CloudExamCheap

ACE Practice Exam: Associate Cloud Engineer

375 questions · 120 min timed mode · Google Cloud · Updated 2026

The GCP entry cert: deploy apps, manage projects, wrangle IAM, keep the wheels on.

What you'll be tested on

Sample ACE questions

Every employee of your company has a Google account. Your operational team needs to manage a large number of instances on Compute Engine. Each member of this team needs only administrative access to the servers. Your security team wants to ensure that the deployment of credentials is operationally efficient and must be able to determine who accessed a given instance. What should you do?
  1. Generate a new SSH key pair. Give the private key to each member of your team. Configure the public key in the metadata of each instance.
  2. Ask each member of the team to generate a new SSH key pair and to send you their public key. Use a configuration management tool to deploy those keys on each instance.
  3. Ask each member of the team to generate a new SSH key pair and to add the public key to their Google account. Grant the ג€compute.osAdminLoginג€ role to the Google group corresponding to this team.
  4. Generate a new SSH key pair. Give the private key to each member of your team. Configure the public key as a project-wide public SSH key in your Cloud Platform project and allow project-wide public SSH keys on each instance.
Show answerC — Ask each member of the team to generate a new SSH key pair and to add the public key to their Google account. Grant the ג€compute.osAdminLoginג€ role to the Google group corresponding to this team.
OS Login is the correct approach: it ties SSH access to each user's Google account identity, so each person uses their own credentials and every login is attributed to an individual, satisfying the auditability requirement. Granting compute.osAdminLogin to the team's Google group gives administrative access efficiently without distributing keys. Sharing a single private key (options A and D) makes it impossible to tell who accessed an instance. Collecting and deploying individual keys with a config management tool (B) is operationally heavy compared with OS Login's automatic, centralized management.
You need to create a custom VPC with a single subnet. The subnet's range must be as large as possible. Which range should you use?
  1. 0.0.0.0/0
  2. 10.0.0.0/8
  3. 172.16.0.0/12
  4. 192.168.0.0/16
Show answerB — 10.0.0.0/8
Subnet ranges must be valid RFC 1918 private address ranges. Of the valid private ranges listed, 10.0.0.0/8 is the largest, providing about 16.7 million addresses, and its /8 mask gives the biggest possible subnet. 0.0.0.0/0 is not a private range and cannot be used for a VPC subnet. 172.16.0.0/12 offers about 1 million addresses and 192.168.0.0/16 offers only about 65 thousand, so both are smaller than the 10.0.0.0/8 option.
You want to select and configure a cost-effective solution for relational data on Google Cloud Platform. You are working with a small set of operational data in one geographic location. You need to support point-in-time recovery. What should you do?
  1. Select Cloud SQL (MySQL). Verify that the enable binary logging option is selected.
  2. Select Cloud SQL (MySQL). Select the create failover replicas option.
  3. Select Cloud Spanner. Set up your instance with 2 nodes.
  4. Select Cloud Spanner. Set up your instance as multi-regional.
Show answerA — Select Cloud SQL (MySQL). Verify that the enable binary logging option is selected.
Cloud SQL with MySQL is the cost-effective choice for a small relational dataset in a single location. Point-in-time recovery in Cloud SQL is achieved by enabling binary logging together with automated backups, so option A directly satisfies the requirement. A failover replica (B) provides high availability, not point-in-time recovery, and adds cost. Cloud Spanner (C and D) is designed for massive, globally distributed, strongly consistent workloads and is far more expensive per node, making it unjustifiable for a small, single-region operational dataset.

Access plans

AccessPrice
3 months$8.99$3.99
1 year$14.99$8.99
Lifetime$24.99$14.99
Practice ACE now →
Free preview inside — try 5 questions before you pay anything.

FAQ

How many practice questions are in this ACE bank?
375 questions covering the current ACE Associate Cloud Engineer syllabus, every one with the correct answer and an explanation.
How long is the real ACE exam?
The official ACE exam gives you 120 minutes. Our timed exam mode uses the same limit so the pace feels familiar.
What does ACE access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.