Google Associate Cloud Engineer sample questions with answers

10 free Google Associate Cloud Engineer sample questions across the exam's domains, each with its answer and an explanation. No account needed.

Google Associate Cloud Engineer sample questions

Google Associate Cloud Engineer, Google Cloud.

  1. Question 1

    Domain: Setting up a cloud solution environment

    Which service provides an inventory of Google Cloud resources across projects, including their IAM policies and change history?

    1. Cloud Asset Inventory
    2. Resource Manager labels
    3. Security Command Center
    4. Cloud Logging
    Show the answer

    Answer: A. Cloud Asset Inventory

    Cloud Asset Inventory records the metadata and IAM policies of resources with a time-series history and lets you search and export assets. Cloud Logging stores logs, not an asset inventory.

    Checked against: https://cloud.google.com/asset-inventory/docs/overview

  2. Question 2

    Domain: Setting up a cloud solution environment

    In a newly created project, running gcloud sql instances create fails with an error stating that the API has not been used or is disabled.

    What is the most likely reason?

    1. The user lacks the Billing Account Administrator role on the project's billing account
    2. The Cloud SQL Admin API (sqladmin.googleapis.com) is not enabled in the project
    3. The project has no VPC network
    4. Cloud SQL is not available in the default region configured for the new project
    Show the answer

    Answer: B. The Cloud SQL Admin API (sqladmin.googleapis.com) is not enabled in the project

    Most Google Cloud services require their API to be enabled per project before resources can be created; a new project has only a few APIs enabled by default and gcloud reports an error that the API is disabled. Billing roles and VPC networks are unrelated to this error.

    Checked against: https://cloud.google.com/service-usage/docs/enable-disable

  3. Question 3

    Domain: Planning and implementing a cloud solution

    Which Google Cloud service offers a managed, PostgreSQL-compatible database designed for demanding transactional and analytical workloads?

    1. AlloyDB for PostgreSQL
    2. Bigtable
    3. Cloud Storage with BigQuery external tables
    4. Firestore
    Show the answer

    Answer: A. AlloyDB for PostgreSQL

    AlloyDB is Google's fully managed PostgreSQL-compatible database with a columnar engine for analytics and high availability built in. Bigtable and Firestore are NoSQL, and Cloud Storage is object storage.

    Checked against: https://cloud.google.com/alloydb/docs/overview

  4. Question 4

    Domain: Planning and implementing a cloud solution

    Which database service provides horizontally scalable relational storage with global strong consistency and SQL?

    1. Firestore
    2. Bigtable
    3. Cloud SQL
    4. Spanner
    Show the answer

    Answer: D. Spanner

    Spanner is a globally distributed relational database offering SQL, ACID transactions and horizontal scaling. Cloud SQL is a regional managed MySQL/PostgreSQL/SQL Server, Bigtable is a wide-column NoSQL store, and Firestore is a document database.

    Checked against: https://cloud.google.com/spanner/docs/overview

  5. Question 5

    Domain: Planning and implementing a cloud solution

    An analyst needs to load several CSV files from a Cloud Storage bucket into the BigQuery table sales.transactions, letting BigQuery detect the schema.

    Which command loads the data?

    1. bq query --use_legacy_sql=false 'LOAD gs://my-bucket/transactions-*.csv'
    2. gcloud bigquery import sales.transactions gs://my-bucket/
    3. bq load --source_format=CSV --autodetect sales.transactions gs://my-bucket/transactions-*.csv
    4. gcloud storage cp gs://my-bucket/transactions-*.csv bq://sales.transactions --source_format=CSV
    Show the answer

    Answer: C. bq load --source_format=CSV --autodetect sales.transactions gs://my-bucket/transactions-*.csv

    The bq load command creates a load job from Cloud Storage URIs (wildcards supported) into a table, with --autodetect inferring the schema. gcloud storage cannot write to BigQuery and there is no gcloud bigquery import command.

    Checked against: https://cloud.google.com/bigquery/docs/loading-data-cloud-storage-csv

  6. Question 6

    Domain: Ensuring the successful operation of a cloud solution

    A batch job accidentally overwrote several important objects in a Cloud Storage bucket, and the team wants to be able to recover previous content if this happens again.

    What is the most reliable way to protect against this?

    1. Take a daily persistent disk snapshot of the bucket's contents so that earlier data can be restored
    2. Enable object versioning so earlier versions are kept when objects are overwritten or deleted
    3. Enable Requester Pays
    4. Set the storage class to Archive
    Show the answer

    Answer: B. Enable object versioning so earlier versions are kept when objects are overwritten or deleted

    Object versioning keeps noncurrent versions when an object is replaced or deleted, so a bad overwrite can be reverted; lifecycle rules can trim old versions. Buckets have no disk snapshots and storage class does not protect content.

    Checked against: https://cloud.google.com/storage/docs/object-versioning

  7. Question 7

    Domain: Ensuring the successful operation of a cloud solution

    A FinOps team wants Google Cloud to suggest which VMs are oversized or idle so they can reduce cost.

    Which tool provides these recommendations?

    1. Cloud Trace, which reports each VM's utilisation alongside request latency data
    2. Bucket Lock reports, which flag VMs whose disks have not been modified recently
    3. Cloud DNS
    4. Active Assist recommenders, such as the machine type and idle VM recommenders
    Show the answer

    Answer: D. Active Assist recommenders, such as the machine type and idle VM recommenders

    Active Assist uses recommenders to analyse usage and suggest rightsizing, idle resource cleanup and IAM reductions, viewable in the Recommendation Hub. Trace, DNS and Bucket Lock do not offer optimisation advice.

    Checked against: https://cloud.google.com/recommender/docs/whatis-activeassist

  8. Question 8

    Domain: Ensuring the successful operation of a cloud solution

    A Deployment applied to a GKE Autopilot cluster runs, but the Pods are sized differently from what the team expected and the bill is higher than planned.

    What is the likely cause and fix?

    1. The Pod needs a node selector for the default node pool
    2. The cluster needs a manually added node pool
    3. Autopilot applies default and minimum Pod requests; set explicit CPU and memory requests
    4. Autopilot does not support Deployments
    Show the answer

    Answer: C. Autopilot applies default and minimum Pod requests; set explicit CPU and memory requests

    In Autopilot, Google sets default requests when none are specified and adjusts requests to allowed minimums and ratios; you control Pod sizing by specifying requests explicitly. Autopilot manages node pools, so adding them manually is not possible.

    Checked against: https://cloud.google.com/kubernetes-engine/docs/concepts/autopilot-resource-requests

  9. Question 9

    Domain: Configuring access and security

    Which role must a user have on a service account to attach it to a Compute Engine VM they create?

    1. Service Account Admin
    2. Service Account Key Admin (roles/iam.serviceAccountKeyAdmin)
    3. Service Account User (roles/iam.serviceAccountUser)
    4. Compute Viewer
    Show the answer

    Answer: C. Service Account User (roles/iam.serviceAccountUser)

    Attaching a service account to a resource lets the resource act as that account, so IAM requires the creator to hold iam.serviceAccountUser (or a role including iam.serviceAccounts.actAs) on the service account. Admin roles manage the account itself.

    Checked against: https://cloud.google.com/iam/docs/attach-service-accounts

  10. Question 10

    Domain: Configuring access and security

    An ingestion VM publishes messages to a Pub/Sub topic, and a Cloud Run service subscribes and writes rows to a BigQuery dataset.

    Which arrangement provides least privilege for the two components?

    1. Separate service accounts: Publisher for the VM; Subscriber and BigQuery Data Editor for Cloud Run
    2. The default Compute Engine service account shared by both components, with its broad Editor role removed
    3. Owner on the project for the processing service
    4. One shared service account with the project Editor role, used by both the VM and the Cloud Run service
    Show the answer

    Answer: A. Separate service accounts: Publisher for the VM; Subscriber and BigQuery Data Editor for Cloud Run

    Separate identities per component with roles scoped to specific resources mean a compromise of one component cannot read or write beyond its need. Editor or Owner would allow either component to modify unrelated resources.

    Checked against: https://cloud.google.com/iam/docs/best-practices-for-securing-service-accounts

More practice

A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.

Google Associate Cloud Engineer course and practice exam: Google Cloud certification: the exam guide, with the format, cost, pass mark and domains from the vendor.