Google Associate Cloud Engineer practice questions
209 free questions with answers and explanations.
- 1.You are setting up a new Google Cloud project for an internal application. The application will use a service account to access various Google Cloud services. As a security best practice, you want to ensure that this service account does not have a static key file that could be compromised. How should you configure the service account for authentication?Configuring access and security
- 2.A data engineering team needs a service account to run batch jobs on Compute Engine instances. These jobs will access data stored in Cloud Storage buckets. To minimize the attack surface, the security team mandates that the service account should not have any directly attached keys, and its credentials should be automatically managed by Google Cloud. Which authentication method should the team use for this service account?Configuring access and security
- 3.A data engineering team needs to grant a newly created service account the ability to invoke Cloud Functions for data processing. This service account should only be able to trigger the function and not modify its configuration or deploy new versions. Which IAM role should be assigned to the service account?Configuring access and security
- 4.A company is implementing a robust security posture across its Google Cloud projects. They want to ensure that all service accounts created within a specific folder adhere to the principle of least privilege, meaning they should only be granted roles that are absolutely necessary for their function. To enforce this, they need a way to review and approve all new IAM role grants to service accounts. Which Google Cloud feature allows for such controlled and auditable role assignments?Configuring access and security
- 5.A new project manager needs to manage virtual machine instances in a specific project, including starting, stopping, and deleting them. However, they should not have permissions to manage networks, disks, or other Compute Engine resources beyond the instances themselves. Which IAM role should be granted to the project manager?Configuring access and security
- 6.A compliance team needs to regularly review IAM policy changes across all projects in a Google Cloud organization. Specifically, they need to know when IAM policies are created, updated, or deleted. Which type of audit log, collected at the organization level, should they monitor?Configuring access and security
- 7.A project manager needs to delegate the responsibility of managing virtual machine instances (creating, starting, stopping, deleting) within a specific Google Cloud project to a new operations engineer. The engineer should not have permissions to manage networking, IAM, or billing for the project. Which predefined IAM role is most appropriate for this task?Configuring access and security
- 8.An organization uses Google Cloud Identity to manage its users. A new employee joins the data science team and needs access to a specific BigQuery dataset for analysis. According to the principle of least privilege, how should you grant this access?Configuring access and security
- 9.A development team is deploying a new application to Google Kubernetes Engine (GKE). The application needs to access data stored in a Cloud Storage bucket within the same Google Cloud project. To ensure the application has the necessary permissions while adhering to the principle of least privilege, which IAM role should be granted to the GKE service account for accessing the Cloud Storage bucket?Configuring access and security
- 10.A company is migrating an on-premises application to Google Cloud. The application uses a custom identity provider for user authentication. You need to configure IAM to allow users from this identity provider to access Google Cloud resources without manually creating Google accounts for each user. Which IAM feature should you implement?Configuring access and security
- 11.A team is developing a highly sensitive application that requires a dedicated service account to interact with Google Cloud APIs. Due to strict security policies, the service account must not have any directly downloadable key files. Instead, it needs to authenticate using a short-lived credential that is automatically rotated by Google Cloud. Which type of service account key should be used?Configuring access and security
- 12.A data analytics team requires a dedicated service account to run batch jobs on Compute Engine instances. This service account needs to read data from specific BigQuery datasets and write results to a Cloud Storage bucket. Which two IAM roles should you assign to this service account, adhering to the principle of least privilege?Configuring access and security
- 13.A financial institution is deploying a new application on Google Cloud that processes highly sensitive customer data. They need to ensure that only authenticated and authorized users can access the application's resources and that all access attempts are logged for auditing purposes. The application uses a service account to interact with other Google Cloud services. Which IAM role should be granted to the service account to allow it to read data from a BigQuery dataset, while adhering to the principle of least privilege?Configuring access and security
- 14.A startup is building a serverless application using Cloud Functions. They need to grant a newly created service account the ability to invoke specific Cloud Functions within their project. However, they want to ensure this service account cannot deploy, delete, or modify the functions. Which IAM role should be assigned to the service account?Configuring access and security
- 15.A company policy dictates that all users should only have the minimum necessary permissions to perform their job functions. You are tasked with granting a new developer the ability to view all resources within a Google Cloud project, but not modify them. Which IAM role should you assign directly to the developer's user account?Configuring access and security
- 16.A startup is building a new application that processes sensitive customer data. They need to ensure that access to this data, stored in Cloud Storage buckets, is strictly controlled and auditable. The security team requires that all data reads and writes are logged, including who accessed what data and when. Which type of audit log should be explicitly enabled and monitored for these Cloud Storage buckets?Configuring access and security
- 17.A new compliance officer has joined your team and needs to review all Identity and Access Management (IAM) policy changes that have occurred across all projects in your Google Cloud organization over the last six months. They need to see who made the changes, what changes were made, and when. Which type of audit log should the compliance officer examine?Configuring access and security
- 18.A security auditor needs to review all administrative activities performed on a critical Google Cloud project, specifically focusing on who created, updated, or deleted resources. Which type of audit log should the auditor primarily examine in Cloud Logging?Configuring access and security
- 19.A development team is working on a new application that needs to create and manage virtual machine instances on Google Compute Engine. They have a dedicated service account for this application. To ensure that the service account can only perform actions related to Compute Engine instances within their project and nothing else, which IAM role should be assigned?Configuring access and security
- 20.A security team needs to monitor all administrative actions performed by users and service accounts across their Google Cloud organization to ensure compliance with internal security policies. They specifically want to see who performed which action and when. Which type of audit log should they focus on for this requirement?Configuring access and security
- 21.A large enterprise is migrating its on-premises user directory to Google Cloud Identity. They have an existing identity provider (IdP) that manages all employee identities. They want to enable their employees to access Google Cloud resources using their existing IdP credentials without synchronizing user accounts into Google Cloud. Which Google Cloud IAM feature should they implement?Configuring access and security
- 22.An internal audit reveals that several service accounts in a critical project have overly permissive roles, such as 'Editor' or 'Owner'. The security team wants to enforce a policy that prevents the creation of any new service accounts with these broad roles, and also restricts existing service accounts from being granted such roles, across the entire organization. Which Google Cloud feature should they use?Configuring access and security
- 23.A team member reports that they are unable to delete a specific Cloud Storage bucket, even though they believe they have the necessary 'Storage Admin' role. You check the IAM policy for the bucket and confirm they have 'roles/storage.admin' at the bucket level. What is a common reason for this unexpected permission denial?Configuring access and security
- 24.A data privacy officer needs to ensure that all access attempts to sensitive customer data stored in Google Cloud Storage buckets are logged, regardless of whether the access was successful or denied. These logs are critical for forensic analysis in case of a data breach. Which type of audit log should they enable and monitor?Configuring access and security
- 25.A company is deploying a new application on Google Cloud that requires persistent storage for its database. The application needs high availability and strong consistency across multiple zones within a region. Which storage option should the company choose to meet these requirements?Ensuring successful operation of a cloud solution
- 26.A team needs to ensure that all outbound internet traffic from their Compute Engine instances is routed through a single, central egress point for security inspection and policy enforcement. They want to avoid assigning external IP addresses directly to the instances. Which networking component should they configure?Ensuring successful operation of a cloud solution
- 27.A company has a critical application running on Compute Engine instances that requires strict uptime. They need a mechanism to automatically restart instances that become unhealthy due to application-level issues, even if the underlying VM is still running. Which feature should be configured to address this requirement?Ensuring successful operation of a cloud solution
- 28.A company requires all new Compute Engine instances to be created with a specific set of security hardening configurations, such as disabled SSH password authentication and specific firewall tags. They want to ensure consistency and prevent misconfigurations across all deployments. Which resource should they define and use?Ensuring successful operation of a cloud solution
- 29.A data analytics team needs to process large datasets that are stored in Cloud Storage. The processing requires significant computational power but is intermittent and can tolerate some startup latency. The team wants to use a managed service that automatically provisions and scales resources as needed, and they prefer to pay only for the compute time consumed. Which compute option should they use?Ensuring successful operation of a cloud solution
- 30.A company is designing a highly available architecture for a critical application. The application's backend services are deployed on Compute Engine instances across multiple zones within a single region. To distribute incoming traffic and ensure resilience against zone failures, they need a global load balancer that can direct traffic to the closest healthy instance. Which Google Cloud load balancing option should they choose?Ensuring successful operation of a cloud solution
- 31.A network administrator needs to establish a secure and highly available connection between their on-premises data center and a Google Cloud Virtual Private Cloud (VPC) network. The connection requires low latency and high throughput for critical business applications. Which Google Cloud networking product should be recommended?Ensuring successful operation of a cloud solution
- 32.A company is using Cloud Monitoring to oversee their Compute Engine instances. They need to set up an alert that triggers if the CPU utilization of any instance exceeds 80% for more than 5 minutes. The alert should notify the operations team via email. Which components are essential for configuring this alert policy?Ensuring successful operation of a cloud solution
- 33.A startup is deploying an application that processes large volumes of streaming data from IoT devices. The data needs to be ingested, transformed, and then loaded into a data warehouse for real-time analytics. The solution must be fully managed, highly scalable, and support both batch and stream processing using a unified programming model. Which Google Cloud service should be used for the data processing component?Ensuring successful operation of a cloud solution
- 34.A company is deploying a new web application on Google Cloud that needs to serve users globally with low latency. The application's backend consists of stateless Compute Engine instances. Which load balancing option should be implemented to distribute traffic efficiently across multiple regions and provide a single global IP address?Ensuring successful operation of a cloud solution
- 35.A developer needs to deploy a containerized application to Google Cloud. The application is stateless, scales dynamically based on traffic, and the developer wants to minimize operational overhead. Which compute option is the most suitable for this scenario?Ensuring successful operation of a cloud solution
- 36.A company is migrating an on-premises application that relies on a network file system (NFS) for shared storage. The application requires low-latency access to shared files for a cluster of Compute Engine instances within the same region. Which Google Cloud storage service should the company choose?Ensuring successful operation of a cloud solution
- 37.A company requires strict compliance for data residency, mandating that all data and compute resources for a specific application must remain within a single, designated geographic region. They also need to ensure that database backups are stored within the same region. Which Cloud Storage storage class is most appropriate for storing these database backups while adhering to the data residency requirement?Ensuring successful operation of a cloud solution
- 38.A company is migrating a legacy application to Google Cloud. The application requires a persistent block storage volume that can be attached to a single Compute Engine instance and offers high performance for I/O-intensive database workloads. The storage needs to be highly durable and available within a specific zone. Which storage option is most appropriate?Ensuring successful operation of a cloud solution
- 39.An administrator is setting up a new Virtual Private Cloud (VPC) network in Google Cloud. They need to create a custom network that supports private IP addresses for Compute Engine instances and allows for firewall rules to control traffic between subnets. Which type of VPC network should the administrator create?Ensuring successful operation of a cloud solution
- 40.A system administrator needs to analyze detailed network traffic patterns, including source/destination IP addresses, ports, protocols, and byte counts, for all Compute Engine instances in a specific subnet to troubleshoot connectivity issues and identify potential security threats. Which Google Cloud service should be enabled and utilized?Ensuring successful operation of a cloud solution
- 41.A developer is building a new application that needs to store frequently accessed, semi-structured data. The application requires high read and write throughput, low latency, and automatic scaling without needing to provision servers. The data model is flexible and does not require strong transactional consistency across multiple tables. Which Google Cloud database is the most appropriate choice?Ensuring successful operation of a cloud solution
- 42.A data engineering team is setting up a new data pipeline that requires a fully managed, serverless NoSQL database service capable of handling petabytes of data with single-digit millisecond latency. The data structure is highly flexible and subject to frequent changes. Which Google Cloud service is best suited for this requirement?Ensuring successful operation of a cloud solution
- 43.A developer needs to deploy a containerized machine learning inference service that experiences unpredictable traffic patterns, with long periods of inactivity followed by sudden bursts of requests. The service must scale to zero to minimize costs during idle times. Which Google Cloud compute option is the most cost-effective and appropriate for this scenario?Ensuring successful operation of a cloud solution
- 44.A developer is constantly deploying new versions of an application on Compute Engine instances. To ensure the application remains stable and performs optimally after each deployment, they need to implement automated checks that verify application health and automatically roll back to a previous version if issues are detected. Which Compute Engine feature should the developer leverage?Ensuring successful operation of a cloud solution
- 45.A team is developing a new microservices-based application on Google Cloud. Each microservice is deployed as a container on Google Kubernetes Engine (GKE). They need a way to store and retrieve small amounts of unstructured data (e.g., user preferences, session data) with extremely low latency and high throughput. The data does not require complex querying or transactional integrity across multiple items. Which data storage option is most appropriate?Ensuring successful operation of a cloud solution
- 46.A security auditor needs to ensure that all network traffic between Compute Engine instances within a specific Virtual Private Cloud (VPC) network is explicitly denied by default, and only allowed traffic is permitted based on least privilege. Which VPC networking component should be configured to enforce this policy effectively?Ensuring successful operation of a cloud solution
- 47.A security team needs to monitor all ingress and egress traffic for Compute Engine instances within a specific subnet to detect anomalies and potential security threats. They want to capture metadata about network flows, such as source/destination IP, ports, and protocols, without installing agents on the VMs. Which Google Cloud logging feature should they enable?Ensuring successful operation of a cloud solution
- 48.A media company stores large video files in a Cloud Storage bucket. They need to ensure that these files are automatically transcoded into multiple formats (e.g., MP4, WebM) whenever a new video is uploaded to the bucket. The transcoding process is computationally intensive and should be triggered by the upload event. Which combination of Google Cloud services should be used to achieve this?Ensuring successful operation of a cloud solution
- 49.A developer is writing an application that needs to securely store sensitive configuration data, such as API keys and database credentials, and access them programmatically from Compute Engine instances. The solution must provide strong encryption, versioning, and access control. Which Google Cloud service should be used?Ensuring successful operation of a cloud solution
- 50.A data analytics team requires a new project in Google Cloud. They want to ensure that billing for this project is charged to a specific departmental billing account, separate from the company's main billing account. Which of the following is the correct sequence of steps to associate a newly created project with a specific, existing billing account?Setting up a cloud solution environment