SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
ACE · Domain 2

Planning and implementing a cloud solution practice questions

Planning and implementing a cloud solution is worth 30% of the ACE exam — the heaviest of the 4 domains. Planning and deploying compute, storage/data, networking, and resources via tooling. Official (approximate) weighting ~30%. 6 fully worked examples are further down this page, answers included.

Exam weight
30%
the heaviest of the 4 domains
Questions
80
across 4 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 4 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Planning and implementing a cloud solution questions, fully explained

Questions from the ACE bank mapped to domain 2, with the answer key and the reasoning behind every option. None of them repeat the examples on the main ACE practice page.

Question 1Planning and implementing a cloud solution

A media company runs a nightly batch rendering job on Compute Engine. The job checkpoints its progress to Cloud Storage every few minutes and can restart from the last checkpoint if interrupted. Which option is the MOST cost-effective way to run this job?

Choose one.

  • a
    Run the job on Spot VMs Correct

    Spot VMs offer the deepest Compute Engine discounts (typically 60-91 percent off on-demand) in exchange for possible preemption, which this checkpointed, restartable job tolerates by design.

  • b
    Run the job on standard VMs and rely on sustained use discounts

    Sustained use discounts are modest and apply to VMs running a large portion of the month; a nightly job neither runs long enough to maximize them nor comes close to Spot pricing.

  • c
    Purchase a three-year committed use discount for standard VMs

    Committed use discounts require a long-term spend commitment and suit steady, predictable 24/7 usage - paying for committed capacity that sits idle most of the day costs more than Spot for an interruptible nightly batch.

  • d
    Run the job on sole-tenant nodes

    Sole-tenant nodes dedicate an entire physical server to you for compliance or licensing needs and carry a price premium - the opposite of a cost optimization.

The concept

Spot VMs are Compute Engine capacity sold at a steep discount because Google can preempt them at any time; they are the standard cost lever for fault-tolerant, interruptible workloads like batch processing.

Why that’s the answer

The job's checkpoint-and-restart design means preemption costs only a few minutes of rework, so the workload matches the Spot model exactly and captures the largest possible discount. Sustained use discounts are small and usage-proportional, committed use requires paying for capacity around the clock, and sole-tenant nodes increase cost rather than reduce it.

How to reason it out
  1. Confirm the workload is fault tolerant: it checkpoints and can resume after interruption.
  2. Map fault-tolerant batch work to Spot VMs, the discount model built for preemptible capacity.
  3. Reject discount models designed for steady always-on usage (sustained use, committed use) and premium isolation options (sole-tenant).

Exam tip: If a workload can survive preemption, Spot VMs are almost always the most cost-effective Compute Engine choice.

Choosing and Deploying Compute: Compute Engine, GKE, and Cloud Run — the lesson that teaches this.

Question 2Planning and implementing a cloud solution

An in-memory analytics application on Compute Engine needs 6 vCPUs and 52 GB of memory. The closest predefined machine types either provide too little memory or significantly overprovision vCPUs. What should you do to run the workload at the LOWEST cost?

Choose one.

  • a
    Create a VM with a custom machine type of 6 vCPUs and 52 GB of memory, using extended memory if needed Correct

    Custom machine types let you set vCPU and memory independently (with extended memory beyond the default per-vCPU ratio), so you pay for exactly the shape the workload needs.

  • b
    Choose the next larger predefined machine type that meets the memory requirement

    Sizing up a predefined type to reach 52 GB of memory also buys vCPUs the application will never use, and you pay for that stranded capacity every hour.

  • c
    Run two smaller predefined VMs and split the workload between them

    An in-memory analytics workload needs its memory in one address space; splitting it across VMs adds complexity and does not change the fact that predefined shapes misfit the requirement.

  • d
    Attach additional Persistent Disk volumes to use as swap space

    Swapping to Persistent Disk is orders of magnitude slower than RAM and would cripple an in-memory analytics workload; disk is not a substitute for memory capacity.

The concept

Compute Engine custom machine types decouple vCPU count from memory size so you can match a VM precisely to a workload instead of rounding up to the nearest predefined shape.

Why that’s the answer

The requirement (6 vCPUs, 52 GB) falls between predefined shapes, which is exactly the gap custom machine types exist to fill. If 52 GB exceeds the default memory-per-vCPU ceiling for the machine family, the extended memory option covers the difference. Every alternative either overpays for unused vCPUs, re-architects the app unnecessarily, or destroys performance by substituting disk for RAM.

How to reason it out
  1. Determine the exact vCPU and memory requirement of the workload.
  2. Compare against predefined machine types and note the misfit in the CPU-to-memory ratio.
  3. Create a custom machine type with the precise shape, enabling extended memory if the ratio exceeds the family default.

Exam tip: When predefined machine shapes force you to overprovision, custom machine types (with extended memory) buy exactly what the workload needs.

Choosing and Deploying Compute: Compute Engine, GKE, and Cloud Run — the lesson that teaches this.

Question 3Planning and implementing a cloud solution

You need to create a managed instance group that automatically scales the number of identical web-server VMs based on average CPU utilization. Which resource must you create FIRST?

Choose one.

  • a
    An unmanaged instance group containing existing VMs

    Unmanaged instance groups hold heterogeneous, hand-built VMs and do not support autoscaling; they are not a precursor to a managed instance group.

  • b
    A snapshot schedule for the web servers' boot disks

    Snapshot schedules protect disk data for backup purposes; they play no role in defining or creating the instances of a managed instance group.

  • c
    An instance template that defines the VM configuration Correct

    A managed instance group is created from an instance template; the template defines the machine type, image, disks, and metadata that every instance in the group is stamped from.

  • d
    A standalone VM designated as the group's primary node

    Managed instance groups have no concept of a primary node; all instances are identical replicas created from the template, not clones of a designated leader VM.

The concept

Managed instance groups (MIGs) create and manage identical VMs from an instance template, which is the reusable definition of machine type, boot image, disks, network, and startup configuration.

Why that’s the answer

The creation order is fixed: define the instance template, create the MIG from it, then attach an autoscaling policy (for example, target CPU utilization of 60 percent). Without a template the MIG has nothing to instantiate. Unmanaged groups cannot autoscale, snapshots are unrelated to instance creation, and MIGs are leaderless by design.

How to reason it out
  1. Create an instance template capturing the web server's machine type, image, and startup script.
  2. Create the managed instance group from that template in the target zone or region.
  3. Configure autoscaling on the group with a target metric such as average CPU utilization.

Exam tip: Instance template first, managed instance group second, autoscaling policy third - a MIG cannot exist without a template to stamp instances from.

Choosing and Deploying Compute: Compute Engine, GKE, and Cloud Run — the lesson that teaches this.

Question 4Planning and implementing a cloud solution

A platform team wants to run containerized microservices with the full Kubernetes API but does not want to size, provision, upgrade, or secure nodes and node pools. They also want to be billed for the resources their Pods request rather than for the underlying VMs. Which deployment option meets these requirements?

Choose one.

  • a
    A GKE Standard cluster with node auto-provisioning

    Node auto-provisioning creates node pools automatically, but in Standard mode the team still owns node configuration, security, and maintenance decisions, and billing remains per node, not per Pod request.

  • b
    Cloud Run

    Cloud Run removes node management but does not expose the full Kubernetes API - no custom resources, DaemonSets, or kubectl-managed cluster objects - which the team explicitly wants.

  • c
    Managed instance groups running container-optimized VMs

    MIGs run containers on VMs you fully manage, with no Kubernetes control plane at all; the team would lose the Kubernetes API and gain node operations work.

  • d
    A GKE Autopilot cluster Correct

    Autopilot is the GKE mode in which Google provisions and manages nodes automatically and bills for Pod resource requests, while the team keeps the standard Kubernetes API for their workloads.

The concept

GKE offers two modes: Standard, where you manage node pools and pay per node, and Autopilot, where Google manages the nodes and you pay for the CPU, memory, and storage your Pods request.

Why that’s the answer

The two requirements - keep the Kubernetes API, drop node management with per-Pod-request billing - are the definition of Autopilot. Standard with node auto-provisioning automates node pool creation but leaves node lifecycle and per-node billing with the team. Cloud Run trades away the Kubernetes API entirely, and MIGs provide no orchestration at all.

How to reason it out
  1. Confirm the team needs real Kubernetes (kubectl, the full API), ruling out non-Kubernetes platforms.
  2. Confirm they want zero node management and Pod-request-based billing.
  3. Select GKE Autopilot, the mode built to combine the Kubernetes API with Google-managed nodes.

Exam tip: Kubernetes API without node operations and with per-Pod billing means GKE Autopilot, not Standard mode or Cloud Run.

Choosing and Deploying Compute: Compute Engine, GKE, and Cloud Run — the lesson that teaches this.

Question 5Planning and implementing a cloud solution

Your company is deploying a production GKE Standard cluster. A key requirement is that the Kubernetes control plane must remain available even if a single zone experiences an outage. Which cluster configuration should you choose?

Choose one.

  • a
    A multi-zonal cluster

    A multi-zonal cluster spreads nodes across zones but runs only a single control plane replica in one zone - if that zone fails, the Kubernetes API becomes unavailable even though workloads keep running.

  • b
    A zonal cluster with node auto-repair enabled

    Node auto-repair replaces unhealthy nodes; it does nothing for the control plane, which in a zonal cluster lives in exactly one zone.

  • c
    A regional cluster Correct

    A regional cluster replicates the control plane across multiple zones in the region, so the Kubernetes API stays available during a zonal outage.

  • d
    A private cluster

    Private clusters remove public IPs from nodes for network security; the private setting is independent of control-plane replication and does not add zonal resilience.

The concept

GKE cluster availability is determined by where the control plane runs: zonal and multi-zonal clusters have a single-zone control plane, while regional clusters replicate the control plane across zones.

Why that’s the answer

Only a regional cluster satisfies the requirement, because it runs multiple control-plane replicas in different zones of the region. The classic trap is the multi-zonal cluster: its nodes span zones, but its control plane does not, so a zonal outage can take down the API server. Auto-repair and private networking address different concerns entirely.

How to reason it out
  1. Identify that the requirement is about control-plane availability, not just node availability.
  2. Recall that zonal and multi-zonal clusters both run the control plane in a single zone.
  3. Choose a regional cluster, which replicates both the control plane and (by default) nodes across multiple zones.

Exam tip: Multi-zonal spreads only nodes; regional is the only GKE configuration that makes the control plane survive a zone outage.

Choosing and Deploying Compute: Compute Engine, GKE, and Cloud Run — the lesson that teaches this.

Question 6Planning and implementing a cloud solution

You deployed a private GKE cluster in which nodes have only internal IP addresses. Pods must download packages from public repositories on the internet during startup, but the nodes must remain unreachable from the internet. What should you configure?

Choose one.

  • a
    Assign external IP addresses to the node pool

    External IPs would make the nodes directly addressable from the internet, which breaks the private-cluster requirement rather than solving egress.

  • b
    Cloud NAT for the cluster's subnet Correct

    Cloud NAT provides outbound-only internet access for resources without external IPs, letting nodes and Pods reach public repositories while remaining unreachable for inbound connections.

  • c
    An external passthrough Network Load Balancer in front of the nodes

    A load balancer handles inbound traffic to services; it does not give nodes a path for outbound connections to the internet.

  • d
    Cloud VPN to the corporate data center

    Cloud VPN connects the VPC to an on-premises network; it does not by itself provide internet egress for nodes, and routing egress through the data center adds needless complexity for this need.

The concept

Private GKE clusters give nodes internal IPs only, so any outbound internet access must be provided by Cloud NAT, which performs source NAT for egress without exposing the instances to inbound traffic.

Why that’s the answer

Cloud NAT is the purpose-built answer for exactly this pattern: internal-only instances that need to reach public endpoints. External IPs violate the security requirement, load balancers only serve inbound traffic, and a VPN tunnel targets private connectivity to on-premises rather than internet egress.

How to reason it out
  1. Recognize the need: outbound internet access from nodes that have no external IPs.
  2. Create a Cloud Router in the cluster's region and VPC.
  3. Configure a Cloud NAT gateway on that router covering the cluster's subnet and Pod ranges.

Exam tip: Private cluster plus internet egress equals Cloud NAT - outbound access with no inbound exposure.

Choosing and Deploying Compute: Compute Engine, GKE, and Cloud Run — the lesson that teaches this.

What ACE domain 2 tests, topic by topic

The official exam guide breaks Planning and implementing a cloud solution into 4 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published ACE practice questions per topic in Planning and implementing a cloud solution
TopicWhat it coversQuestions
Planning and implementing compute resourcesOfficial ACE exam-guide sub-section. Selecting compute for a workload (Compute Engine, GKE, Cloud Run, Cloud Run functions, Agent Runtime on Gemini Enterprise Agent Platform); launching instances (availability policy, SSH keys); choosing Compute Engine storage (zonal/regional Persistent Disk, Hyperdisk); autoscaled managed instance groups with instance templates; OS Login; VM Manager; Spot VMs and custom machine types; kubectl; deploying GKE clusters (Autopilot, regional, private); deploying containerized apps to GKE; serverless deployments and event processing (Pub/Sub, Cloud Storage notifications, Eventarc); choosing GPUs vs TPUs.20
Planning and implementing storage and data solutionsOfficial ACE exam-guide sub-section. Choosing and deploying data products (Cloud SQL, BigQuery, Firestore, Spanner, Bigtable, AlloyDB, Dataflow, Pub/Sub, Managed Service for Apache Kafka, Memorystore); choosing and deploying storage products (Cloud Storage, Filestore, NetApp Volumes, Managed Lustre) and Cloud Storage classes (Standard, Nearline, Coldline, Archive); loading data (CLI upload, from Cloud Storage, Storage Transfer Service); maintaining multi-region redundancy.20
Planning and implementing networking resourcesOfficial ACE exam-guide sub-section. Creating a VPC with subnets (custom mode, Shared VPC, VPC Network Peering); creating and applying VPC firewall rules and Cloud NGFW policies with ingress/egress attributes; using Tags (secure Tags) and service accounts in NGFW policy rules; establishing connectivity (Cloud VPN, VPC Network Peering, Cloud Interconnect); choosing and deploying load balancers; differentiating Network Service Tiers.20
Planning and implementing resources using toolingOfficial ACE exam-guide sub-section. Infrastructure as Code tooling (Fabric FAST, Config Connector, Terraform, Helm); AI-assisted planning and implementation (Gemini CLI, Google Antigravity, Gemini Cloud Assist, Application Design Center).20
Total80

Revise Planning and implementing a cloud solution before you drill it

Other ACE domains

Planning and implementing a cloud solution: your questions

Planning and implementing a cloud solution is domain 2 of the ACE exam guide and carries 30% of the scored content — the heaviest of the 4 domains. On a 55-question paper that works out to roughly 17 questions, though Google Cloud does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official ACE exam guide.