ACE — Google Cloud Certified Associate Cloud Engineer
Google

Google Cloud Certified Associate Cloud Engineer (ACE) Practice Questions

★★★★★★ 4.8 121 verified reviews
84 questions
2026-06-22 updated
✓ Online quiz simulator

Domain coverage

  • Setting up a Cloud Solution Environment (~17%)
  • Planning and Configuring a Cloud Solution (~18%)
  • Deploying and Implementing a Cloud Solution (~25%)
  • Ensuring Successful Cloud Solution Operation (~22%)
  • Configuring Access and Security (~18%)

Sample Questions (9 of 84 shown)

Q1 Setting up a cloud solution environment
Your team is building a website that handles votes from a large user population. The incoming votes will arrive at various rates. You want to optimize the storage and processing of the votes. What should you do?
  1. Save the incoming votes to Firestore. Use Cloud Scheduler to trigger a Cloud Functions instance to periodically process the votes.
  2. Use a dedicated instance to process the incoming votes. Send the votes directly to this instance.
  3. Save the incoming votes to a JSON file on Cloud Storage. Process the votes in a batch at the end of the day.
  4. Save the incoming votes to Pub/Sub. Use the Pub/Sub topic to trigger a Cloud Functions instance to process the votes.
✓ Correct Answer: D
D. Cloud Pub/Sub decouples vote ingestion from processing - votes arrive via Pub/Sub subscriptions, then the application processes asynchronously. Cloud Functions (A) has concurrency limits for rapid incoming votes. Cloud SQL (B) isn't designed for pub-sub messaging. Cloud Tasks (C) distributes tasks but Pub/Sub is the standard for high-volume event ingestion.
Q2 Setting up a cloud solution environment
Your company uses BigQuery to store and analyze data. Upon submitting your query in BigQuery, the query fails with a quotaExceeded error. You need to diagnose the issue causing the error. What should you do? (Choose two.)
  1. Use BigQuery BI Engine to analyze the issue.
  2. Use the INFORMATION_SCHEMA views to analyze the underlying issue.
  3. Configure Cloud Trace to analyze the issue.
  4. Search errors in Cloud Audit Logs to analyze the issue.
✓ Correct Answer: BD
BD. BigQuery reservations (B) provide dedicated slot capacity preventing quotaExceeded errors. Reservations allocate fixed compute resources. Cloud Scheduling (D-context: partition clustering) isn't relevant - B's correct. Option B ensures dedicated slots, and (D option) is about the primary solution. The question asks the best approach to avoid quota errors - BigQuery Reservations allocate dedicated slots.
Q3 Setting up a cloud solution environment
You are the Organization Administrator for your company's Google Cloud resources. Your company has strict compliance rules that require you to be notified about any modifications to files and documents hosted on Cloud Storage. In a recent incident, one of your team members was able to modify files and you did not receive any notifications, causing other production jobs to fail. You must ensure that you receive notifications for all changes to files and documents in Cloud Storage while minimizing management overhead. What should you do?
  1. View Cloud Audit logs for all Cloud Storage files in Logs Explorer. Filter by Admin Activity logs.
  2. Enable Cloud Storage object versioning on your bucket. Configure Pub/Sub notifications for your Cloud Storage buckets.
  3. Enable versioning on the Cloud Storage bucket. Set up a custom script that scans versions of Cloud Storage objects being modified and alert the admin by using the script.
  4. Configure Object change notifications on the Cloud Storage buckets. Send the events to Pub/Sub.
✓ Correct Answer: B
B. Organization policies with constraints (e.g., resource locations, service disablement) enforce compliance rules across all projects in the org. IAM Deny roles (A) block specific permissions but don't enforce compliance policies. Cloud Audit Logs (C) record activity. VPC Service Controls (D) prevent data exfiltration.
Q4 Setting up a cloud solution environment
Your organization has strict requirements to control access to Google Cloud projects. You need to enable your Site Reliability Engineers (SREs) to approve requests from the Google Cloud support team when an SRE opens a support case. You want to follow Google-recommended practices. What should you do?
  1. Add your SREs to roles/iam.roleAdmin role.
  2. Add your SREs to roles/accessapproval.approver role.
  3. Add your SREs to a group and then add this group to roles/iam.roleAdmin.role.
  4. Add your SREs to a group and then add this group to roles/accessapproval.approver role.
✓ Correct Answer: D
D. Granting IAM roles/iam.securityReviewer on the organization level to the SRE group gives them read-only security access across all projects without individual project permissions. Custom roles (A/B) require per-project creation. Organization viewer (C) is too broad for security auditing.
Q5 Setting up a cloud solution environment
Your organization needs to grant users access to query datasets in BigQuery but prevent them from accidentally deleting the datasets. You want a solution that follows Google-recommended practices. What should you do?
  1. Add users to roles/bigquery user role only, instead of roles/bigquery dataOwner.
  2. Add users to roles/bigquery dataEditor role only, instead of roles/bigquery dataOwner.
  3. Create a custom role by removing delete permissions, and add users to that role only.
  4. Create a custom role by removing delete permissions. Add users to the group, and then add the group to the custom role.
✓ Correct Answer: D
D. BigQuery dataviewer role grants read-only query access without delete permissions. BigQuery admin (A) includes delete. BigQuery user (B) can query but also create datasets. BigQuery jobUser (C) only submits jobs.
Q6 Setting up a cloud solution environment
You have a developer laptop with the Cloud SDK installed on Ubuntu. The Cloud SDK was installed from the Google Cloud Ubuntu package repository. You want to test your application locally on your laptop with Cloud Datastore. What should you do?
  1. Export Cloud Datastore data using gcloud datastore export.
  2. Create a Cloud Datastore index using gcloud datastore indexes create.
  3. Install the google-cloud-sdk-datastore-emulator component using the apt get install command.
  4. Install the cloud-datastore-emulator component using the gcloud components install command.
✓ Correct Answer: C
C. gcloud components update updates the Cloud SDK to the latest version. gcloud components install (A) installs specific components. gcloud version (B) shows version. gcloud components list (D) lists components.
Q7 Setting up a cloud solution environment
Your company set up a complex organizational structure on Google Cloud. The structure includes hundreds of folders and projects. Only a few team members should be able to view the hierarchical structure. You need to assign minimum permissions to these team members, and you want to follow Google-recommended practices. What should you do?
  1. Add the users to roles/browser role.
  2. Add the users to roles/iam.roleViewer role.
  3. Add the users to a group, and add this group to roles/browser.
  4. Add the users to a group, and add this group to roles/iam.roleViewer role.
✓ Correct Answer: C
C. Cloud Asset Inventory discovers and inventories all projects, folders, and resources across the organization. Cloud Resource Manager (A) manages projects individually. Deployment Manager (B) deploys resources. Cloud Monitoring (D) tracks metrics.
Q8 Setting up a cloud solution environment
Your organization has a dedicated person who creates and manages all service accounts for Google Cloud projects. You need to assign this person the minimum role for projects. What should you do?
  1. Add the user to roles/iam.roleAdmin role.
  2. Add the user to roles/iam.securityAdmin role.
  3. Add the user to roles/iam.serviceAccountUser role.
  4. Add the user to roles/iam.serviceAccountAdmin role.
✓ Correct Answer: D
D. Granting roles/iam.serviceAccountUser on the service accounts allows the dedicated person to create and manage them. Service Account Admin (A) includes creation but not user. Service Account Key Admin (B) manages keys. Service Account Token Creator (C) creates tokens.
Q9 Setting up a cloud solution environment
Your organization has user identities in Active Directory. Your organization wants to use Active Directory as their source of truth for identities. Your organization wants to have full control over the Google accounts used by employees for all Google services, including your Google Cloud Platform (GCP) organization. What should you do?
  1. Use Google Cloud Directory Sync (GCDS) to synchronize users into Cloud Identity.
  2. Use the cloud Identity APIs and write a script to synchronize users to Cloud Identity.
  3. Export users from Active Directory as a CSV and import them to Cloud Identity via the Admin Console.
  4. Ask each employee to create a Google account using self signup. Require that each employee use their company email address and password.
✓ Correct Answer: A
A. Google Cloud Directory Sync (GCDS) synchronizes Active Directory with Cloud Identity, using AD as the identity source. SAML federation (B) enables SSO. IAM policies (C) control access. Cloud Identity-Aware Proxy (D) secures apps.

You've viewed 3 of 84 questions. Start the free practice exam to answer all questions with instant feedback.

Exam overview

The Google Cloud Associate Cloud Engineer (ACE) certification is the hands-on, technically-grounded entry point into Google Cloud Platform credentials. Unlike theory-heavy foundational exams, ACE tests your real-world ability to deploy applications, monitor operations, and manage enterprise solutions using GCP services—from Compute Engine and GKE to Cloud Run, VPC, and IAM. If you can navigate gcloud CLI commands and GCP Console with confidence, you are already halfway there.

Our ACE practice test suite is built by Google Cloud-certified professionals who understand exactly what the exam demands. With 400+ unique questions covering all five domains, each question includes in-depth answer explanations that reveal not just the correct choice but the architectural reasoning behind it—whether it's choosing a machine type for cost optimization, configuring a VPC firewall rule, or setting up Cloud Monitoring alerts. This mirroring of the exam's scenario-heavy format ensures you build real diagnostic skills, not rote memorization.

What separates our materials is the emphasis on practical workflow. The ACE exam frequently presents questions in the form of gcloud commands, YAML configuration snippets, and troubleshooting scenarios drawn from day-to-day cloud engineering. Our practice tests replicate these exact patterns, requiring you to think like a cloud engineer—selecting the right service, identifying misconfigurations, and optimizing deployments. At just $125, the ACE exam is one of the most affordable professional certifications in the cloud industry; our practice tests ensure you don't waste that investment on a retake.

Official Exam Domains & Weighting

To successfully pass the ACE exam, candidates must demonstrate practical mastery across the following five core domains:
  • Domain 1: Setting up a Cloud Solution Environment (~17%) — Project hierarchy, billing accounts, Cloud SDK installation, and Cloud Shell configuration.
  • Domain 2: Planning and Configuring a Cloud Solution (~18%) — Compute engine sizing, storage class selection, VPC design, and load balancing strategy.
  • Domain 3: Deploying and Implementing a Cloud Solution (~25%) — Instance templates, managed instance groups, GKE, Cloud Functions, Cloud SQL, and BigQuery deployment.
  • Domain 4: Ensuring Successful Cloud Solution Operation (~22%) — Cloud Monitoring metrics and alerts, Cloud Logging, Error Reporting, snapshot and image management.
  • Domain 5: Configuring Access and Security (~18%) — IAM roles and policies, service accounts, firewall rules, VPC Service Controls, and audit logs.

What Our Customers Say 121 verified reviews

4.8 ★★★★★★ Based on 121 reviews
★★★★★
These Google exam dumps for ACE saved me weeks of study time. The questions cover every domain thoroughly.
— Jessica W.
★★★★★★
I recommend this to everyone preparing for ACE. The lifetime access is great — I keep coming back for reference.
— Robert C.
★★★★★★
The progress tracking feature for ACE really motivated me. Seeing my improvement over time was incredibly satisfying.
— Daniel H.
★★★★★★
I was really impressed by the quality of the ACE questions. No typos, no vague wording — they clearly know the material.
— Stella P.
★★★★★★
The ACE practice test is spot-on. The multi-select questions and explanations are exactly what you need for the real exam.
— Emily R.
★★★★★
I bought the ACE question bank a week before my exam and passed with 90%+. The questions are that good.
— Maria V.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

ACE is moderately difficult—more hands-on than AWS Cloud Practitioner but less architecturally demanding than AWS SAA-C03. The key differentiator is that ACE tests your ability to actually execute commands (gcloud CLI) and navigate the GCP Console, whereas [SAA-C03](https://www.examcert.app/exams/aws-saa-c03/) tests design decisions. Our practice tests include gcloud CLI scenarios that mirror this hands-on emphasis.

Google does not publish the exact passing score, but community consensus places it around 70%. There is no penalty for wrong answers, so answer every question. We recommend consistently scoring 80%+ on our full-length practice exams before booking the real one—this provides a comfortable safety margin.

Google recommends 6+ months of hands-on GCP experience. For focused preparation, 4-6 weeks (1-2 hours/day) is typical for those with some cloud background. Beginners to GCP should budget 8-10 weeks. Our practice tests include difficulty-progressive question sets so you can build skills incrementally.

Compute Engine and IAM appear in nearly every domain. GKE, Cloud Storage, Cloud SQL, and Cloud Monitoring are strongly represented. BigQuery and App Engine show up frequently in data and deployment scenarios. Our practice questions are weighted to reflect this distribution—you'll get extensive exposure to Compute Engine sizing, IAM role hierarchy, and load balancer selection.

Yes, Google offers online-proctored exams through Kryterion. You will need a quiet room, stable internet, and a webcam. Testing centers are also available. Our practice tests are accessible 24/7 online, so you can simulate the online exam environment during your preparation.

The ACE certification is valid for 2 years. To recertify, you must pass the current version of the exam again before expiration. Google occasionally offers a shorter recertification exam (fewer questions, lower cost). Our question bank is regularly updated to reflect the latest exam version.

Most cloud engineers pursue the Professional Cloud Architect (PCA) certification after ACE. PCA builds directly on ACE knowledge and focuses on enterprise solution design. If your interests lie in data, consider the Associate Data Practitioner (ADP). Our practice tests build the foundational confidence you'll need for these advanced credentials.