Google Cloud Associate Cloud Engineer Practice Exam
Practice questions for the Google Cloud Associate Cloud Engineer certification: the resource hierarchy, organization policies, Cloud Identity, IAM basics, billing accounts, budgets, billing export, APIs and the gcloud CLI; Compute Engine, managed instance groups, GKE Standard and Autopilot, Cloud Run, Cloud Run functions and App Engine; Cloud Storage classes and lifecycle, Cloud SQL, AlloyDB, Spanner, Firestore, Bigtable, BigQuery and Memorystore; VPC networks, firewall rules and policies, Cloud NAT, load balancing, Cloud VPN, Cloud Interconnect, Shared VPC, VPC Network Peering and Private Google Access; Terraform, Cloud Foundation Toolkit and Infrastructure Manager; snapshots, images, GKE and Cloud Run operations, Cloud Monitoring, Cloud Logging, log sinks, Error Reporting and Cloud Trace; and IAM roles, service accounts, impersonation, Workload Identity Federation and audit logs. Every question includes a written explanation.
100 questions · 12 free preview
Studying more than one? All Google Cloud exams for $29 · every exam for $79
Free sample questions
- Sample · question 1 · Coldline minimum storage duration charge
A team at Orchard Lane stored 5 TB of quarterly reports in a Coldline bucket and deleted them 20 days later after realizing they were duplicates. What billing effect should they expect?
- A.An early deletion charge, because Coldline has a 90-day minimum storage duration and they are billed as if the objects were stored for the remainder of itcorrect
- B.A retrieval charge for each object, because deleting an object counts as reading it
- C.No extra charge, because deletion in any class stops billing immediately
- D.A charge for 365 days of storage, because Coldline has a one-year minimum
Why: Coldline objects have a 90-day minimum storage duration, so deleting them earlier incurs a charge equal to storing them for the rest of that period. The one-year minimum applies to Archive, not Coldline. Deleting objects does not count as data retrieval.
Open this question on its own page → - Sample · question 2 · Cloud Run jobs for run-to-completion tasks
Every night, Pebblestone Media must run a containerized script that resizes images for about 20 minutes and then exits. It does not serve HTTP requests. Which Google Cloud option fits best with the least management?
- A.A Cloud Run service with minimum instances set to 1
- B.A GKE Standard cluster dedicated to the script
- C.A Cloud Run job executed on a schedulecorrect
- D.An App Engine standard service with a cron.yaml file
Why: Cloud Run jobs run containers that perform work and exit, and they can be executed on a schedule without any servers to manage. Cloud Run services are designed to serve requests, and keeping an instance warm wastes money. A dedicated GKE cluster adds operational overhead, and App Engine cron calls HTTP handlers rather than running a container to completion.
Open this question on its own page → - Sample · question 3 · Auto mode VPC creates regional subnets
An engineer at Brindle Sports creates a new VPC network in auto mode. What happens to subnets?
- A.No subnets are created until the engineer adds them manually
- B.A single global subnet is created that spans all regions
- C.One subnet is created automatically in each region from a predefined IP range, and subnets are added as new regions become availablecorrect
- D.One subnet is created in each zone of the engineer's default region
Why: Auto mode networks automatically get one subnet per region using predefined ranges within 10.128.0.0/9, and new regions get subnets added automatically. Custom mode networks start with no subnets. Subnets are regional, never global or zonal.
Open this question on its own page → - Sample · question 4 · App Engine traffic splitting between versions
Halcyon Tours deployed version v2 of its App Engine default service alongside v1. It wants 20% of users to reach v2 while 80% stay on v1. Which command does this?
- A.gcloud app instances split default --v2=20
- B.gcloud app versions migrate v2 --percent=20
- C.gcloud app deploy --version=v2 --traffic=20
- D.gcloud app services set-traffic default --splits=v1=0.8,v2=0.2correct
Why: gcloud app services set-traffic with the --splits flag distributes traffic between versions using fractional weights. Deploying a version does not accept a percentage for traffic, gcloud app versions migrate moves all traffic to a version rather than a fraction, and gcloud app instances has no split command.
Open this question on its own page → - Sample · question 5 · gcloud config list active settings
Before running a destructive command, an engineer at Kestrel Waters wants to confirm which account and project her gcloud CLI is currently using. Which command shows this?
- A.gcloud projects list
- B.gcloud config listcorrect
- C.gcloud info --show-log
- D.gcloud auth print-access-token
Why: gcloud config list displays the properties of the active configuration, including the account and project. gcloud projects list shows every project the account can access rather than the active one, printing an access token reveals a credential instead of settings, and the --show-log option prints the last log file.
Open this question on its own page → - Sample · question 6 · Globally unique Cloud Storage bucket names
Running gcloud storage buckets create gs://backups --location=us-east1 fails at Fairhaven Labs because the name is unavailable, although the company has no bucket with that name. Why?
- A.Bucket names share a single global namespace, so another customer already uses that namecorrect
- B.Bucket names must include the project ID as a prefix
- C.Buckets must be created with gsutil rather than gcloud storage
- D.The us-east1 region does not allow new buckets
Why: Cloud Storage bucket names are globally unique across all Google Cloud customers, so a common name is often already taken and a more specific name is needed. Project IDs are not required in bucket names, us-east1 supports buckets, and gcloud storage is the recommended CLI for creating them.
Open this question on its own page → - Sample · question 7 · bq load CSV into a table
An analyst at Thistle Grocers must load the file gs://thistle-exports/sales.csv, which has a header row, into the BigQuery table retail.sales_raw with schema auto-detection. Which command should she run?
- A.bq cp gs://thistle-exports/sales.csv retail.sales_raw
- B.bq query --destination_table=retail.sales_raw gs://thistle-exports/sales.csv
- C.bq extract retail.sales_raw gs://thistle-exports/sales.csv
- D.bq load --source_format=CSV --skip_leading_rows=1 --autodetect retail.sales_raw gs://thistle-exports/sales.csvcorrect
Why: bq load imports data from Cloud Storage into a table, and the flags set the CSV format, skip the header row and infer the schema. bq query runs SQL rather than loading files, bq cp copies tables, and bq extract exports a table to Cloud Storage, the opposite direction.
Open this question on its own page → - Sample · question 8 · kubectl rollout undo for bad releases
Minutes after updating the image of the billing Deployment in a GKE cluster at Quayside Finance, error rates spike. The team wants to return the Deployment to its previous revision immediately. Which command should they run?
- A.kubectl delete deployment billing
- B.kubectl scale deployment billing --replicas=0
- C.kubectl rollout undo deployment billingcorrect
- D.gcloud container clusters upgrade billing --rollback
Why: kubectl rollout undo rolls a Deployment back to its previous revision using the stored rollout history. Deleting the Deployment or scaling it to zero causes a full outage, and gcloud container clusters upgrade manages cluster versions rather than application revisions.
Open this question on its own page → - Sample · question 9 · Browser role for hierarchy visibility
A project coordinator at Velmont Group must be able to browse the organization's folders and projects in the console to find project owners, but must not see resources such as VMs or buckets inside the projects. Which role fits best?
- A.Browser (roles/browser)correct
- B.Compute Viewer (roles/compute.viewer)
- C.Folder Admin (roles/resourcemanager.folderAdmin)
- D.Viewer (roles/viewer)
Why: The Browser role grants read access to browse the resource hierarchy, including folders and projects and their IAM policies, without access to the resources inside projects. Viewer is a basic role that can read most resources. Folder Admin can modify folders, and Compute Viewer reads Compute Engine resources, which the coordinator should not see.
Open this question on its own page → - Sample · question 10 · Log Analytics SQL queries on logs
Site reliability engineers at Garnet Cloudworks want to run SQL queries, including joins and aggregations, over their Cloud Logging data without exporting it first. What should they use?
- A.Error Reporting on the project
- B.Log Analytics on a log bucket that has been upgraded to use itcorrect
- C.Cloud Trace analysis reports
- D.A log-based metric with a distribution type
Why: Log Analytics lets you query log entries stored in upgraded log buckets with SQL directly from Cloud Logging. Error Reporting groups exceptions, log-based metrics produce time series rather than ad hoc SQL results, and Cloud Trace reports cover request latency.
Open this question on its own page → - Sample · question 11 · Cloud SQL Auth Proxy benefits
Developers at Moorfield Apps connect to a Cloud SQL for PostgreSQL instance from Compute Engine VMs. Why might they use the Cloud SQL Auth Proxy? (Select TWO.)
- A.It increases the maximum storage size of the instance
- B.It removes the need for database users and passwords in every case
- C.It authorizes connections using IAM permissions instead of maintaining authorized network IP listscorrect
- D.It replicates the database to the VM for faster local reads
- E.It encrypts connections automatically without the team managing SSL/TLS certificatescorrect
Why: The Cloud SQL Auth Proxy authorizes connections using IAM and encrypts traffic with TLS automatically, so no authorized networks or certificate management is needed. It does not replicate data or change instance storage limits. Unless IAM database authentication is configured, database user credentials are still required.
Open this question on its own page → - Sample · question 12 · Secret Manager for application credentials
A Cloud Run service at Oakhurst Ticketing needs a third-party API token. Today the token is hard-coded in the source repository. The team wants it stored centrally, versioned and readable only by the service's identity. What should they use?
- A.A label on the Cloud Run service containing the token
- B.Secret Manager, granting the service's service account the Secret Manager Secret Accessor role on the secretcorrect
- C.A Cloud Storage object with public read access
- D.A plain environment variable set in the Dockerfile
Why: Secret Manager stores secrets with versioning and audit logging, and granting Secret Accessor only to the service account limits who can read the value; Cloud Run can expose a secret as an environment variable or volume. Values in a Dockerfile end up in the image and repository, public objects are readable by anyone, and labels are metadata visible to anyone who can view the service.
Open this question on its own page →
Like the sample?
Other practice exams
- AnthropicClaude Certified Architect — Foundations100 questions · $19
- CompTIACompTIA Security+ (SY0-701)100 questions · $19
- ISC2CISSP100 questions · $19
- DatabricksDatabricks Data Engineer Associate100 questions · $19
- DatabricksDatabricks Data Engineer Professional100 questions · $19
- Google CloudGoogle Cloud Professional Cloud Architect100 questions · $19
- Google CloudGoogle Cloud Professional Data Engineer100 questions · $19
- HashiCorpTerraform Associate (004)100 questions · $19
- Microsoft Power BI & FabricPower BI Data Analyst (PL-300)100 questions · $19
- Microsoft Power BI & FabricFabric Analytics Engineer (DP-600)100 questions · $19
- SnowflakeSnowPro Core (COF-C03)250 questions · $19
- SnowflakeSnowPro Advanced: Data Engineer100 questions · $19
- SnowflakeSnowPro Advanced: Architect100 questions · $19
- AWSAWS Cloud Practitioner (CLF-C02)100 questions · $19
- AWSAWS Solutions Architect Associate (SAA-C03)100 questions · $19
- AWSAWS AI Practitioner (AIF-C01)100 questions · $19
- Microsoft AzureAzure Fundamentals (AZ-900)100 questions · $19
- Microsoft AzureAzure Administrator (AZ-104)100 questions · $19
- Microsoft AzureAzure AI Fundamentals (AI-901)100 questions · $19
- Microsoft AzureAzure Solutions Architect Expert (AZ-305)100 questions · $19