Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 75 pages
Exam (elaborations)

[Google Associate Cloud Engineer Exam] – EXAM-STYLE QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | 2026/27 LATEST UPDATE | EXAM PREP | STUDY GUIDE | PRACTICE TEST

Document preview thumbnail
Preview 4 out of 75 pages

[Google Associate Cloud Engineer Exam] – EXAM-STYLE QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | 2026/27 LATEST UPDATE | EXAM PREP | STUDY GUIDE | PRACTICE TEST

Content preview

[Google Associate Cloud Engineer Exam] – EXAM-STYLE QUESTIONS AND
ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES |
GUARANTEED PASS | 2026/27 LATEST UPDATE | EXAM PREP | STUDY GUIDE |
PRACTICE TEST




1. An organization is deploying a new microservices application on Google
Kubernetes Engine. The application's pods need to authenticate with Google
Cloud APIs. What is the most secure and sustainable method to provide these
credentials?

A. Create a service account with the necessary IAM roles and distribute its JSON
key file to the pods using a Kubernetes Secret.
B. Place the application's service account key in a Cloud Storage bucket and
configure the pods to download the key at startup.
C. Configure the GKE nodes with the required permissions and rely on the
Compute Engine default service account.
D. Create a Kubernetes service account and link it to a Google Cloud service
account using Workload Identity.

Correct Answer: D. Create a Kubernetes service account and link it to a Google
Cloud service account using Workload Identity.

Rationale: Workload Identity is the recommended and most secure method for GKE
workloads to access Google Cloud services. It allows you to assign IAM roles to a
Kubernetes service account, which is then linked to a Google Cloud service account.
This eliminates the need to manage and rotate service account keys, a significant
security risk, and follows the principle of least privilege. Option A is insecure due to

,key management. Option B is also insecure and operationally complex. Option C is
insecure as it grants broad permissions to all pods on a node.




2. A developer needs to store a large, immutable dataset for a data processing
pipeline. The data will be written once, processed many times, and then
archived. The pipeline runs monthly. Which storage option is the most cost-
effective for this use case?

A. Multi-Regional Cloud Storage bucket with Standard storage class.
B. Regional Cloud Storage bucket with Nearline storage class.
C. Zonal Persistent Disk with standard SSD performance.
D. Filestore instance providing a network-attached file system.

Correct Answer: B. Regional Cloud Storage bucket with Nearline storage class.

Rationale: Cloud Storage Nearline is ideal for data accessed less than once a
month, which aligns with a monthly processing pipeline. It offers a lower storage
cost than Standard and a low retrieval fee, making it the most cost-effective option
for this specific access pattern. The "Regional" location further optimizes cost
compared to Multi-Regional. Option A is too expensive for infrequent access. Option
C is a persistent disk, not ideal for long-term immutable object storage. Option D
(Filestore) is a high-performance file system and would be significantly over-
provisioned and costly for this purpose.




3. You have just created a new Google Cloud project. You need to ensure that
all new Compute Engine instances created in this project are, by default, not

,publicly accessible from the internet via an external IP address. What is the
most effective way to enforce this policy across the organization for this
specific project?

A. Configure the project's VPC firewall rules to deny all incoming traffic from the
internet.
B. Instruct all developers to not assign external IP addresses when they create
instances.
C. Set a project-level metadata key-value pair to disable external IP assignment
for all new instances.
D. Disable the "Allow HTTP traffic" and "Allow HTTPS traffic" checkboxes in the
instance creation form.

Correct Answer: C. Set a project-level metadata key-value pair to disable
external IP assignment for all new instances.

Rationale: Google Cloud provides a project-level metadata key, "instance-set-
external-ip," which can be set to "FALSE" to prevent the automatic assignment of
external IP addresses when new Compute Engine instances are created. This is a
scalable and enforceable way to apply a default policy across a project without
relying on manual developer action (B) or overly broad firewall rules (A) that
wouldn't prevent the instance from having a public IP. Option D only controls
default firewall rule creation, not the external IP address itself.




4. An engineer is deploying a new application to Compute Engine and wants to
automate the initial configuration of the VM at boot time. The configuration
includes installing specific packages and running setup scripts. Which approach
is the most reliable for this task?

, A. SSH into the VM after it starts and manually run the setup commands.
B. Create a custom image with all the software pre-installed.
C. Provide a startup script in the metadata of the Compute Engine instance.
D. Use a Cloud Function to run the configuration after the VM is created.

Correct Answer: C. Provide a startup script in the metadata of the Compute
Engine instance.

Rationale: Startup scripts are a native and reliable feature of Compute Engine for
automating initial configuration tasks. They are executed by the VM on every boot,
ensuring the desired state is achieved without manual intervention. Option A is
manual and not scalable. Option B (creating a custom image) is good for pre-
installed software, but a startup script is more flexible for configuration and
updates. Option D introduces an external, event-driven service that adds
unnecessary complexity and potential points of failure for a simple boot-time
configuration.




5. A team is setting up a Continuous Integration/Continuous Deployment
(CI/CD) pipeline on Google Cloud. Their build artifacts are often large, and they
need a fast and reliable way to store them and make them accessible to other
stages of the pipeline. Which Google Cloud service is best suited for this?

A. Cloud Storage
B. Cloud Source Repositories
C. Artifact Registry
D. Cloud Pub/Sub

Correct Answer: C. Artifact Registry

Document information

Uploaded on
August 4, 2026
Number of pages
75
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$22.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PrepPulse1
4.0
(21)
Sold
280
Followers
6
Items
3688
Last sold
1 day ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions