ACE sample questions with answers

10 free practice questions for the Associate Cloud Engineer exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Setting up a cloud solution environment

Veltrix Design has hired a 30-person agency for six months. The agency's staff sign in to their employer's Okta tenant, and Veltrix policy forbids issuing Cloud Identity accounts to anyone who is not an employee. During the engagement they must use the Google Cloud console to read objects in one Cloud Storage bucket, and Veltrix wants no account lifecycle work of its own. What should you do?

  1. A.

    Create 30 Cloud Identity accounts in the Veltrix domain, grant each roles/storage.objectViewer on the bucket, and delete the accounts after six months.

  2. B.

    Create one service account, grant it roles/storage.objectViewer on the bucket, download a JSON key, and email the key to the agency.

  3. C.

    Configure Workload Identity Federation so that Okta tokens are exchanged for credentials of a service account that has roles/storage.objectViewer on the bucket.

  4. D.

    Configure Workforce Identity Federation: create a workforce pool with an OIDC provider for the agency's Okta tenant, then grant that pool's principalSet roles/storage.objectViewer on the bucket.

Show answer

Answer: D

Workforce Identity Federation lets external human users sign in to the console with their own IdP, so no Cloud Identity accounts are created and access is bound to the workforce pool.

  • A. Creating Cloud Identity accounts directly violates the stated policy and adds exactly the account lifecycle work Veltrix wants to avoid.
  • B. A shared, emailed service account key gives an untraceable shared identity, cannot be tied to an individual, and is the practice Google explicitly warns against.
  • C. Workload Identity Federation is designed for applications and automated workloads; it does not give people an interactive Google Cloud console session.
  • D. Workforce Identity Federation gives external human users console sign-in through their own IdP with IAM bound to the pool, and creates no Google accounts.
Question 2Setting up a cloud solution environment

Grand Harbour Group owns two legal entities that must receive separate Google Cloud invoices and must not see each other's costs. Both keep their projects inside the group's single organization, and central IT continues to administer every project. Each entity's finance lead needs read-only visibility of their own entity's charges and nothing more. What should you do?

  1. A.

    Create a separate Google Cloud organization for each legal entity, migrate its projects there, and grant its finance lead roles/billing.viewer on the new organization.

  2. B.

    Create one Cloud Billing account per legal entity, link that entity's projects to it, and grant the entity's finance lead roles/billing.viewer on that account.

  3. C.

    Grant each finance lead roles/billing.admin at the organization node so that each can build cost reports for their own entity's projects.

  4. D.

    Keep the group's single billing account, label every project with legal-entity, and grant each finance lead roles/billing.viewer on that account to filter their own charges.

Show answer

Answer: B

One Cloud Billing account per legal entity produces separate invoices, and Billing Account Viewer on only that account gives each finance lead read-only sight of their own charges.

  • A. Splitting the organization is a heavyweight migration that breaks central IT's administration and is unnecessary, because billing is already independent of the hierarchy.
  • B. The billing account is the invoicing boundary, so one per legal entity yields separate invoices, and billing.viewer bound on that account alone is read-only and scoped to it.
  • C. Billing Administrator at the organization is write access over every billing account, the opposite of the read-only, single-entity scope required.
  • D. A label slices cost reporting inside one billing account but still produces one combined invoice, and viewer on the shared account exposes both entities' charges.
Question 3Setting up a cloud solution environment

Auros Bank has ruled that no Compute Engine instance beneath the payments folder may have an external IP address. Several teams create projects under that folder, and the rule must apply automatically to projects that do not exist yet. Developers keep Compute Admin in their own projects, and you hold Organization Policy Administrator. What should you do?

  1. A.

    Create a hierarchical firewall policy on the payments folder that denies all egress traffic to 0.0.0.0/0.

  2. B.

    Remove roles/compute.admin from the developers in every project under the folder and grant roles/compute.viewer instead.

  3. C.

    Set the constraints/compute.vmExternalIpAccess list constraint on the payments folder with an empty allowed-values list so all external IPs are denied.

  4. D.

    Add a VPC firewall rule in each project that denies ingress from 0.0.0.0/0 to all instances.

Show answer

Answer: C

The compute.vmExternalIpAccess organization policy constraint, set at the folder with an empty allow list, blocks external IPs on all current and future child projects.

  • A. A firewall policy filters traffic; it never stops an external IP from being attached, and denying all egress would break Cloud NAT and Google API access.
  • B. Stripping Compute Admin blocks all instance management, not just external IPs, and any user who keeps create rights could still attach one.
  • C. This constraint is purpose-built to forbid external IP assignment and is inherited by all current and future projects under the folder.
  • D. Per-project ingress rules are manual, do not apply to new projects, and again filter packets rather than prevent IP assignment.
Question 4Setting up a cloud solution environment

Northwind Analytics runs 40 projects in one organization; 18 belong to the Retail business unit. The internal audit group must read the configuration of every resource in the Retail projects and in no other project. Retail creates two or three new projects each month, and you do not want to revisit the audit group's access each time. What should you do?

  1. A.

    Grant the audit group roles/browser at the organization node and ask Retail to tag their projects with unit=retail.

  2. B.

    Create a retail folder, move the 18 projects into it, have new Retail projects created in that folder, and grant the audit group roles/viewer on the folder.

  3. C.

    Grant the audit group roles/viewer on each of the 18 Retail projects, and add a "grant audit viewer" step to the project-creation runbook for projects created later.

  4. D.

    Grant the audit group roles/viewer at the organization node so that every current and future project is covered.

Show answer

Answer: B

A folder that holds the business unit's projects lets one roles/viewer binding inherit down to every current and future project in that unit.

  • A. roles/browser only reveals the hierarchy (project, folder and organization metadata); it does not let auditors read resource configuration, and labels do not grant access.
  • B. A folder-level binding is inherited by all current and future child projects, scoping read access to exactly the Retail unit.
  • C. Per-project bindings require a manual step every month, exactly the recurring work the requirement rules out.
  • D. An organization-level viewer binding also exposes the other 22 projects, which breaches the stated "and no other project" constraint.
Question 5Setting up a cloud solution environment

Cindermill Foods wants to be warned when spend on the data-platform-prod project reaches 50%, 90% and 100% of a monthly US$40,000 budget. The warnings must reach the finance-alerts mailing list, which holds no IAM role and must not be granted one, and no custom code may be run. What should you do?

  1. A.

    Create a Cloud Billing budget scoped to the project with threshold rules at 50%, 90% and 100%, and attach a Cloud Monitoring email notification channel for finance-alerts to the budget.

  2. B.

    Create a budget on the billing account with a single 100% threshold so that finance is notified once total spend across all projects reaches $40,000.

  3. C.

    Enable billing export to BigQuery and schedule a query that compares month-to-date spend with $40,000 and emails the list when a threshold is crossed.

  4. D.

    Create the budget with the three thresholds and rely on the default email to Billing Account Administrators and Users, then ask those recipients to forward each alert to the finance-alerts list.

Show answer

Answer: A

A budget scoped to the project with three thresholds plus a Cloud Monitoring email notification channel delivers alerts to an arbitrary address with no IAM grant and no code.

  • A. Project-scoped budget with three thresholds meets the spend requirement, and a Monitoring email channel reaches the list without any IAM grant or code.
  • B. A billing-account-scoped budget measures spend across every project and only one threshold, so it misses both the project scope and the 50% and 90% warnings.
  • C. A scheduled query with custom email logic is exactly the custom code the company ruled out, and duplicates a managed feature.
  • D. Manual forwarding by billing administrators is unreliable and still fails the requirement that finance be notified directly.
Question 6Setting up a cloud solution environment

Delphine Ceramics wants a newly appointed team lead to attach freshly created projects to the company billing account and to detach projects being decommissioned. The lead must not change the payment instrument, close the billing account, or grant billing roles. All of the projects sit in the workshop folder. Following least privilege, what should you do?

  1. A.

    Grant the lead roles/billing.admin on the billing account.

  2. B.

    Grant the lead roles/billing.user on the billing account and roles/billing.projectManager on the workshop folder.

  3. C.

    Grant the lead roles/owner on every project in the workshop folder.

  4. D.

    Grant the lead roles/billing.viewer on the billing account and roles/editor on the workshop folder.

Show answer

Answer: B

Linking a project to a billing account needs Billing Account User on the account plus Project Billing Manager on the project or folder — two narrow roles, not Billing Administrator.

  • A. Billing Administrator can change the payment instrument, close the account and grant billing roles, all of which are explicitly forbidden.
  • B. Billing Account User plus Project Billing Manager is the documented minimum pair for linking and unlinking projects, and excludes payment and role management.
  • C. Owner does include billing assignment but also grants full control of every resource in those projects, far beyond the requirement.
  • D. Billing Account Viewer is read-only, so the lead could not link a project at all, and folder Editor grants broad resource write access instead.
Question 7Setting up a cloud solution environment

Rowanpike Retail's finance team wants a Data Studio (formerly Looker Studio) dashboard breaking last quarter's Google Cloud spend down by project, by service and by the cost-centre label. It must refresh daily with no recurring manual step, and the analysts want to write their own SQL against the underlying data. What should you do?

  1. A.

    Open the Cost table report in the console, export it to CSV each morning, and upload the file to a Cloud Storage bucket for Data Studio.

  2. B.

    Download the monthly invoice CSV from the billing console and load it into BigQuery with bq load at the start of each month.

  3. C.

    Enable standard usage cost export from the Cloud Billing account into a BigQuery dataset, then point Data Studio at the exported table.

  4. D.

    Configure a file export of billing data to a Cloud Storage bucket and have analysts read the CSV objects with gcloud storage cat.

Show answer

Answer: C

Cloud Billing export to BigQuery continuously delivers detailed cost rows, including labels, that Data Studio (formerly Looker Studio) and SQL can query directly.

  • A. A daily console export is precisely the recurring manual step the team rejected, and CSV in a bucket is not SQL-queryable.
  • B. An invoice CSV is a monthly manual download, lacks the label detail, and cannot support a daily refresh.
  • C. BigQuery billing export delivers labelled, per-service cost rows continuously and is directly queryable by SQL and Data Studio.
  • D. File export to Cloud Storage produces flat files that analysts cannot query with SQL, and reading them with gcloud storage cat is not analysis.
Question 8Setting up a cloud solution environment

Pellmeyer Health runs 120 projects in one organization. Compliance asks for an immediate list of every Compute Engine instance and Cloud Storage bucket anywhere in the organization, and the same inventory refreshed into BigQuery nightly so analysts can join it to other tables with SQL. You hold Cloud Asset Viewer and BigQuery Data Editor at the organization. Which two actions should you take? (Choose TWO.)

Choose 2.

  1. A.

    Ask each project owner to run gcloud compute instances list and gcloud storage ls and to email you the output.

  2. B.

    Enable Data Access audit logs for Compute Engine and Cloud Storage in every project and query the resulting log entries.

  3. C.

    Build a Cloud Monitoring dashboard containing instance count and bucket count charts for the organization.

  4. D.

    Schedule a nightly job that runs gcloud asset export --organization=ORG_ID --content-type=resource --bigquery-table=projects/P/datasets/inventory/tables/assets.

  5. E.

    Run gcloud asset search-all-resources --scope=organizations/ORG_ID --asset-types='compute.googleapis.com/Instance,storage.googleapis.com/Bucket' to produce the immediate list.

Show answer

Answer: D, E

Cloud Asset Inventory answers both needs: search-all-resources for an on-demand organization-wide list, and an asset export to BigQuery for the nightly refresh.

  • A. Manual per-project commands and emailed output cannot be refreshed nightly and depend on 120 people doing the work correctly.
  • B. Data Access audit logs record API calls against resources, not the set of resources that currently exist, and they add substantial log volume and cost.
  • C. Cloud Monitoring charts show metric time series; they do not provide a per-resource inventory with names and configuration that analysts can join in SQL.
  • D. asset export writes a resource snapshot straight into BigQuery, so a nightly schedule produces the SQL-queryable refreshed inventory.
  • E. search-all-resources queries the asset index across the whole organization scope and filters by asset type, giving the immediate inventory in one command.
Question 9Setting up a cloud solution environment

A new analyst at Pentlow Group must be able to browse the organization's folder and project hierarchy in the console, and to browse datasets and preview table data in the pg-warehouse project. They must gain no other access anywhere. What should you do?

  1. A.

    Grant roles/browser at the organization node and roles/bigquery.dataViewer on the pg-warehouse project.

  2. B.

    Grant roles/resourcemanager.organizationViewer at the organization node and roles/bigquery.dataViewer on the pg-warehouse project.

  3. C.

    Grant roles/browser at the organization node and roles/bigquery.admin on the pg-warehouse project.

  4. D.

    Grant roles/viewer at the organization node, which covers both the hierarchy and the BigQuery data.

Show answer

Answer: A

Browser at the organization shows the folder and project hierarchy without resource access, and BigQuery Data Viewer on the one project allows browsing datasets and reading table data.

  • A. Browser covers the hierarchy without resource access, and Data Viewer on the one project covers dataset browsing and table preview.
  • B. Organization Viewer only shows the organization resource itself, not the folders and projects beneath it.
  • C. BigQuery Admin adds full control of datasets, tables and their permissions, which is far more than browsing.
  • D. Basic Viewer at the organization grants read access to nearly every resource in every project, breaking the no-other-access requirement.
Question 10Setting up a cloud solution environment

A project at Stanmere Publishing was created with the default VPC network and is being promoted to production. The security team wants the network hardened, while the existing web tier must keep serving HTTPS to the internet. Which TWO actions should you take? (Choose TWO.)

Choose 2.

  1. A.

    Delete the implied deny-ingress rule, because it is what blocks the HTTPS traffic the web tier serves.

  2. B.

    Replace the broad default-allow-internal rule with rules that permit only the ports each tier actually needs from each source.

  3. C.

    Delete the automatically created default-allow-ssh and default-allow-rdp rules and reach instances through Identity-Aware Proxy TCP forwarding instead.

  4. D.

    Convert the network from auto mode to custom mode, which removes the automatically created firewall rules.

  5. E.

    Add an ingress rule at the lowest priority that allows all traffic from 0.0.0.0/0, so that health checks are never blocked.

Show answer

Answer: B, C

Hardening a default network means removing the wide-open management rules and narrowing the blanket internal-allow rule to the ports actually needed.

  • A. Implied rules cannot be deleted, and the implied deny is not what governs the HTTPS traffic, which an explicit allow rule already permits.
  • B. The blanket internal-allow rule lets any instance reach any other on any port, so narrowing it is core hardening.
  • C. Those two rules accept management ports from any address; IAP TCP forwarding replaces them with IAM-authorised access.
  • D. Switching to custom mode stops automatic subnet creation; it leaves the existing firewall rules untouched.
  • E. An allow-all rule from the internet would undo every other hardening step in the list.

Keep going with 539 more ACE questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

ACE sample questions with answers (10 free) · CertifyCloudx