Google Associate Cloud Engineer sample questions with answers
10 free Google Associate Cloud Engineer sample questions across the exam's domains, each with its answer and an explanation. No account needed.
Google Associate Cloud Engineer sample questions
Google Associate Cloud Engineer, Google Cloud.
Question 1
Domain: Setting up a cloud solution environment
Which service provides an inventory of Google Cloud resources across projects, including their IAM policies and change history?
- Cloud Asset Inventory
- Resource Manager labels
- Security Command Center
- Cloud Logging
Show the answer
Answer: A. Cloud Asset Inventory
Cloud Asset Inventory records the metadata and IAM policies of resources with a time-series history and lets you search and export assets. Cloud Logging stores logs, not an asset inventory.
Checked against: https://cloud.google.com/asset-inventory/docs/overview
Question 2
Domain: Setting up a cloud solution environment
In a newly created project, running gcloud sql instances create fails with an error stating that the API has not been used or is disabled.
What is the most likely reason?
- The user lacks the Billing Account Administrator role on the project's billing account
- The Cloud SQL Admin API (sqladmin.googleapis.com) is not enabled in the project
- The project has no VPC network
- Cloud SQL is not available in the default region configured for the new project
Show the answer
Answer: B. The Cloud SQL Admin API (sqladmin.googleapis.com) is not enabled in the project
Most Google Cloud services require their API to be enabled per project before resources can be created; a new project has only a few APIs enabled by default and gcloud reports an error that the API is disabled. Billing roles and VPC networks are unrelated to this error.
Checked against: https://cloud.google.com/service-usage/docs/enable-disable
Question 3
Domain: Planning and implementing a cloud solution
Which Google Cloud service offers a managed, PostgreSQL-compatible database designed for demanding transactional and analytical workloads?
- AlloyDB for PostgreSQL
- Bigtable
- Cloud Storage with BigQuery external tables
- Firestore
Show the answer
Answer: A. AlloyDB for PostgreSQL
AlloyDB is Google's fully managed PostgreSQL-compatible database with a columnar engine for analytics and high availability built in. Bigtable and Firestore are NoSQL, and Cloud Storage is object storage.
Checked against: https://cloud.google.com/alloydb/docs/overview
Question 4
Domain: Planning and implementing a cloud solution
Which database service provides horizontally scalable relational storage with global strong consistency and SQL?
- Firestore
- Bigtable
- Cloud SQL
- Spanner
Show the answer
Answer: D. Spanner
Spanner is a globally distributed relational database offering SQL, ACID transactions and horizontal scaling. Cloud SQL is a regional managed MySQL/PostgreSQL/SQL Server, Bigtable is a wide-column NoSQL store, and Firestore is a document database.
Checked against: https://cloud.google.com/spanner/docs/overview
Question 5
Domain: Planning and implementing a cloud solution
An analyst needs to load several CSV files from a Cloud Storage bucket into the BigQuery table sales.transactions, letting BigQuery detect the schema.
Which command loads the data?
- bq query --use_legacy_sql=false 'LOAD gs://my-bucket/transactions-*.csv'
- gcloud bigquery import sales.transactions gs://my-bucket/
- bq load --source_format=CSV --autodetect sales.transactions gs://my-bucket/transactions-*.csv
- gcloud storage cp gs://my-bucket/transactions-*.csv bq://sales.transactions --source_format=CSV
Show the answer
Answer: C. bq load --source_format=CSV --autodetect sales.transactions gs://my-bucket/transactions-*.csv
The bq load command creates a load job from Cloud Storage URIs (wildcards supported) into a table, with --autodetect inferring the schema. gcloud storage cannot write to BigQuery and there is no gcloud bigquery import command.
Checked against: https://cloud.google.com/bigquery/docs/loading-data-cloud-storage-csv
Question 6
Domain: Ensuring the successful operation of a cloud solution
A batch job accidentally overwrote several important objects in a Cloud Storage bucket, and the team wants to be able to recover previous content if this happens again.
What is the most reliable way to protect against this?
- Take a daily persistent disk snapshot of the bucket's contents so that earlier data can be restored
- Enable object versioning so earlier versions are kept when objects are overwritten or deleted
- Enable Requester Pays
- Set the storage class to Archive
Show the answer
Answer: B. Enable object versioning so earlier versions are kept when objects are overwritten or deleted
Object versioning keeps noncurrent versions when an object is replaced or deleted, so a bad overwrite can be reverted; lifecycle rules can trim old versions. Buckets have no disk snapshots and storage class does not protect content.
Checked against: https://cloud.google.com/storage/docs/object-versioning
Question 7
Domain: Ensuring the successful operation of a cloud solution
A FinOps team wants Google Cloud to suggest which VMs are oversized or idle so they can reduce cost.
Which tool provides these recommendations?
- Cloud Trace, which reports each VM's utilisation alongside request latency data
- Bucket Lock reports, which flag VMs whose disks have not been modified recently
- Cloud DNS
- Active Assist recommenders, such as the machine type and idle VM recommenders
Show the answer
Answer: D. Active Assist recommenders, such as the machine type and idle VM recommenders
Active Assist uses recommenders to analyse usage and suggest rightsizing, idle resource cleanup and IAM reductions, viewable in the Recommendation Hub. Trace, DNS and Bucket Lock do not offer optimisation advice.
Checked against: https://cloud.google.com/recommender/docs/whatis-activeassist
Question 8
Domain: Ensuring the successful operation of a cloud solution
A Deployment applied to a GKE Autopilot cluster runs, but the Pods are sized differently from what the team expected and the bill is higher than planned.
What is the likely cause and fix?
- The Pod needs a node selector for the default node pool
- The cluster needs a manually added node pool
- Autopilot applies default and minimum Pod requests; set explicit CPU and memory requests
- Autopilot does not support Deployments
Show the answer
Answer: C. Autopilot applies default and minimum Pod requests; set explicit CPU and memory requests
In Autopilot, Google sets default requests when none are specified and adjusts requests to allowed minimums and ratios; you control Pod sizing by specifying requests explicitly. Autopilot manages node pools, so adding them manually is not possible.
Checked against: https://cloud.google.com/kubernetes-engine/docs/concepts/autopilot-resource-requests
Question 9
Domain: Configuring access and security
Which role must a user have on a service account to attach it to a Compute Engine VM they create?
- Service Account Admin
- Service Account Key Admin (roles/iam.serviceAccountKeyAdmin)
- Service Account User (roles/iam.serviceAccountUser)
- Compute Viewer
Show the answer
Answer: C. Service Account User (roles/iam.serviceAccountUser)
Attaching a service account to a resource lets the resource act as that account, so IAM requires the creator to hold iam.serviceAccountUser (or a role including iam.serviceAccounts.actAs) on the service account. Admin roles manage the account itself.
Checked against: https://cloud.google.com/iam/docs/attach-service-accounts
Question 10
Domain: Configuring access and security
An ingestion VM publishes messages to a Pub/Sub topic, and a Cloud Run service subscribes and writes rows to a BigQuery dataset.
Which arrangement provides least privilege for the two components?
- Separate service accounts: Publisher for the VM; Subscriber and BigQuery Data Editor for Cloud Run
- The default Compute Engine service account shared by both components, with its broad Editor role removed
- Owner on the project for the processing service
- One shared service account with the project Editor role, used by both the VM and the Cloud Run service
Show the answer
Answer: A. Separate service accounts: Publisher for the VM; Subscriber and BigQuery Data Editor for Cloud Run
Separate identities per component with roles scoped to specific resources mean a compromise of one component cannot read or write beyond its need. Editor or Owner would allow either component to modify unrelated resources.
Checked against: https://cloud.google.com/iam/docs/best-practices-for-securing-service-accounts
More practice
A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.
Google Associate Cloud Engineer course and practice exam: Google Cloud certification: the exam guide, with the format, cost, pass mark and domains from the vendor.