Google Cloud Associate Cloud Engineer (ACE)
The Associate Cloud Engineer exam asks what you would actually do on Google Cloud — create the VPC, size the disk, grant the role. Learn the four domains it tests, including the places where Google Cloud genuinely does not work like AWS, and remember them with spaced repetition.
- flashcards
- 115
- flashcards
- per day
- ~10 min
- per day
- level
- Beginner → Intermediate
- level
- modules
- 7
- modules
What the Associate Cloud Engineer exam actually tests
The Associate Cloud Engineer is Google Cloud's hands-on associate certification: deploying and securing applications and infrastructure, monitoring projects, and keeping deployed solutions running. Google recommends around six months of hands-on experience, and the questions are phrased as tasks rather than definitions — which is why rote service lists tend not to survive contact with the paper.
The published exam guide splits into four sections at stated weights: setting up a cloud solution environment (~20%), planning and implementing a cloud solution (~30%), ensuring the successful operation of a cloud solution (~30%), and configuring access and security (~20%). These {modules} modules follow those weights, so the time you spend tracks how the exam is actually weighted rather than how easy a topic is to write questions about.
The hardest part for anyone arriving from another cloud is not the new service names, it is the structural differences. A VPC in Google Cloud is global and its subnets are regional, the reverse of the AWS arrangement. There are no security groups — firewall rules target instances by network tag or by service account. An IAM allow policy hangs on the resource and binds roles to members, rather than being a document attached to a principal, and an inherited grant cannot be narrowed further down the hierarchy. Where the two clouds genuinely differ, these cards teach the difference instead of restating the AWS answer.
Exam details change. Confirm the current sections, price and format against Google's own exam guide before you book, and treat any prep material — this one included — as a companion to hands-on practice rather than a substitute for it. If you are still choosing a cloud, the AWS Cloud Practitioner and Azure AI Fundamentals tracks cover the entry-level certifications on the other two.
7 modules, seed to bloom
Each module is a set of flashcards — 115 in total. Answer, review, and watch your knowledge grow from seed to full bloom.
Projects & Billing
Resource hierarchy, organization policies, quotas, billing accounts, budgets and cost attribution
20 cardsCompute Engine
Machine types, Spot VMs, disks, instance templates, managed instance groups, images and snapshots
15 cardsGKE & Serverless
GKE cluster and node pool design, autoscaling, workload identity, Cloud Run revisions and Eventarc
15 cardsStorage & Data
Cloud Storage classes and access control, database selection across Cloud SQL, Spanner, BigQuery and Bigtable, backups and encryption keys
15 cardsNetworking
Global VPC and regional subnets, Shared VPC and peering, firewall rules and Cloud NGFW, NAT, load balancers, DNS and routing
15 cardsOperations & Tooling
Cloud Monitoring alerts and metrics, Cloud Logging routing and audit logs, tracing, Managed Prometheus and infrastructure-as-code tooling
15 cardsIAM & Service Accounts
Allow and deny policies, role types and inheritance, service accounts, impersonation, short-lived credentials and identity federation
20 cardsSample questions
A taste of the real flashcards. Pick an answer, then reveal the explanation.
What scope does a VPC network have in Google Cloud, and what scope do its subnets have?
- AThe network is global; each subnet belongs to exactly one region
- BThe network is regional; each subnet belongs to exactly one zone
- CThe network is global; each subnet belongs to exactly one zone
- DThe network is regional; each subnet spans every zone in the region
What does an IAM allow policy in Google Cloud attach to, and what does it contain?
- AIt attaches to a resource and binds roles to the members granted them
- BIt attaches to a principal and lists the actions that principal may take
- CIt attaches to a role and lists the resources that role may be used on
- DIt attaches to a project and lists the APIs that principals may enable
In GKE Autopilot mode, what changes compared with Standard mode?
- AGoogle manages the nodes and you are billed for the Pods' requested resources
- BGoogle manages the control plane and you are billed for the nodes you provision
- CGoogle manages the workloads and you are billed for the cluster's uptime hours
- DGoogle manages the network and you are billed for the traffic your Pods generate
What is the minimum storage duration billed for an object in the Coldline storage class?
- A90 days, charged even if the object is deleted sooner than that
- B30 days, charged even if the object is deleted sooner than that
- C365 days, charged even if the object is deleted sooner than that
- DNo minimum, so deleting the object stops the charge immediately
Learn it once, keep it for good
Answer a question
Each card is one practical concept with multiple options. Pick what you think is right.
Get the full answer
See the correct option plus a clear explanation, and a link to deeper docs when one is available.
Review at the right time
A spaced-repetition engine (SM-2 or FSRS) resurfaces each card just before you would forget it.
Why this certification is worth the time
The third cloud, not the third choice
Google Cloud runs a large share of data and Kubernetes workloads. ACE is its associate-level entry point.
Task-shaped, not trivia-shaped
The blueprint is written as things you do, so what you learn transfers straight to the console and the CLI.
Unlearns the AWS reflexes
Global VPCs, tag-targeted firewalls and resource-bound IAM catch experienced engineers more often than beginners.
Foundation for the professional tier
The hierarchy, IAM and networking models here carry directly into the Professional Cloud Architect material.
Common questions
What is the Google Cloud Associate Cloud Engineer exam? +
It is Google Cloud's associate-level certification for people who deploy and operate on the platform. The published guide covers four areas: setting up a cloud solution environment, planning and implementing a solution, ensuring its successful operation, and configuring access and security. Check the current format and price on Google's exam page before booking.
Is ACE harder than the AWS Cloud Practitioner? +
Yes, they sit at different levels. Cloud Practitioner is a foundational exam with no assumed hands-on time; ACE is an associate exam and Google recommends roughly six months of practical experience. The closer AWS comparison is the Solutions Architect Associate.
How long does it take to prepare? +
About 10 minutes a day here, alongside real practice in a project of your own. Spaced repetition means short frequent sessions beat cramming, and the recall you need on exam day is exactly what it optimises for.
Do I need to know AWS or Azure first? +
No, and prior AWS knowledge cuts both ways. The concepts transfer, but several Google Cloud models are genuinely inverted — global VPCs with regional subnets, firewall rules targeted by tag or service account, IAM policies attached to resources. This track calls those out explicitly.
Is it free? +
Yes, completely free. No registration or credit card is required, and all your progress is stored locally in your browser.
Is this an official Google Cloud course? +
No — Gnoseed is a study companion, not a course, an exam dump or an official Google product. It will not replace hands-on labs or the official documentation, but it makes the facts the exam tests stick in long-term memory.
Ready for the Associate Cloud Engineer?
Plant your first seed today. Ten minutes a day is all it takes to grow real, lasting knowledge.
