Step2Study
IT & Technology100% Free

Google Associate Cloud Engineer

Practice bank
209 Qs
Real exam
50 Qs
Time limit
120 min
Passing
The exam does not publish a passing score. The exam is graded on a pass/fail basis.

Exam blueprint

Setting up a cloud solution environment
18%
Planning and configuring a cloud solution
24%
Deploying and implementing a cloud solution
28%
Ensuring successful operation of a cloud solution
18%
Configuring access and security
12%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 216 min · pass 70% · 209 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Google Associate Cloud Engineer practice test questions

Sample questions from the 209-question bank, with answers and explanations.

All questions
  1. 1. A large enterprise is migrating its on-premises user directory to Google Cloud Identity. They have an existing identity provider (IdP) that manages all employee identities. They want to enable their employees to access Google Cloud resources using their existing IdP credentials without synchronizing user accounts into Google Cloud. Which Google Cloud IAM feature should they implement?

    Configuring access and security

    • A. Cloud Identity Groups
    • B. Domain-wide Delegation
    • C. Workforce Identity Federation
    • D. Managed Service for Microsoft Active Directory
    Show answer

    C. Workforce Identity Federation

    Workforce Identity Federation allows external identity providers (like an on-premises IdP) to authenticate and authorize users to access Google Cloud resources without synchronizing user accounts to Google Cloud Directory. This is ideal for managing access for employees from existing IdPs.

  2. 2. A development team is deploying a new application to Google Kubernetes Engine (GKE). The application needs to access data stored in a Cloud Storage bucket within the same Google Cloud project. To ensure the application has the necessary permissions while adhering to the principle of least privilege, which IAM role should be granted to the GKE service account for accessing the Cloud Storage bucket?

    Configuring access and security

    • A. roles/viewer
    • B. roles/storage.objectViewer
    • C. roles/storage.admin
    • D. roles/editor
    Show answer

    B. roles/storage.objectViewer

    The application only needs to read data from the Cloud Storage bucket. The 'Storage Object Viewer' role (roles/storage.objectViewer) provides read-only access to objects, aligning with the principle of least privilege. Other roles provide broader, unnecessary permissions.

  3. 3. A team member reports that they are unable to delete a specific Cloud Storage bucket, even though they believe they have the necessary 'Storage Admin' role. You check the IAM policy for the bucket and confirm they have 'roles/storage.admin' at the bucket level. What is a common reason for this unexpected permission denial?

    Configuring access and security

    • A. The Storage Admin role does not include the 'storage.buckets.delete' permission.
    • B. The user's Cloud Identity account is not synchronized correctly.
    • C. The bucket is currently in use by an active Compute Engine instance.
    • D. There is an Organization Policy denying bucket deletion for that project.
    Show answer

    D. There is an Organization Policy denying bucket deletion for that project.

    Organization Policies can set constraints at the organization, folder, or project level that override IAM permissions. If an Organization Policy constraint like 'Disable Force Delete' or 'Restrict deletion of specific resources' is active, it can prevent even an Owner or Storage Admin from deleting resources.

  4. 4. A financial institution is deploying a new application on Google Cloud that processes highly sensitive customer data. They need to ensure that only authenticated and authorized users can access the application's resources and that all access attempts are logged for auditing purposes. The application uses a service account to interact with other Google Cloud services. Which IAM role should be granted to the service account to allow it to read data from a BigQuery dataset, while adhering to the principle of least privilege?

    Configuring access and security

    • A. BigQuery Admin
    • B. BigQuery Data Viewer
    • C. Project Editor
    • D. BigQuery Data Editor
    Show answer

    B. BigQuery Data Viewer

    The BigQuery Data Viewer role provides read-only access to BigQuery datasets, which aligns with the principle of least privilege for a service account that only needs to read data. This role does not grant permissions to modify or administer BigQuery resources.

  5. 5. A startup is building a serverless application using Cloud Functions. They need to grant a newly created service account the ability to invoke specific Cloud Functions within their project. However, they want to ensure this service account cannot deploy, delete, or modify the functions. Which IAM role should be assigned to the service account?

    Configuring access and security

    • A. Cloud Functions Invoker
    • B. Cloud Functions Viewer
    • C. Project Editor
    • D. Cloud Functions Developer
    Show answer

    A. Cloud Functions Invoker

    The Cloud Functions Invoker role grants permission to invoke (call) a Cloud Function. This role aligns perfectly with the principle of least privilege, as it allows execution without granting deployment or management capabilities, which is exactly what the scenario requires.

  6. 6. A company policy dictates that all users should only have the minimum necessary permissions to perform their job functions. You are tasked with granting a new developer the ability to view all resources within a Google Cloud project, but not modify them. Which IAM role should you assign directly to the developer's user account?

    Configuring access and security

    • A. Project Editor
    • B. Cloud Asset User
    • C. Owner
    • D. Viewer
    Show answer

    D. Viewer

    The 'Viewer' role (roles/viewer) grants read-only access to all resources within a project, aligning perfectly with the requirement to view but not modify resources.

  7. 7. A new project manager needs to manage virtual machine instances in a specific project, including starting, stopping, and deleting them. However, they should not have permissions to manage networks, disks, or other Compute Engine resources beyond the instances themselves. Which IAM role should be granted to the project manager?

    Configuring access and security

    • A. Compute Admin
    • B. Compute Instance Admin (v1)
    • C. Project Editor
    • D. Compute Network Admin
    Show answer

    B. Compute Instance Admin (v1)

    The Compute Instance Admin (v1) role provides comprehensive control over Compute Engine instances, allowing the project manager to start, stop, and delete VMs. This role adheres to the principle of least privilege by limiting access to instances and excluding other Compute Engine resources like networks and disks.

  8. 8. A data analytics team requires a dedicated service account to run batch jobs on Compute Engine instances. This service account needs to read data from specific BigQuery datasets and write results to a Cloud Storage bucket. Which two IAM roles should you assign to this service account, adhering to the principle of least privilege?

    Configuring access and security

    • A. roles/bigquery.admin and roles/storage.admin
    • B. roles/bigquery.dataViewer and roles/storage.objectCreator
    • C. roles/bigquery.dataViewer and roles/storage.objectAdmin
    • D. roles/bigquery.user and roles/storage.objectCreator
    Show answer

    B. roles/bigquery.dataViewer and roles/storage.objectCreator

    The 'BigQuery Data Viewer' role provides read-only access to BigQuery data, satisfying the 'read data' requirement. The 'Storage Object Creator' role allows writing new objects to a bucket, fulfilling the 'write results' requirement without granting excessive delete or management permissions.

  9. 9. A startup is building a new application that processes sensitive customer data. They need to ensure that access to this data, stored in Cloud Storage buckets, is strictly controlled and auditable. The security team requires that all data reads and writes are logged, including who accessed what data and when. Which type of audit log should be explicitly enabled and monitored for these Cloud Storage buckets?

    Configuring access and security

    • A. System Event logs
    • B. Admin Activity logs
    • C. Custom logs with specific filters
    • D. Data Access logs (Read and Write)
    Show answer

    D. Data Access logs (Read and Write)

    Data Access logs record API calls that read or write user-provided data. For sensitive data in Cloud Storage, enabling and monitoring 'Data Access logs' for both 'Read' and 'Write' operations is crucial to track who accessed what data and when, fulfilling the strict audibility requirement.

  10. 10. A project manager needs to delegate the responsibility of managing virtual machine instances (creating, starting, stopping, deleting) within a specific Google Cloud project to a new operations engineer. The engineer should not have permissions to manage networking, IAM, or billing for the project. Which predefined IAM role is most appropriate for this task?

    Configuring access and security

    • A. Service Account User
    • B. Compute Network Admin
    • C. Compute Instance Admin (v1)
    • D. Project Editor
    Show answer

    C. Compute Instance Admin (v1)

    The 'Compute Instance Admin (v1)' role (roles/compute.instanceAdmin.v1) provides comprehensive permissions for managing Compute Engine instances, including creating, starting, stopping, and deleting them, without granting broader project-level or other service-specific administrative privileges.

  11. 11. A compliance team needs to regularly review IAM policy changes across all projects in a Google Cloud organization. Specifically, they need to know when IAM policies are created, updated, or deleted. Which type of audit log, collected at the organization level, should they monitor?

    Configuring access and security

    • A. System Event logs
    • B. Data Access logs
    • C. Admin Activity logs
    • D. Policy Denied logs
    Show answer

    C. Admin Activity logs

    Admin Activity logs record all administrative actions, including changes to IAM policies (e.g., `setIamPolicy` calls). Monitoring these logs at the organization level will capture all such changes across projects.

  12. 12. A data engineering team needs a service account to run batch jobs on Compute Engine instances. These jobs will access data stored in Cloud Storage buckets. To minimize the attack surface, the security team mandates that the service account should not have any directly attached keys, and its credentials should be automatically managed by Google Cloud. Which authentication method should the team use for this service account?

    Configuring access and security

    • A. OAuth 2.0 client IDs
    • B. Workload Identity Federation for GKE
    • C. Service account keyless authentication
    • D. User-managed service account keys
    Show answer

    C. Service account keyless authentication

    Service account keyless authentication (also known as attached service accounts or managed credentials) involves assigning a service account directly to a Compute Engine instance or other Google Cloud resource. Google Cloud then automatically manages the credentials for the service account, eliminating the need for user-managed keys and enhancing security.

  13. 13. A new compliance officer has joined your team and needs to review all Identity and Access Management (IAM) policy changes that have occurred across all projects in your Google Cloud organization over the last six months. They need to see who made the changes, what changes were made, and when. Which type of audit log should the compliance officer examine?

    Configuring access and security

    • A. Admin Activity logs
    • B. Data Access logs
    • C. System Event logs
    • D. Cloud Audit Logs (all types)
    Show answer

    A. Admin Activity logs

    Admin Activity logs record all API calls and administrative actions that modify the configuration or metadata of Google Cloud resources, including changes to IAM policies. These logs are crucial for auditing and compliance, providing the 'who, what, and when' for policy modifications.

  14. 14. A team is developing a highly sensitive application that requires a dedicated service account to interact with Google Cloud APIs. Due to strict security policies, the service account must not have any directly downloadable key files. Instead, it needs to authenticate using a short-lived credential that is automatically rotated by Google Cloud. Which type of service account key should be used?

    Configuring access and security

    • A. Google-managed service account key
    • B. External service account key
    • C. SSH key for service account
    • D. User-managed service account key
    Show answer

    A. Google-managed service account key

    Google-managed service account keys (also known as service account keyless authentication or managed credentials) provide short-lived credentials that are automatically rotated by Google. This method eliminates the need for user-managed key files, significantly enhancing security by reducing the risk of key compromise and adhering to the 'no directly downloadable key files' policy.

  15. 15. A data privacy officer needs to ensure that all access attempts to sensitive customer data stored in Google Cloud Storage buckets are logged, regardless of whether the access was successful or denied. These logs are critical for forensic analysis in case of a data breach. Which type of audit log should they enable and monitor?

    Configuring access and security

    • A. Data Access logs
    • B. System Event logs
    • C. Admin Activity logs
    • D. Cloud Trace logs
    Show answer

    A. Data Access logs

    Data Access logs record API calls that read or modify user-provided data within Google Cloud resources, such as Cloud Storage. To capture all access attempts to sensitive customer data, including successful and denied attempts, Data Access logs must be explicitly enabled for the relevant services and configured to log 'DATA_READ' and 'DATA_WRITE' operations.

  16. 16. A security auditor needs to review all administrative activities performed on a critical Google Cloud project, specifically focusing on who created, updated, or deleted resources. Which type of audit log should the auditor primarily examine in Cloud Logging?

    Configuring access and security

    • A. Data Access logs
    • B. System Event logs
    • C. Policy Denied logs
    • D. Admin Activity logs
    Show answer

    D. Admin Activity logs

    Admin Activity logs record API calls or other administrative actions that modify the configuration or metadata of resources. This directly addresses the auditor's need to see who created, updated, or deleted resources.

  17. 17. An organization uses Google Cloud Identity to manage its users. A new employee joins the data science team and needs access to a specific BigQuery dataset for analysis. According to the principle of least privilege, how should you grant this access?

    Configuring access and security

    • A. Grant the user a custom role with permissions to read all BigQuery datasets in the organization.
    • B. Add the user to a Google Group, and grant the Google Group the 'BigQuery Data Editor' role on the dataset.
    • C. Grant the user the 'BigQuery Admin' role at the project level.
    • D. Add the user directly to the dataset's IAM policy with the 'BigQuery Data Viewer' role.
    Show answer

    D. Add the user directly to the dataset's IAM policy with the 'BigQuery Data Viewer' role.

    Granting the 'BigQuery Data Viewer' role directly on the specific dataset provides read-only access to only that dataset, adhering to the principle of least privilege. Option C correctly identifies the most granular and least privileged approach.

  18. 18. A data engineering team needs to grant a newly created service account the ability to invoke Cloud Functions for data processing. This service account should only be able to trigger the function and not modify its configuration or deploy new versions. Which IAM role should be assigned to the service account?

    Configuring access and security

    • A. roles/iam.serviceAccountUser
    • B. roles/cloudfunctions.invoker
    • C. roles/cloudfunctions.developer
    • D. roles/editor
    Show answer

    B. roles/cloudfunctions.invoker

    The 'Cloud Functions Invoker' role (roles/cloudfunctions.invoker) grants the specific permission to invoke Cloud Functions, which aligns with the requirement to trigger the function without granting broader development or administrative permissions.

  19. 19. You are setting up a new Google Cloud project for an internal application. The application will use a service account to access various Google Cloud services. As a security best practice, you want to ensure that this service account does not have a static key file that could be compromised. How should you configure the service account for authentication?

    Configuring access and security

    • A. Generate a key file and store it securely in a dedicated Cloud Storage bucket.
    • B. Embed the service account's email and password directly into the application code.
    • C. Attach the service account directly to the Compute Engine or GKE resource.
    • D. Create a custom IAM role with `serviceAccount.keys.create` permission.
    Show answer

    C. Attach the service account directly to the Compute Engine or GKE resource.

    Attaching a service account directly to a Compute Engine instance, GKE node, or Cloud Function allows the resource to obtain short-lived credentials automatically through the metadata server, eliminating the need for static key files.

  20. 20. A company is implementing a robust security posture across its Google Cloud projects. They want to ensure that all service accounts created within a specific folder adhere to the principle of least privilege, meaning they should only be granted roles that are absolutely necessary for their function. To enforce this, they need a way to review and approve all new IAM role grants to service accounts. Which Google Cloud feature allows for such controlled and auditable role assignments?

    Configuring access and security

    • A. IAM Conditions
    • B. IAM Policy Troubleshooter
    • C. Organization Policy Constraints
    • D. IAM Recommender
    Show answer

    C. Organization Policy Constraints

    Organization Policy Constraints can enforce policies at the folder or project level, preventing the granting of overly permissive roles to service accounts. Specifically, the 'Restrict service account usage' constraint can be configured to block service accounts from being granted certain roles, thereby enforcing least privilege and requiring a process (like policy exemption) for any exceptions, which can be part of a review/approval workflow.

  21. 21. A development team is working on a new application that needs to create and manage virtual machine instances on Google Compute Engine. They have a dedicated service account for this application. To ensure that the service account can only perform actions related to Compute Engine instances within their project and nothing else, which IAM role should be assigned?

    Configuring access and security

    • A. Compute Instance Admin (v1)
    • B. Compute Network Admin
    • C. Project Owner
    • D. Compute Viewer
    Show answer

    A. Compute Instance Admin (v1)

    The Compute Instance Admin (v1) role grants full control over Compute Engine instances, including creation, deletion, and modification, which is precisely what the development team needs for managing VMs. It adheres to the principle of least privilege by limiting access to instances only.

  22. 22. A company is migrating an on-premises application to Google Cloud. The application uses a custom identity provider for user authentication. You need to configure IAM to allow users from this identity provider to access Google Cloud resources without manually creating Google accounts for each user. Which IAM feature should you implement?

    Configuring access and security

    • A. Managed Service for Microsoft Active Directory
    • B. Identity Platform
    • C. Service Accounts
    • D. Cloud Identity with Workforce Identity Federation
    Show answer

    D. Cloud Identity with Workforce Identity Federation

    Workforce Identity Federation allows you to use an external identity provider (IdP) to authenticate and authorize users to access Google Cloud resources, without syncing user accounts to Cloud Identity or Google Directory. This is ideal for integrating custom or third-party IdPs.

  23. 23. An internal audit reveals that several service accounts in a critical project have overly permissive roles, such as 'Editor' or 'Owner'. The security team wants to enforce a policy that prevents the creation of any new service accounts with these broad roles, and also restricts existing service accounts from being granted such roles, across the entire organization. Which Google Cloud feature should they use?

    Configuring access and security

    • A. IAM Conditions
    • B. Organization Policy Constraints
    • C. Custom IAM Roles
    • D. Cloud Asset Inventory
    Show answer

    B. Organization Policy Constraints

    Organization Policy Constraints allow administrators to define guardrails for resource creation and configuration across an entire organization. Specifically, the 'Restrict service account usage' constraint can prevent service accounts from being created with or granted overly permissive roles like Editor or Owner, enforcing the principle of least privilege at an organizational level.

  24. 24. A security team needs to monitor all administrative actions performed by users and service accounts across their Google Cloud organization to ensure compliance with internal security policies. They specifically want to see who performed which action and when. Which type of audit log should they focus on for this requirement?

    Configuring access and security

    • A. Admin Activity logs
    • B. Data Access logs
    • C. Policy Denied logs
    • D. System Event logs
    Show answer

    A. Admin Activity logs

    Admin Activity logs record administrative actions that modify the configuration or metadata of Google Cloud resources. These logs are crucial for security and compliance, as they show who did what and when, which directly addresses the security team's requirement.

  25. 25. A security auditor needs to ensure that all network traffic between Compute Engine instances within a specific Virtual Private Cloud (VPC) network is explicitly denied by default, and only allowed traffic is permitted based on least privilege. Which VPC networking component should be configured to enforce this policy effectively?

    Ensuring successful operation of a cloud solution

    • A. VPC Service Controls
    • B. Shared VPC
    • C. Firewall rules
    • D. Cloud VPN
    Show answer

    C. Firewall rules

    VPC firewall rules allow you to control traffic to and from your Compute Engine instances. By default, all ingress traffic is denied, and all egress traffic is allowed. You can create rules to explicitly allow specific ingress and egress traffic, enforcing a least privilege model.

Google Associate Cloud Engineer flashcards

Tap a card to flip it. 134 flashcards in the full deck.

  • Workforce Identity Federation

    Flip card

    Workforce Identity Federation enables employees and partners to access Google Cloud resources using their existing external identity provider (IdP) credentials.

    • Eliminates the need to synchronize user accounts into Google Cloud Directory.
    • Supports various IdPs (e.g., Okta, Azure AD, custom SAML/OIDC providers).
    • Simplifies identity management for large organizations with existing IdPs.
    Study this card →
  • Storage Object Viewer Role

    Flip card

    The `roles/storage.objectViewer` IAM role grants read-only access to objects within a Cloud Storage bucket.

    • Allows listing and getting objects.
    • Does not allow creating, updating, or deleting objects.
    • Adheres to the principle of least privilege for read-only access.
    Study this card →
  • Organization Policy Constraints

    Flip card

    Rules defined at the organization, folder, or project level that restrict how cloud resources can be configured or used, overriding IAM permissions in some cases.

    • Enforce compliance and security across the resource hierarchy.
    • Can prevent actions like resource deletion, IP address usage, or specific API calls.
    • Applied hierarchically and inherited by child resources.
    Study this card →
  • BigQuery Data Viewer Role

    Flip card

    The BigQuery Data Viewer role grants read-only access to BigQuery datasets and tables.

    • Provides permissions to read data and metadata from BigQuery.
    • Adheres to the principle of least privilege for data consumption.
    • Does not allow modification or deletion of data or resources.
    Study this card →
  • Cloud Functions Invoker Role

    Flip card

    The Cloud Functions Invoker role grants permission to execute a Cloud Function.

    • Allows invocation of published Cloud Functions.
    • Does not grant permissions to deploy, delete, or manage functions.
    • Essential for service accounts or users that need to trigger functions programmatically.
    Study this card →
  • Viewer IAM Role

    Flip card

    A predefined IAM role in Google Cloud that grants read-only access to all resources within a project or organization.

    • Provides permissions like `compute.instances.get`, `storage.buckets.get`.
    • Does not grant permissions to modify, create, or delete resources.
    • Ideal for users who need to monitor or audit resources without making changes.
    Study this card →
  • Compute Instance Admin (v1) Role

    Flip card

    The Compute Instance Admin (v1) role grants full control over Google Compute Engine virtual machine instances.

    • Allows starting, stopping, deleting, and modifying VM instances.
    • Does not grant permissions to manage networks, disks, or other Compute Engine infrastructure.
    • Ideal for users or service accounts focused solely on VM lifecycle management.
    Study this card →
  • Least Privilege for Service Accounts

    Flip card

    The security principle of granting a service account only the minimum necessary permissions to perform its intended function, reducing potential security risks.

    • Avoid using primitive roles (Owner, Editor, Viewer) for service accounts.
    • Use predefined roles that match specific tasks.
    • Create custom roles if predefined roles are too broad.
    Study this card →
  • Data Access Logs

    Flip card

    Audit logs that record API calls that read or write user-provided data within Google Cloud services, providing visibility into data access patterns.

    • Not enabled by default for all services due to potential high volume.
    • Requires explicit configuration (e.g., for Cloud Storage, BigQuery).
    • Categories include ADMIN_READ, DATA_READ, and DATA_WRITE.
    Study this card →
  • IAM Policy Audit Logging

    Flip card

    The process of recording and reviewing changes to Identity and Access Management policies within Google Cloud, primarily through Admin Activity logs.

    • IAM policy changes are recorded as `setIamPolicy` calls in Admin Activity logs.
    • These logs are always enabled and cannot be disabled.
    • Crucial for security, compliance, and auditing access controls.
    Study this card →
  • Service Account Keyless Authentication

    Flip card

    Service account keyless authentication refers to the practice of attaching a service account directly to a Google Cloud resource (like a VM) so that Google Cloud manages its credentials automatically.

    • Eliminates the need to create, download, and manage service account keys.
    • Reduces the risk of key compromise and improves security posture.
    • The attached resource receives credentials automatically from the metadata server.
    Study this card →
  • Google-managed Service Account Key

    Flip card

    A Google-managed service account key refers to credentials that are automatically provisioned and rotated by Google Cloud, typically used when a service account is attached to a resource like a VM.

    • No physical key file is generated or downloaded by the user.
    • Credentials are short-lived and automatically rotated by Google Cloud.
    • Enhances security by eliminating key management overhead and reducing compromise risk.
    Study this card →
  • Admin Activity Logs

    Flip card

    Audit logs that record API calls or other actions that modify the configuration or metadata of resources within a Google Cloud project.

    • Always enabled by default and cannot be disabled.
    • Includes operations like creating VMs, updating IAM policies, deleting storage buckets.
    • Helps track administrative changes and maintain security posture.
    Study this card →
  • Organization Policy for Service Accounts

    Flip card

    Organization Policies, specifically constraints like 'Restrict service account usage', can enforce rules on how service accounts are created and what roles they can be granted.

    • Prevents granting overly permissive roles to service accounts.
    • Enforces the principle of least privilege at an organizational or folder level.
    • Can be used in conjunction with policy exemptions for controlled exceptions and approval workflows.
    Study this card →
  • VPC Firewall Rules

    Flip card

    Network rules that control ingress and egress traffic to and from Compute Engine instances within a Virtual Private Cloud (VPC) network.

    • Stateless, applied at the instance level
    • Default deny for ingress, default allow for egress
    • Can specify source/destination, protocols, ports, and targets
    Study this card →
  • Custom mode VPC network

    Flip card

    A type of Virtual Private Cloud (VPC) network that gives users full control over subnet creation, IP address ranges, and routing.

    • Manual subnet creation
    • Custom IP ranges
    • Fine-grained firewall control
    Study this card →
  • Bigtable

    Flip card

    A fully managed, highly scalable NoSQL wide-column database service designed for large analytical and operational workloads, offering petabyte scale and low latency.

    • NoSQL wide-column store
    • Petabyte scale and high throughput
    • Single-digit millisecond latency
    Study this card →
  • VPC Flow Logs

    Flip card

    A feature that records a sample of network flows sent from and received by VM instances in your Virtual Private Cloud (VPC) network.

    • Captures network flow metadata
    • No agents required on VMs
    • Useful for security analysis and network monitoring
    Study this card →
  • Cloud Functions with Storage Triggers

    Flip card

    A serverless compute service that runs code in response to events, including file uploads (object finalization) in Cloud Storage buckets.

    • Event-driven execution model
    • Serverless and scales automatically
    • Supports various programming languages
    Study this card →
  • Secret Manager

    Flip card

    A fully managed Google Cloud service for securely storing, managing, and accessing secrets such as API keys, passwords, and certificates.

    • Stores secrets securely with strong encryption
    • Provides automatic versioning for secrets
    • Offers fine-grained access control (IAM)
    Study this card →
  • Cloud Run

    Flip card

    A fully managed serverless platform that allows you to run stateless containers via web requests or Pub/Sub events.

    • Serverless and fully managed
    • Scales automatically (even to zero)
    • Pay-per-use billing
    Study this card →
  • Memorystore for Redis

    Flip card

    A fully managed in-memory data store service built on open-source Redis, offering extremely high performance for caching and real-time use cases.

    • Fully managed in-memory data store
    • Extremely low latency, high throughput
    • Ideal for caching, session management, real-time data
    Study this card →
  • Filestore

    Flip card

    A fully managed Network File System (NFS) file storage service for applications running on Google Compute Engine and Google Kubernetes Engine.

    • Managed NFS service
    • Shared file system access
    • Low-latency for Compute Engine/GKE
    Study this card →
  • Cloud Dataflow

    Flip card

    A fully managed, serverless service in Google Cloud for executing Apache Beam pipelines, supporting both batch and stream processing with a unified programming model.

    • Fully managed and serverless
    • Unified programming model for batch and stream processing (Apache Beam)
    • Auto-scaling and high throughput
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.