Google Cloud

Google Cloud Associate Cloud Engineer (GCP-ACE) practice questions

Deploy, secure, and operate applications and infrastructure on Google Cloud.

New to GCP-ACE? Read the how to pass Google Cloud Associate Cloud Engineer study guide for a domain breakdown, a study plan, and exam-day tips.

Revising? The GCP-ACE cheat sheet puts the domain weightings, key facts, and easy-to-confuse traps on one printable page.

Prefer flashcards? See a free sample of the GCP-ACE flashcard deck, concept and misconception cards side by side.

50 to 60
Questions
120 min
Time allowed
$125
Exam cost (USD)
295
Practice questions

Exam domains and weighting

The GCP-ACE blueprint is split across 4 domains. See the official exam guide for the authoritative breakdown.

GCP-ACE domains by share of the exam
DomainWeight
Setting up a cloud solution environment20%
Planning and implementing a cloud solution30%
Ensuring the successful operation of a cloud solution30%
Configuring access and security20%

Free sample questions

No account needed. Every question explains why every answer is right or wrong, just like the full bank.

Free sampleSetting up a cloud solution environmentmedium

A boolean organization policy constraint is enforced on a folder. A team then creates a new project inside that folder, and no policy is set directly on the project. How does the constraint apply to the new project?

  • AThe constraint is inherited from the folder and enforced on the new project, because a project evaluates an effective policy built from every ancestor above it. Correct
  • BThe constraint does not reach the project, because organization policies attach to the organization node and folders but stop above the project level.
  • CThe constraint applies only after an administrator re-applies it on the project, since existing policies do not propagate to resources created after the policy is set.
  • DThe constraint is inherited but downgraded to advisory, so violations on the project are recorded in Cloud Logging instead of being blocked.
An organization policy set on a folder is inherited by and enforced on every project created beneath it. The Resource Manager computes an effective organization policy for each node by combining that node's own policy with those inherited from its ancestor folders and organization, so a folder-level constraint reaches all descendant projects even those created afterwards.

Why A is correct: Correct: the effective policy for any node is the result of evaluating its own policy against those inherited from the folders and organization above it, so a folder constraint applies to child projects.

Why B is wrong: It sounds plausible if you assume policies protect only higher tiers, but organization policies attach to and are enforced at organization, folder, and project nodes alike.

Why C is wrong: The timing detail is tempting, but inheritance is evaluated dynamically at each request, so a project created later still inherits the folder policy without any manual re-application.

Why D is wrong: It borrows the idea of a dry-run mode, but an enforced organization policy actively blocks non-compliant actions rather than merely logging them as advisory events.

Free sampleConfiguring access and securitymedium

A colleague new to Google Cloud asks how the three IAM role types differ. Which statement correctly characterises basic, predefined, and custom roles?

  • ABasic roles are granular roles maintained by Google for a single service, predefined roles are the legacy Owner, Editor, and Viewer, and custom roles are copies of basic roles scoped to one project.
  • BBasic roles are the broad legacy Owner, Editor, and Viewer roles, predefined roles are granular Google-maintained roles for specific services, and custom roles let you assemble a chosen set of permissions. Correct
  • CBasic roles apply only to Cloud Storage buckets, predefined roles apply only to Compute Engine, and custom roles are the sole way to grant access to any other Google Cloud service.
  • DBasic roles and predefined roles are both authored by the customer, whereas custom roles are supplied and updated automatically by Google as services change.
Distinguish basic roles as broad legacy roles, predefined roles as granular Google-maintained roles, and custom roles as customer-defined permission sets. IAM offers three role types: basic roles (Owner, Editor, Viewer) grant broad legacy access, predefined roles give granular Google-maintained permissions per service, and custom roles let an administrator combine exactly the permissions a task requires.

Why A is wrong: This swaps the definitions of basic and predefined roles; Owner, Editor, and Viewer are the basic roles, while the granular per-service roles maintained by Google are the predefined ones.

Why B is correct: This matches the model exactly: basic roles are broad and legacy, predefined roles are fine-grained and maintained by Google, and custom roles are built by selecting the specific permissions you want.

Why C is wrong: This invents per-service limits that do not exist; basic and predefined roles both span many services, and custom roles are an option for tailoring permissions rather than the only route to most services.

Why D is wrong: This reverses authorship; basic and predefined roles are provided and maintained by Google, while custom roles are the ones the customer authors and must maintain themselves.

Free sampleConfiguring access and securitymedium

A team wants to grant an application the permissions to publish and consume Pub/Sub messages without giving any broader access. What is the main advantage of choosing a predefined role over a basic role here?

  • AA predefined role can be edited by the team to add or remove individual permissions, whereas a basic role has a fixed permission set that cannot be changed.
  • BA predefined role automatically applies across the whole organisation hierarchy, so it needs to be granted only once, unlike a basic role that must be granted per resource.
  • CA predefined role bundles a curated set of permissions for a specific service, granting just the Pub/Sub access the application needs rather than broad access to unrelated services. Correct
  • DA predefined role grants temporary permissions that expire after the application finishes, while a basic role grants permanent access that must be revoked manually.
Understand that predefined roles grant granular, service-specific permissions that support least privilege better than broad basic roles. A predefined role is a Google-maintained bundle of permissions for a particular service, so granting a Pub/Sub publisher or subscriber role gives an application only what it needs, avoiding the wide access a basic role would confer.

Why A is wrong: This confuses predefined with custom roles; predefined roles are maintained by Google and are not customer-editable, so editability is not the advantage they offer.

Why B is wrong: This misstates inheritance; both role types follow the same policy-inheritance rules based on where they are granted, so this is not a distinguishing benefit of predefined roles.

Why C is correct: Predefined roles are granular and service-focused, so a Pub/Sub publisher or subscriber role grants only the relevant permissions, aligning with least privilege far better than a broad basic role.

Why D is wrong: This invents an expiry behaviour; predefined roles do not self-expire, and time-bound access is handled separately, so the genuine advantage is their granular service scope.

More free GCP-ACE practice questions, every answer explained

Frequently asked questions

How many questions are on the Associate Cloud Engineer exam?
The Google Cloud Associate Cloud Engineer (GCP-ACE) exam has 50 to 60 questions and runs for 120 minutes. The format is multiple choice and multiple select.
What score do I need to pass Associate Cloud Engineer?
Google Cloud does not publish a fixed pass mark for Associate Cloud Engineer, so treat any "X%" figure you see elsewhere as unofficial. Examworthy gives you a per-domain readiness score so you can judge when you are ready across every domain.
How much does the Associate Cloud Engineer exam cost?
The exam costs 125 USD to sit. Practising on Examworthy is free to start, and every answer is explained, right and wrong.
Is there a Associate Cloud Engineer practice exam?
Yes. Examworthy's exam mode runs a timed Associate Cloud Engineer practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand. Timed mocks are free with an account.
How does Examworthy help me prepare for Associate Cloud Engineer?
Every practice question explains why the right answer is right and why each wrong one is wrong, mapped to the official blueprint domains. You learn the reasoning, not just the letter.
Is Examworthy affiliated with Google Cloud?
No. Examworthy is not affiliated with or endorsed by Google Cloud. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.

Examworthy is not affiliated with or endorsed by Google Cloud. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. GCP-ACE and related marks belong to their respective owners.