1 | Page
GOOGLE CLOUD ASSOCIATE CLOUD
ENGINEER PRACTICE EXAM 2026/2027
QUESTIONS WITH VERIFIED ANSWERS &
COMPLETE RATIONALES
## SECTION 1: SETTING UP A CLOUD SOLUTION
**1. An Associate Cloud Engineer needs to set up a new project
for a development team. Which of the following should be
configured first to establish the foundation for access control
and resource organization?**
A. Create a service account and download its key.
B. Set up a VPC network with subnets.
C. Create a resource hierarchy with folders and projects.
D. Enable billing and link a payment method.
**Correct answer:** C
**Rationale:** The resource hierarchy (organization, folders,
projects) is the foundation for applying organizational policies
and IAM roles. Setting it up first ensures that access control
and governance are structured correctly from the beginning.
Billing and networking are important but should be configured
within the established hierarchy.
,2 | Page
---
**2. A company wants to ensure that all new projects created
within a specific department automatically inherit a set of IAM
policies. What should the engineer configure?**
A. Organization Policy constraints at the folder level.
B. IAM roles assigned to each project individually.
C. A service account with project creation permissions.
D. A Cloud Function that triggers on project creation.
**Correct answer:** A
**Rationale:** Organization Policy constraints can be applied at
the organization, folder, or project level. Policies applied at the
folder level are inherited by all child projects, ensuring
consistent governance without manual configuration for each
new project.
---
**3. An engineer needs to grant a user the ability to view all
resources in a project but not modify them. Which IAM role
should be assigned?**
, 3 | Page
A. roles/viewer
B. roles/editor
C. roles/owner
D. roles/browser
**Correct answer:** A
**Rationale:** The `roles/viewer` role grants read-only access
to all resources within a project. `roles/editor` allows
modification, `roles/owner` includes full control plus billing and
access management, and `roles/browser` only grants
permission to browse the resource hierarchy.
---
**4. A team needs to run a containerized web application that
will automatically scale based on traffic. They want to minimize
infrastructure management overhead. Which Google Cloud
compute service should they choose?**
A. Compute Engine with a managed instance group.
B. Google Kubernetes Engine (GKE) with a regional cluster.
C. Cloud Run.
D. Cloud Functions.
**Correct answer:** C
GOOGLE CLOUD ASSOCIATE CLOUD
ENGINEER PRACTICE EXAM 2026/2027
QUESTIONS WITH VERIFIED ANSWERS &
COMPLETE RATIONALES
## SECTION 1: SETTING UP A CLOUD SOLUTION
**1. An Associate Cloud Engineer needs to set up a new project
for a development team. Which of the following should be
configured first to establish the foundation for access control
and resource organization?**
A. Create a service account and download its key.
B. Set up a VPC network with subnets.
C. Create a resource hierarchy with folders and projects.
D. Enable billing and link a payment method.
**Correct answer:** C
**Rationale:** The resource hierarchy (organization, folders,
projects) is the foundation for applying organizational policies
and IAM roles. Setting it up first ensures that access control
and governance are structured correctly from the beginning.
Billing and networking are important but should be configured
within the established hierarchy.
,2 | Page
---
**2. A company wants to ensure that all new projects created
within a specific department automatically inherit a set of IAM
policies. What should the engineer configure?**
A. Organization Policy constraints at the folder level.
B. IAM roles assigned to each project individually.
C. A service account with project creation permissions.
D. A Cloud Function that triggers on project creation.
**Correct answer:** A
**Rationale:** Organization Policy constraints can be applied at
the organization, folder, or project level. Policies applied at the
folder level are inherited by all child projects, ensuring
consistent governance without manual configuration for each
new project.
---
**3. An engineer needs to grant a user the ability to view all
resources in a project but not modify them. Which IAM role
should be assigned?**
, 3 | Page
A. roles/viewer
B. roles/editor
C. roles/owner
D. roles/browser
**Correct answer:** A
**Rationale:** The `roles/viewer` role grants read-only access
to all resources within a project. `roles/editor` allows
modification, `roles/owner` includes full control plus billing and
access management, and `roles/browser` only grants
permission to browse the resource hierarchy.
---
**4. A team needs to run a containerized web application that
will automatically scale based on traffic. They want to minimize
infrastructure management overhead. Which Google Cloud
compute service should they choose?**
A. Compute Engine with a managed instance group.
B. Google Kubernetes Engine (GKE) with a regional cluster.
C. Cloud Run.
D. Cloud Functions.
**Correct answer:** C