SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
ACE · Domain 1

Setting up a cloud solution environment practice questions

Setting up a cloud solution environment is worth 20% of the ACE exam — the 3rd-heaviest of the 4 domains. Setting up cloud projects, accounts, and billing on Google Cloud. Official (approximate) weighting ~20%. 6 fully worked examples are further down this page, answers included.

Exam weight
20%
the 3rd-heaviest of the 4 domains
Questions
40
across 2 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 4 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Setting up a cloud solution environment questions, fully explained

Questions from the ACE bank mapped to domain 1, with the answer key and the reasoning behind every option. None of them repeat the examples on the main ACE practice page.

Question 1Setting up a cloud solution environment

A security auditor was granted the Viewer role at the organization level. The owners of one sensitive project want to prevent the auditor from viewing that specific project while leaving access to all other projects intact. What should you tell them?

Choose one.

  • a
    Remove the auditor's binding from the sensitive project's IAM policy

    The binding does not exist on the project — it exists at the organization level. There is nothing on the project's own policy to remove, and inherited access remains.

  • b
    Create an organization policy constraint on the project that blocks the auditor's access

    Organization policy constraints restrict what configurations are allowed (for example, blocking external IPs); they do not remove a specific principal's IAM access.

  • c
    Inherited roles cannot be revoked at a lower level; the organization-level grant itself must be changed or rescoped Correct

    Correct. IAM allow policies are additive: the effective policy is the union of the resource's policy and everything inherited. A child resource cannot subtract an ancestor's grant, so the fix must happen where the grant was made.

  • d
    Add a deny entry for the auditor in the project's allow policy

    Allow policies have no deny entries. Denials require a separate mechanism, and the standard ACE-level answer is that allow policies are additive and allow-only.

The concept

IAM allow policies in Google Cloud are additive and allow-only. A resource's effective policy is the union of the policy set directly on it and the policies inherited from its ancestors — a lower level can add access but never take inherited access away.

Why that’s the answer

Because the Viewer grant lives at the organization level, it flows down to every project, including the sensitive one. Option (c) is right: the only clean fixes are to change the grant at its source — for example, remove the org-level binding and instead grant Viewer on the folders or projects the auditor actually needs. Option (a) fails because there is no project-level binding to remove. Option (b) confuses organization policy (configuration guardrails) with IAM (who can do what). Option (d) invents deny entries inside allow policies, which do not exist.

How to reason it out
  1. Identify where the binding was made — here, on the organization node.
  2. Recall that inheritance is additive: child policies cannot subtract ancestor grants.
  3. Rescope the grant: remove the org-level Viewer binding and re-grant it on the specific folders or projects that should be visible.

Exam tip: You cannot revoke an inherited role at a lower level — fix the grant where it was made.

Setting Up Google Cloud Projects, Resource Hierarchy, and IAM — the lesson that teaches this.

Question 2Setting up a cloud solution environment

Your compliance team requires that no Compute Engine VM anywhere in the company can be created with an external IP address, regardless of which IAM roles the creator holds. What is the MOST appropriate mechanism?

Choose one.

  • a
    Remove the Compute Admin role from all users and grant a custom role without the external IP permission

    IAM controls who can act, not what configurations are valid. Role surgery is fragile, hard to maintain across every current and future project, and there is no single permission that maps cleanly to "assign external IP".

  • b
    Configure a firewall rule in every VPC that blocks inbound traffic from the internet

    Firewall rules filter traffic to VMs; they do not prevent an external IP from being assigned in the first place, which is what the requirement demands.

  • c
    Apply the compute.vmExternalIpAccess organization policy constraint at the organization level Correct

    Correct. Organization policy constraints are configuration guardrails that apply no matter what IAM permissions a user has, and setting the constraint at the organization node covers every project.

  • d
    Set a budget alert so administrators are notified when VMs with external IPs are created

    Budgets monitor spend, not network configuration, and alerts are reactive notifications — they cannot prevent anything.

The concept

Organization policies and IAM answer different questions. IAM decides who can perform actions; organization policy constraints decide what resource configurations are allowed at all, and they bind everyone — even project owners — throughout the subtree where they are set.

Why that’s the answer

The requirement is a configuration guardrail that must hold "regardless of IAM roles," which is the textbook use case for an organization policy constraint. Applying compute.vmExternalIpAccess (set to deny all) at the organization node enforces it everywhere, including future projects. Option (a) tries to encode a configuration rule in IAM, which cannot express it reliably and must be repeated for every principal. Option (b) restricts traffic after the fact but leaves the external IP assignable. Option (d) is monitoring, not prevention.

How to reason it out
  1. Recognize "must hold regardless of who or which role" as an organization policy requirement, not an IAM one.
  2. Choose the matching constraint — compute.vmExternalIpAccess — and configure it to deny all external IPs.
  3. Set the constraint at the organization node so every current and future folder and project inherits it.

Exam tip: Use organization policy constraints for what can be configured; use IAM for who can act.

Setting Up Google Cloud Projects, Resource Hierarchy, and IAM — the lesson that teaches this.

Question 3Setting up a cloud solution environment

Three new analysts join your company next week and need the same access as the existing analytics team, which already receives its roles through the group data-analysts@example.com. Following Google-recommended practices, what should you do?

Choose one.

  • a
    Copy each role binding from the group and grant it to the three users individually

    Individual grants duplicate the group's bindings, drift over time as the group's roles change, and contradict the recommendation to manage access through groups.

  • b
    Grant the three users the basic Editor role on the analytics projects until access can be reviewed

    Basic Editor is far broader than the team's curated access and violates least privilege — "temporary" broad grants tend to become permanent.

  • c
    Add the three new analysts to the data-analysts@example.com group in Cloud Identity Correct

    Correct. Because the roles are bound to the group, adding the users to the group grants them the full set of access immediately with no IAM policy changes.

  • d
    Create a new group for the three users and mirror the existing group's role bindings onto it

    A duplicate group with copied bindings creates two sources of truth that will drift apart; the new analysts belong in the existing team group.

The concept

Google recommends binding IAM roles to Google groups managed in Cloud Identity, so that onboarding and offboarding are group-membership operations rather than IAM policy edits.

Why that’s the answer

The access model is already correct: roles are attached to data-analysts@example.com. Adding the three hires to that group (c) gives them exactly the team's access, instantly and auditable. Option (a) creates parallel individual bindings that will drift when the group's roles evolve. Option (b) grants a basic role that is much broader than needed, violating least privilege. Option (d) forks the access model into a second group that must be kept manually in sync — the definition of avoidable operational risk.

How to reason it out
  1. Confirm the team's roles are bound to the Google group, not to individuals.
  2. Add the new analysts' Cloud Identity accounts to the group.
  3. Verify access, and rely on the same mechanism (removal from the group) when people leave.

Exam tip: When roles are bound to a group, onboarding is a group-membership change — never a pile of new IAM bindings.

Setting Up Google Cloud Projects, Resource Hierarchy, and IAM — the lesson that teaches this.

Question 4Setting up a cloud solution environment

You created a brand-new project and your first gcloud compute instances create command fails with an error saying the API has not been used in the project before. Which command resolves this?

Choose one.

  • a
    gcloud apis activate compute.googleapis.com

    There is no gcloud apis command group; API enablement lives under gcloud services.

  • b
    gcloud services enable compute.googleapis.com Correct

    Correct. New projects have most service APIs disabled; gcloud services enable activates the Compute Engine API for the current (or specified) project.

  • c
    gcloud projects enable compute.googleapis.com

    gcloud projects manages project lifecycle and IAM policies; it does not enable service APIs.

  • d
    gcloud compute enable-api

    The gcloud compute group manages Compute Engine resources; it has no enable-api command — enablement is done through gcloud services for every product.

The concept

Every Google Cloud service exposes its functionality through an API that must be enabled per project before use. The gcloud services command group (enable, disable, list) manages this enablement.

Why that’s the answer

The error is the standard symptom of a disabled API in a fresh project, and gcloud services enable compute.googleapis.com (b) is the canonical fix, optionally with --project to target a specific project. Options (a), (c), and (d) name command groups or subcommands that do not exist — gcloud apis is not a group, gcloud projects handles project lifecycle rather than APIs, and gcloud compute has no enable-api verb. Remembering that all API enablement flows through gcloud services eliminates every distractor.

How to reason it out
  1. Read the error: an "API has not been used" message means the service API is disabled in the project.
  2. Run gcloud services enable compute.googleapis.com --project=PROJECT_ID (or rely on the configured default project).
  3. Confirm with gcloud services list --enabled, then retry the original command.

Exam tip: APIs are enabled per project with gcloud services enable SERVICE_NAME.

Setting Up Google Cloud Projects, Resource Hierarchy, and IAM — the lesson that teaches this.

Question 5Setting up a cloud solution environment

Your team's deployment fails with a QUOTA_EXCEEDED error for CPUs in region us-central1, and next month's launch will need roughly triple the current vCPU count in that region. What is the MOST appropriate course of action?

Choose one.

  • a
    Request a quota increase for the CPUs quota in us-central1 from the Quotas page well before the launch Correct

    Correct. Quota increases are requested per quota and region through the console's Quotas page, and because approval is not instant, Google recommends requesting them ahead of anticipated need.

  • b
    Disable quota enforcement for the project using gcloud

    There is no mechanism to switch off quota enforcement; quotas protect both you and Google's capacity and can only be raised via an approved increase request.

  • c
    Upgrade the project's support plan, which automatically raises all quotas

    Support plans affect support response, not quota values; quotas change only through explicit increase requests (or automatically for some quotas as usage history grows).

  • d
    Create additional projects and spread the workload to bypass the regional quota

    Splitting a single workload across projects to dodge quotas fragments management, billing, and IAM, and works against the intent of quota policy; the supported path is an increase request.

The concept

Google Cloud quotas cap resource usage per project, typically per region. When legitimate need exceeds a quota, the supported path is a quota increase request, which is reviewed and may take time to approve — so plan ahead of demand spikes.

Why that’s the answer

Option (a) matches Google's guidance exactly: identify the constrained quota (CPUs in us-central1), file an increase request from the Quotas page, and do it early because approval is not immediate. Option (b) proposes a control that does not exist. Option (c) confuses support entitlements with capacity limits. Option (d) is an anti-pattern: multiplying projects to evade quota complicates IAM, networking, and cost management and does not scale as an operating practice.

How to reason it out
  1. In the console, open IAM & Admin > Quotas and filter to the Compute Engine CPUs quota for us-central1.
  2. Select the quota and submit an increase request with the new required value and justification.
  3. Submit well before the launch date, since requests are reviewed and are not guaranteed to be instant.

Exam tip: Quotas are raised by an increase request on the Quotas page — request early, because approval is not instant.

Setting Up Google Cloud Projects, Resource Hierarchy, and IAM — the lesson that teaches this.

Question 6Setting up a cloud solution environment

A team lead needs to create new projects under the "engineering" folder as new services are spun up, but should not be able to modify the folder's IAM policy or manage other teams' projects. Applying least privilege, which role should you grant, and where?

Choose one.

  • a
    Folder Admin (roles/resourcemanager.folderAdmin) on the "engineering" folder

    Folder Admin can manage the folder itself, including its IAM policy and structure — far more than the stated need to create projects.

  • b
    Project Creator at the organization level

    The role is right but the scope is wrong: at the organization level the lead could create projects anywhere in the company, not just under the engineering folder.

  • c
    Project Creator (roles/resourcemanager.projectCreator) on the "engineering" folder Correct

    Correct. Project Creator on the folder allows creating projects within that folder only, and the creator receives Owner on projects they create — nothing more.

  • d
    Organization Administrator (roles/resourcemanager.organizationAdmin)

    Organization Administrator manages IAM across the entire organization — a massively over-privileged grant for someone who only needs to create projects in one folder.

The concept

Least privilege in the resource hierarchy has two dimensions: pick the narrowest role that covers the task, and grant it at the lowest level of the hierarchy that covers the required scope.

Why that’s the answer

The task is exactly what roles/resourcemanager.projectCreator exists for, and binding it on the "engineering" folder (c) confines project creation to that subtree. Folder Admin (a) matches the scope but not the role — it adds folder IAM and structure management the lead should not have. Option (b) matches the role but not the scope, allowing creation across the whole organization. Organization Administrator (d) fails both tests, granting org-wide IAM control for a single-folder need.

How to reason it out
  1. Identify the minimal capability required: creating projects, nothing else.
  2. Map it to the predefined role roles/resourcemanager.projectCreator.
  3. Bind the role on the "engineering" folder so it applies only within that subtree.

Exam tip: Least privilege means the narrowest role at the lowest sufficient level — Project Creator on the specific folder.

Setting Up Google Cloud Projects, Resource Hierarchy, and IAM — the lesson that teaches this.

What ACE domain 1 tests, topic by topic

The official exam guide breaks Setting up a cloud solution environment into 2 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published ACE practice questions per topic in Setting up a cloud solution environment
TopicWhat it coversQuestions
Setting up cloud projects and accountsOfficial ACE exam-guide sub-section. Creating a resource hierarchy; applying organizational policies; granting IAM roles within a project; managing users and groups in Cloud Identity (manual and automated); enabling APIs; provisioning Google Cloud Observability; assessing quotas and requesting increases; setting up standalone organizations; setting up cloud networking; verifying product availability across regions and zones; configuring Cloud Asset Inventory and using Gemini Cloud Assist to analyze resources; configuring Workforce Identity Federation.20
Managing billing configurationOfficial ACE exam-guide sub-section. Creating one or more billing accounts; linking projects to a billing account; establishing billing budgets and alerts; setting up billing exports.20
Total40

Revise Setting up a cloud solution environment before you drill it

Other ACE domains

Setting up a cloud solution environment: your questions

Setting up a cloud solution environment is domain 1 of the ACE exam guide and carries 20% of the scored content — the 3rd-heaviest of the 4 domains. On a 55-question paper that works out to roughly 11 questions, though Google Cloud does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official ACE exam guide.