expenses before building or scaling a solution.

Why this answer

The Google Cloud Pricing Calculator is a web-based tool that allows you to estimate the cost of Google Cloud services, including Compute Engine VMs, before deploying them. It lets you configure VM types, regions, usage hours, and other parameters to get a detailed monthly cost estimate.

Exam trap

The trap is confusing cost estimation with cost monitoring — candidates may pick Cost Management dashboard or Billing export, but those are for post-deployment cost tracking, not pre-deployment estimation.

How to eliminate wrong answers

Option A is wrong because the Cost Management dashboard (now part of Cloud Billing) shows actual and forecasted costs for resources already deployed, not pre-deployment estimates. Option B is wrong because Active Assist provides recommendations and insights for optimizing existing resources, not cost estimation for future deployments. Option D is wrong because Billing export is used to export detailed billing data to BigQuery or Cloud Storage for analysis, not for estimating future costs.

61
MCQeasy

An organization wants to separate billing and access control for two departments, each with multiple projects. They also need to apply common IAM policies to all projects in a department. What is the recommended way to structure their resource hierarchy?

A.Use folders under the organization node, one per department, and place projects inside them
B.Place all resources in a single project and use Cloud Identity groups for access
C.Create one project per department and use labels to separate them
D.Create separate billing accounts per department and link projects directly
AnswerA

Folders under the organization node establish a resource hierarchy where each department's folder can have IAM policies and billing defaults applied, cascading to all projects within. This separates access control by making the department folder an administrative boundary, and also allows aggregated billing per folder by linking a dedicated billing account to that folder, which individual projects inherit.

Why this answer

Folders sit below the organization node and above projects. They allow grouping projects by department and applying IAM policies at the folder level, which are inherited by all projects within.

62
Multi-Selectmedium

An organization needs to enforce that resources in a specific project cannot use certain machine series (e.g., f1-micro) due to performance requirements. They also need to tag resources with an 'environment' label for cost tracking. Which TWO methods should they use? (Choose TWO.)

Select 2 answers
A.Use resource tags (network tags) to deny f1-micro usage
B.Add a label 'environment' to each resource for cost tracking
C.Use Cloud Audit Logs to monitor f1-micro usage and manually enforce
D.Apply a deny IAM policy to prevent creation of f1-micro instances
E.Create an organization policy with a compute.disableMachineSeries constraint at the folder or project level
AnswersB, E

Labels are key-value pairs that can be applied to all Google Cloud resources and are indexed by Cloud Billing for cost allocation and reporting. Adding an `environment` label to each resource allows the organization to break down costs by environment, ensuring accurate cost tracking and chargeback. This satisfies the requirement of enforcing cost tracking, which labels are specifically designed for.

Why this answer

Option B is correct because labels are the standard Google Cloud mechanism for attaching key-value metadata such as 'environment' to resources, and labels are what feed into billing exports and cost breakdown reports for cost tracking. Option E is correct because an organization policy using the compute.disableMachineSeries constraint (a list constraint on compute.googleapis.com/Instance machine types) can be applied at the project or folder level to block creation of instances using the specified machine series like f1-micro, which directly enforces the performance requirement. Option A is incorrect because network tags are used for firewall rules and routing, not for restricting machine types or enforcing policy.

Option C is incorrect because Cloud Audit Logs only provide visibility and post-hoc monitoring, not preventive enforcement. Option D is incorrect because IAM deny policies control who can perform actions based on permissions, not which machine series or resource configurations are allowed.

Exam trap

GCDL often tests the confusion between network tags (firewall/routing) and labels (metadata/billing), and between IAM deny policies (identity permissions) and org policies (resource configuration guardrails).

63
MCQmedium

A company wants to enforce a policy that prevents all projects in the organization from enabling certain Google Cloud APIs. Where should the policy be applied to ensure it is inherited by all projects, including future ones?

A.On the organization node
B.On the billing account
C.On each individual project
D.On the folder containing the projects
AnswerA

The organization node is the root of the Google Cloud resource hierarchy. Organization policies set at this level are inherited by every folder and project beneath it, including future projects that are created later. This is the only placement that guarantees the policy is enforced uniformly across all projects in the organization without any per-project or per-folder exceptions.

Why this answer

Organization policies applied at the organization node are inherited by all folders and projects under it. This is the most efficient way to enforce a blanket restriction across the entire resource hierarchy.

64
Multi-Selectmedium

Which TWO statements about committed use discounts (CUDs) are true? (Choose two.)

Select 2 answers
A.CUDs provide a discount for sustained usage without any upfront commitment.
B.CUDs can be purchased for specific resources such as vCPUs and memory.
C.CUDs can be applied to any Google Cloud service automatically.
D.CUDs are applied automatically without any action from the user.
E.CUDs require a 1-year or 3-year commitment.
AnswersB, E

CUDs are purchased at the resource level, meaning you commit to a specific quantity of a particular resource type, such as virtual CPUs (vCPUs), memory (GB), or GPUs, within a given region or machine family. This allows you to receive a discounted rate for all matching usage that falls within the committed amount. For example, you might commit to 100 vCPUs in us-central1 for 3 years and pay a reduced hourly rate for those vCPUs, regardless of which compatible VM uses them.

Why this answer

Option B is correct because Google Cloud committed use discounts are purchased against specific resource types, such as vCPUs and memory, for example in Compute Engine, where you commit to a certain amount of vCPU and RAM usage in a region. Option E is correct because CUDs are commitment-based discounts that require either a 1-year or 3-year term, in exchange for lower prices on eligible usage. Option A is incorrect because sustained use discounts, not CUDs, are the automatic discounts for sustained usage without any upfront commitment.

Option C is incorrect because CUDs do not apply to any Google Cloud service automatically; they are limited to specific eligible services and resources, such as Compute Engine and some other services with their own commitment models. Option D is incorrect because CUDs are not applied automatically without user action; the user must purchase or sign up for the commitment, unlike sustained use discounts.

Exam trap

GCDL often tests the confusion between committed use discounts (CUDs) and sustained use discounts (SUDs), causing candidates to incorrectly attribute automatic application or lack of commitment to CUDs.

65
MCQeasy

A company has set a budget alert at 80% and 100% of $10,000 for a specific project. The project has a billing account linked. What happens when the cost reaches $8,000?

A.The project is automatically suspended.
B.All resources in the project are deleted.
C.The billing account is disabled.
D.A notification is sent to the configured Pub/Sub topic.
AnswerD

A notification is sent to the configured Pub/Sub topic—this is the correct and primary behavior of a budget alert. When spending (or forecasted spending) exceeds a threshold, the Cloud Billing service publishes a message containing details like the budget name, current cost, and threshold value to the topic you selected. This message can then be consumed by Cloud Functions, Cloud Run, or other services to trigger automated responses, but the alert itself only delivers the notification.

Why this answer

Budget alerts in Google Cloud are informational only; when spend crosses a threshold (80% of $10,000 = $8,000), the configured notification channel — typically a Pub/Sub topic, and optionally email to billing admins — receives a message. No automatic enforcement action is taken on the project or billing account. This is by design: budgets are for visibility, not control.

Exam trap

GCDL often tests the misconception that budget alerts enforce spending limits — candidates assume a budget can suspend or delete resources, when in fact it only sends notifications.

How to eliminate wrong answers

Option A is wrong because Google Cloud budgets do not automatically suspend projects; suspension requires an explicit programmatic action (e.g., a Cloud Function triggered by the Pub/Sub message calling the Cloud Billing API). Option B is wrong because budgets never delete resources — deletion is a destructive action that must be explicitly invoked. Option C is wrong because the billing account is not disabled by a budget alert; disabling billing is a manual or programmatic action, and even then it stops billing rather than being triggered by the alert itself.

66
MCQhard

A company uses folders to separate environments (dev, test, prod) and teams (eng, data, security). An engineer needs to apply a policy that disables the use of 'g1-small' machine types only in the 'dev' folder under the 'eng' folder. The organization node has no existing constraints. What is the most specific way to apply this policy?

A.Apply the policy at the organization node.
B.Apply the policy at each project individually.
C.Apply the policy at the 'dev' folder.
D.Apply the policy at the 'eng' folder.
AnswerC

The dev folder is the node in the resource hierarchy that contains only development projects and subfolders under eng; applying the policy there inherits to all of those descendants. Because the policy does not flow upward or to sibling folders like test or prod, this is the precise way to scope the restriction to just the dev environment. It leverages the hierarchy to define the policy exactly where the environment boundary is intended.

Why this answer

Organization policies are hierarchical and inherit downward, so applying the constraint at the 'dev' folder scopes it precisely to that folder and its projects without affecting sibling folders or the parent 'eng' folder. This is the most specific node that matches the requirement of restricting only the 'dev' environment.

Exam trap

GCDL often tests whether candidates understand policy inheritance and the 'most specific node' principle, so they over-apply at the org or under-apply at projects instead of using the folder.

How to eliminate wrong answers

Option A is wrong because applying at the organization node would enforce the constraint across all folders and projects, far broader than required. Option B is wrong because applying at each project is more granular than needed and harder to manage, and it doesn't leverage folder inheritance. Option D is wrong because applying at the 'eng' folder would affect all child folders (including test and prod under eng), not just dev.

Ready to test yourself?

Try a timed practice session using only Cdl Resource Management questions.