Exam Details

  • Exam Code
    :ASSOCIATE-CLOUD-ENGINEER
  • Exam Name
    :Associate Cloud Engineer
  • Certification
    :Google Certifications
  • Vendor
    :Google
  • Total Questions
    :377 Q&As
  • Last Updated
    :May 19, 2025

Google Google Certifications ASSOCIATE-CLOUD-ENGINEER Questions & Answers

  • Question 251:

    Your company runs one batch process in an on-premises server that takes around 30 hours to complete. The task runs monthly, can be performed offline, and must be restarted if interrupted. You want to migrate this workload to the cloud while minimizing cost. What should you do?

    A. Create an Instance Template with Spot VMs On. Create a Managed Instance Group from the template and adjust Target CPU Utilization. Migrate the workload.

    B. Migrate the workload to a Compute Engine VM. Start and stop the instance as needed.

    C. Migrate the workload to a Google Kubernetes Engine cluster with Spot nodes.

    D. Migrate the workload to a Compute Engine Spot VM.

  • Question 252:

    You are working for a hospital that stores its medical images in an on-premises data room. The hospital wants to use Cloud Storage for archival storage of these images. The hospital wants an automated process to upload any new medical images to Cloud Storage. You need to design and implement a solution. What should you do?

    A. Create a Pub/Sub topic, and enable a Cloud Storage trigger for the Pub/Sub topic. Create an application that sends all medical images to the Pub/Sub topic.

    B. Create a script that uses the gcloud storage command to synchronize the on-premises storage with Cloud Storage, Schedule the script as a cron job.

    C. Create a Pub/Sub topic, and create a Cloud Function connected to the topic that writes data to Cloud Storage. Create an application that sends all medical images to the Pub/Sub topic.

    D. In the Google Cloud console, go to Cloud Storage. Upload the relevant images to the appropriate bucket.

  • Question 253:

    Your company requires all developers to have the same permissions, regardless of the Google Cloud project they are working on. Your company's security policy also restricts developer permissions to Compute Engine, Cloud Functions, and Cloud SQL. You want to implement the security policy with minimal effort. What should you do?

    A. Create a custom role with Compute Engine, Cloud Functions, and Cloud SQL permissions in one project within the Google Cloud organization. Copy the role across all projects created within the organization with the gcloud iam roles copy command. Assign the role to developers in those projects.

    B. Add all developers to a Google group in Google Groups for Workspace. Assign the predefined role of Compute Admin to the Google group at the Google Cloud organization level.

    C. Add all developers to a Google group in Cloud Identity. Assign predefined roles for Compute Engine, Cloud Functions, and Cloud SQL permissions to the Google group for each project in the Google Cloud organization.

    D. Add all developers to a Google group in Cloud Identity. Create a custom role with Compute Engine, Cloud Functions, and Cloud SQL permissions at the Google Cloud organization level. Assign the custom role to the Google group.

  • Question 254:

    You are running out of primary internal IP addresses in a subnet for a custom mode VPC. The subnet has the IP range 10.0.0.0/20, and the IP addresses are primarily used by virtual machines in the project. You need to provide more IP addresses for the virtual machines. What should you do?

    A. Add a secondary IP range 10.1.0.0/20 to the subnet.

    B. Change the subnet IP range from 10.0.0.0/20 to 10.0.0.0/18.

    C. Change the subnet IP range from 10.0.0.0/20 to 10.0.0.0/22.

    D. Convert the subnet IP range from IPv4 to IPv6.

  • Question 255:

    You are building a data lake on Google Cloud for your Internet of Things (IoT) application. The IoT application has millions of sensors that are constantly streaming structured and unstructured data to your backend in the cloud. You want to build a highly available and resilient architecture based on Google-recommended practices. What should you do?

    A. Stream data to Pub/Sub, and use Dataflow to send data to Cloud Storage.

    B. Stream data to Pub/Sub, and use Storage Transfer Service to send data to BigQuery.

    C. Stream data to Dataflow, and use Dataprep by Trifacta to send data to Bigtable.

    D. Stream data to Dataflow, and use Storage Transfer Service to send data to BigQuery.

  • Question 256:

    You are running a web application on Cloud Run for a few hundred users. Some of your users complain that the initial web page of the application takes much longer to load than the following pages. You want to follow Google's recommendations to mitigate the issue. What should you do?

    A. Set the minimum number of instances for your Cloud Run service to 3.

    B. Set the concurrency number to 1 for your Cloud Run service.

    C. Set the maximum number of instances for your Cloud Run service to 100.

    D. Update your web application to use the protocol HTTP/2 instead of HTTP/1.1.

  • Question 257:

    An external member of your team needs list access to compute images and disks in one of your projects. You want to follow Google-recommended practices when you grant the required permissions to this user. What should you do?

    A. Create a custom role, and add all the required compute.disks.list and compute.images.list permissions as includedPermissions. Grant the custom role to the user at the project level.

    B. Create a custom role based on the Compute Image User role. Add the compute.disks.list to the includedPermissions field. Grant the custom role to the user at the project level.

    C. Create a custom role based on the Compute Storage Admin role. Exclude unnecessary permissions from the custom role. Grant the custom role to the user at the project level.

    D. Grant the Compute Storage Admin role at the project level.

  • Question 258:

    Your team is using Linux instances on Google Cloud. You need to ensure that your team logs in to these instances in the most secure and cost efficient way. What should you do?

    A. Attach a public IP to the instances and allow incoming connections from the internet on port 22 for SSH.

    B. Use the gcloud compute ssh command with the --tunnel-through-iap flag. Allow ingress traffic from the IP range 35.235.240.0/20 on port 22.

    C. Use a third party tool to provide remote access to the instances.

    D. Create a bastion host with public internet access. Create the SSH tunnel to the instance through the bastion host.

  • Question 259:

    Your continuous integration and delivery (CI/CD) server can't execute Google Cloud actions in a specific project because of permission issues. You need to validate whether the used service account has the appropriate roles in the specific project.

    What should you do?

    A. Open the Google Cloud console, and check the Identity and Access Management (IAM) roles assigned to the service account at the project or inherited from the folder or organization levels.

    B. Open the Google Cloud console, and check the organization policies.

    C. Open the Google Cloud console, and run a query to determine which resources this service account can access.

    D. Open the Google Cloud console, and run a query of the audit logs to find permission denied errors for this service account.

  • Question 260:

    You deployed an application on a managed instance group in Compute Engine. The application accepts Transmission Control Protocol (TCP) traffic on port 389 and requires you to preserve the IP address of the client who is making a request. You want to expose the application to the internet by using a load balancer. What should you do?

    A. Expose the application by using an external TCP Network Load Balancer.

    B. Expose the application by using a TCP Proxy Load Balancer.

    C. Expose the application by using an SSL Proxy Load Balancer.

    D. Expose the application by using an internal TCP Network Load Balancer.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Google exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ASSOCIATE-CLOUD-ENGINEER exam preparations and Google certification application, do not hesitate to visit our Vcedump.com to find your solutions here.