ASSOCIATE-CLOUD-ENGINEER Exam Details

  • Exam Code
    :ASSOCIATE-CLOUD-ENGINEER
  • Exam Name
    :Associate Cloud Engineer
  • Certification
    :Google Certifications
  • Vendor
    :Google
  • Total Questions
    :427 Q&As
  • Last Updated
    :Jun 01, 2026

Google ASSOCIATE-CLOUD-ENGINEER Online Questions & Answers

  • Question 281:

    Your company has a large quantity of unstructured data in different file formats. You want to perform ETL transformations on the data. You need to make the data accessible on Google Cloud so it can be processed by a Dataflow job. What should you do?

    A. Upload the data to BigQuery using the bq command line tool.
    B. Upload the data to Cloud Storage using the gcloud storage command.
    C. Upload the data into Cloud SQL using the import function in the Google Cloud console.
    D. Upload the data into Cloud Spanner using the import function in the Google Cloud console.

  • Question 282:

    You are assigned to maintain a Google Kubernetes Engine (GKE) cluster named `dev' that was deployed on Google Cloud. You want to manage the GKE configuration using the command line interface (CLI). You have just downloaded and installed the Cloud SDK. You want to ensure that future CLI commands by default address this specific cluster What should you do?

    A. Use the command gcloud config set container/cluster dev.
    B. Use the command gcloud container clusters update dev.
    C. Create a file called gke.default in the ~/.gcloud folder that contains the cluster name.
    D. Create a file called defaults.json in the ~/.gcloud folder that contains the cluster name.

  • Question 283:

    Your company wants to standardize the creation and management of multiple Google Cloud resources using Infrastructure as Code. You want to minimize the amount of repetitive code needed to manage the environment. What should you do?

    A. Develop templates for the environment using Cloud Deployment Manager.
    B. Use curl in a terminal to send a REST request to the relevant Google API for each individual resource.
    C. Use the Cloud Console interface to provision and manage all related resources.
    D. Create a bash script that contains all requirement steps as gcloud commands.

  • Question 284:

    You've just enabled an API for the developers. A couple of minutes later, one of the developers pastes a screenshot into Slack. The screenshot indicates that the API isn't enabled. You can see that the project ID is correct. What is the most likely reason for this error?

    A. The API hasn't completed the process to become fully enabled yet.
    B. The developer is using the wrong project.
    C. The developer didn't run the gcloud refresh api command.
    D. The developer is trying to use the wrong API.

  • Question 285:

    You have a developer laptop with the Cloud SDK installed on Ubuntu. The Cloud SDK was installed from the Google Cloud Ubuntu package repository. You want to test your application locally on your laptop with Cloud Datastore. What should you do?

    A. Export Cloud Datastore data using gcloud datastore export.
    B. Create a Cloud Datastore index using gcloud datastore indexes create.
    C. Install the google-cloud-sdk-datastore-emulator component using the apt get install command.
    D. Install the cloud-datastore-emulator component using the gcloud components install command.

  • Question 286:

    You're working as a Cloud Engineer for a small company. The lead developer needs to create some new projects in order to get started with deploying the codebase. She tried to create a project and received an error. She messaged you on Slack to ask for help, though, she couldn't recall the exact error message. You checked and found that she does have Project Creator permissions. Keeping in mind the principle of least privilege, what is the best role to grant her so that she can create billable projects?

    A. The "Billing Account Administrator" role.
    B. The "Billing Account User" role.
    C. The "Project Owner" role.
    D. The "Billing Account Viewer" role.

  • Question 287:

    Your management has asked an external auditor to review all the resources in a specific project. The security team has enabled the Organization Policy called Domain Restricted Sharing on the organization node by specifying only your Cloud Identity domain. You want the auditor to only be able to view, but not modify, the resources in that project. What should you do?

    A. Ask the auditor for their Google account, and give them the Viewer role on the project.
    B. Ask the auditor for their Google account, and give them the Security Reviewer role on the project.
    C. Create a temporary account for the auditor in Cloud Identity, and give that account the Viewer role on the project.
    D. Create a temporary account for the auditor in Cloud Identity, and give that account the Security Reviewer role on the project.

  • Question 288:

    You're running an n-tier application on Compute Engine with an Apache web server serving up web requests. You want to consolidate all of your logging into Stackdriver. What's the best approach to get the Apache logs into Stackdriver?

    A. Create a log sink and export it to Stackdriver.
    B. Stackdriver logs application data from all instances by default.
    C. Enable Stackdriver monitoring when creating the instance.
    D. Install the Stackdriver monitoring and logging agents on the instance.

  • Question 289:

    You are building a product on top of Google Kubernetes Engine (GKE). You have a single GKE cluster. For each of your customers, a Pod is running in that cluster, and your customers can run arbitrary code inside their Pod. You want to maximize the isolation between your customers' Pods. What should you do?

    A. Use Binary Authorization and whitelist only the container images used by your customers' Pods.
    B. Use the Container Analysis API to detect vulnerabilities in the containers used by your customers' Pods.
    C. Create a GKE node pool with a sandbox type configured to gvisor. Add the parameter runtimeClassName: gvisor to the specification of your customers' Pods.
    D. Use the cos_containerd image for your GKE nodes. Add a nodeSelector with the value cloud.google.com/gke-os-distribution: cos_containerd to the specification of your customers' Pods.

  • Question 290:

    You have files in a Cloud Storage bucket that you need to share with your suppliers. You want to restrict the time that the files are available to your suppliers to 1 hour. You want to follow Google recommended practices. What should you do?

    A. Create a service account with just the permissions to access files in the bucket. Create a JSON key for the service account. Execute the command gsutil signurl -m 1h gs:///*.
    B. Create a service account with just the permissions to access files in the bucket. Create a JSON key for the service account. Execute the command gsutil signurl -d 1h gs:///**.
    C. Create a service account with just the permissions to access files in the bucket. Create a JSON key for the service account. Execute the command gsutil signurl -p 60m gs:///.
    D. Create a JSON key for the Default Compute Engine Service Account. Execute the command gsutil signurl -t 60m gs:///***

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Google exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ASSOCIATE-CLOUD-ENGINEER exam preparations and Google certification application, do not hesitate to visit our Vcedump.com to find your solutions here.