Google CloudAssociate

Associate Cloud Engineer

ACE

Deploy applications, monitor operations and manage enterprise solutions using the Google Cloud console and gcloud CLI.

Duration
120 min
Exam questions
50–60
Passing score
Pass / Fail (undisclosed)
Exam fee
$125
Question formats:Multiple choiceMultiple response
Free plan
3 free papers
Free account
Mocks locked
Pro only
Upgrade to Pro
Every paper and mock exam.
See Pro

Start with free papers Free

You get 3 free practice papers with your plan.

Free
Mixed paper 1
Domain 1 · 25 questions
Free
Mixed paper 2
Domain 1 · 25 questions
Free
Mixed paper 3
Domain 1 · 25 questions

Domain papers 549 questions

Free
Mixed paper 1
25 questions · 60 min
Free
Mixed paper 2
25 questions · 60 min
Free
Mixed paper 3
25 questions · 60 min
Pro
Mixed paper 4
14 questions · 34 min

Mock exams Pro

Full-length, exam-like practice tests. Available with Pro.

Mock exam 1
55 questions · 120 min
Mock exam 2
55 questions · 120 min
Mock exam 3
55 questions · 120 min

Try a sample question

All 10 sample questions →
Question 1Setting up a cloud solution environment

Veltrix Design has hired a 30-person agency for six months. The agency's staff sign in to their employer's Okta tenant, and Veltrix policy forbids issuing Cloud Identity accounts to anyone who is not an employee. During the engagement they must use the Google Cloud console to read objects in one Cloud Storage bucket, and Veltrix wants no account lifecycle work of its own. What should you do?

  1. A.

    Create 30 Cloud Identity accounts in the Veltrix domain, grant each roles/storage.objectViewer on the bucket, and delete the accounts after six months.

  2. B.

    Create one service account, grant it roles/storage.objectViewer on the bucket, download a JSON key, and email the key to the agency.

  3. C.

    Configure Workload Identity Federation so that Okta tokens are exchanged for credentials of a service account that has roles/storage.objectViewer on the bucket.

  4. D.

    Configure Workforce Identity Federation: create a workforce pool with an OIDC provider for the agency's Okta tenant, then grant that pool's principalSet roles/storage.objectViewer on the bucket.

Show answer

Answer: D

Workforce Identity Federation lets external human users sign in to the console with their own IdP, so no Cloud Identity accounts are created and access is bound to the workforce pool.

  • A. Creating Cloud Identity accounts directly violates the stated policy and adds exactly the account lifecycle work Veltrix wants to avoid.
  • B. A shared, emailed service account key gives an untraceable shared identity, cannot be tied to an individual, and is the practice Google explicitly warns against.
  • C. Workload Identity Federation is designed for applications and automated workloads; it does not give people an interactive Google Cloud console session.
  • D. Workforce Identity Federation gives external human users console sign-in through their own IdP with IAM bound to the pool, and creates no Google accounts.

What's on the exam

4 domains · 12 task statements, straight from the official exam guide (as of 2026-09-14).

  1. 1.1Setting up cloud projects and accounts
    • Creating a resource hierarchy
    • Applying organizational policies to the resource hierarchy
    • Granting members Identity and Access Management (IAM) roles within a project
    • Managing users and groups in Cloud Identity (manually and automated)
    • Enabling APIs within projects
    • Provisioning and setting up products in Google Cloud Observability
    • Assessing quotas and requesting increases
    • Setting up standalone organizations
    • Setting up cloud networking
    • Verifying product availability across geographical locations (e.g., regions, zones)
    • Configuring Cloud Asset Inventory and using Gemini Cloud Assist to analyze resources
    • Configuring Workforce Identity Federation
  2. 1.2Managing billing configuration
    • Creating one or more billing accounts
    • Linking projects to a billing account
    • Establishing billing budgets and alerts
    • Setting up billing exports

Outline reproduced from the vendor's public exam guide for study reference.Official guide

ACE practice — frequently asked questions

Are these real ACE exam questions?

No. Every question on CertifyCloudx is original, written by us against Google Cloud's publicly available ACE exam guide to rehearse the skills it lists. None are actual exam questions, and CertifyCloudx is not affiliated with or endorsed by Google Cloud.

How many ACE practice questions are there?

549 practice questions, including 3 full-length timed mock exams and 52 domain papers of up to 25 questions (mixed and by topic). Every question has a detailed explanation of why the right answer wins and why each distractor loses.

Is the content up to date with the current ACE exam guide?

The questions are written against the ACE exam guide dated 2026-09-14, and we revise them when Google Cloud updates the guide.

What question formats are covered?

The same formats the real ACE uses: Multiple choice, Multiple response. Each is rendered and graded the way the exam does it.

How long is the ACE exam and how many questions does it have?

According to Google Cloud's published exam details: 50–60 questions, 120 minutes, passing score Pass / Fail (undisclosed). Our mock exams use the same time limit, with a question count in the middle of that range. Always confirm current details with Google Cloud before booking.

Can I practise ACE for free?

Yes. 3 papers are free, with up to 10 questions a day on the free plan and no card needed. Pro unlocks every paper and mock exam with no daily limit.

Does CertifyCloudx guarantee that I will pass?

No practice material can guarantee a result. CertifyCloudx helps you find and close your weak areas — accuracy by exam-guide domain and topic shows what to study next.