Google Associate Cloud Engineer flashcards
134 free flashcards. Tap a card to flip it.
Compute Instance Admin (v1) Role
Flip cardA predefined IAM role that grants full administrative control over Compute Engine virtual machine instances.
- Includes permissions like `compute.instances.create`, `compute.instances.delete`, `compute.instances.start`, `compute.instances.stop`.
- Does not include permissions for networking, IAM, or billing.
- Ideal for operations teams managing VM lifecycles.
Memory trick: Instance Admin manages VMs, Network Admin manages wires, Editor changes all, and SA User just lends their attire.
Admin Activity Logs
Flip cardAdmin Activity logs record API calls or other actions that modify the configuration or metadata of resources.
- Always enabled by default, cannot be disabled.
- Crucial for auditing changes to resource configurations.
- Includes who performed the action, which resource, and when.
Memory trick: Admin logs watch the admins, data logs watch the data.
Organization Policy Constraints
Flip cardOrganization Policy Constraints allow administrators to define rules that restrict the configuration of Google Cloud resources across an entire organization, folders, or projects.
- Enforce compliance and security policies at a high level.
- Applied to organizations, folders, or projects.
- Can restrict resource creation, IAM bindings, API usage, and more.
Memory trick: Organization Policies are the gatekeepers for the whole kingdom.
Workforce Identity Federation
Flip cardA Google Cloud feature that enables users from external identity providers (IdPs) to access Google Cloud resources using their existing credentials, without requiring synchronization to Cloud Identity.
- Supports SAML 2.0 and OIDC IdPs.
- Eliminates the need for Google accounts for workforce users.
- Manages access through attribute-based access control (ABAC).
Memory trick: Federate your workforce identities to connect to the cloud, without a Google account shroud.
Organization Policy for Service Accounts
Flip cardOrganization Policies, specifically constraints like 'Restrict service account usage', can enforce rules on how service accounts are created and what roles they can be granted.
- Prevents granting overly permissive roles to service accounts.
- Enforces the principle of least privilege at an organizational or folder level.
- Can be used in conjunction with policy exemptions for controlled exceptions and approval workflows.
Memory trick: Organization Policy is the bouncer for service account roles.
Service Account Keyless Authentication
Flip cardThe practice of using Google Cloud service accounts without generating and managing static key files, typically by attaching the service account directly to a Google Cloud resource.
- Relies on the instance metadata server to provide short-lived credentials.
- Reduces the risk of key compromise and simplifies key management.
- Recommended for Compute Engine, GKE, Cloud Functions, App Engine, etc.
Memory trick: Attach, don't store, for a keyless secure core.
Cloud Functions Invoker Role
Flip cardAn IAM role that grants permission to trigger or invoke a Google Cloud Function.
- Contains the `cloudfunctions.functions.invoke` permission.
- Does not allow modifying, deploying, or deleting functions.
- Essential for services or users that only need to execute a function.
Memory trick: Invoker just triggers, Developer builds, Editor changes everything, Service Account User acts as another.
BigQuery Data Viewer Role
Flip cardAn IAM role for BigQuery that grants read-only access to a specific dataset, table, or view.
- Allows querying data but not modifying schema, data, or managing jobs.
- Useful for analysts or applications that only need to consume data.
- Can be granted at the dataset, table, or project level (though project level is less granular).
Memory trick: To see the data, grant the Viewer role on the specific dataset, no more, no less, just the exact asset.
Data Access Logs
Flip cardData Access logs record API calls that read or modify user-provided data within Google Cloud resources.
- Must be explicitly enabled for specific services (e.g., Cloud Storage).
- Captures 'DATA_READ' and 'DATA_WRITE' operations.
- Essential for auditing access to sensitive data for compliance and security.
Memory trick: Data logs are the watchdogs for your precious data.
Google-managed Service Account Key
Flip cardA Google-managed service account key refers to credentials that are automatically provisioned and rotated by Google Cloud, typically used when a service account is attached to a resource like a VM.
- No physical key file is generated or downloaded by the user.
- Credentials are short-lived and automatically rotated by Google Cloud.
- Enhances security by eliminating key management overhead and reducing compromise risk.
Memory trick: Google-managed means Google handles the key and its rotation.
IAM Policy Audit Logging
Flip cardIAM policy audit logging refers to the process of recording changes made to Identity and Access Management policies in Google Cloud.
- Changes are captured in Admin Activity logs.
- Records who made the change, the specific policy modification, and the timestamp.
- Essential for security audits and compliance tracking of access controls.
Memory trick: Admin logs report on the administrators changing the rules.
Least Privilege for Service Accounts
Flip cardThe security principle of granting a service account only the minimum necessary permissions to perform its intended function, reducing potential security risks.
- Avoid using primitive roles (Owner, Editor, Viewer) for service accounts.
- Use predefined roles that match specific tasks.
- Create custom roles if predefined roles are too broad.
Memory trick: Give your service account only the keys it needs, no extra access, no security seeds.
Viewer IAM Role
Flip cardA predefined IAM role in Google Cloud that grants read-only access to all resources within a project or organization.
- Provides permissions like `compute.instances.get`, `storage.buckets.get`.
- Does not grant permissions to modify, create, or delete resources.
- Ideal for users who need to monitor or audit resources without making changes.
Memory trick: Owner rules all, Editor changes all, Viewer just sees all, Billing pays all.
Storage Object Viewer Role
Flip cardThe `roles/storage.objectViewer` IAM role grants read-only access to objects within a Cloud Storage bucket.
- Allows listing and getting objects.
- Does not allow creating, updating, or deleting objects.
- Adheres to the principle of least privilege for read-only access.
Memory trick: Remember, 'Viewer' sees, 'Admin' owns, 'Editor' changes.
External HTTP(S) Load Balancing
Flip cardA global, proxy-based load balancer for HTTP and HTTPS traffic, offering advanced traffic management and resilience across multiple regions and zones.
- Global load balancer
- Proxy-based for HTTP(S) traffic
- Supports multiple regions/zones, intelligent routing
Memory trick: HTTP(S) external is the global gateway for your web apps.
Persistent Disk
Flip cardDurable, high-performance block storage that can be attached to Compute Engine instances, providing storage for operating systems and application data.
- Block storage, not object or file
- Attaches to Compute Engine instances
- Zonal or regional options
- Offers various performance tiers (Standard, SSD, Balanced, Extreme)
Memory trick: Compute Engine needs a 'Disk' to 'Persist' its data.
Cloud Dataflow
Flip cardA fully managed service for executing Apache Beam pipelines, enabling scalable and cost-effective batch and stream data processing.
- Fully managed and serverless
- Auto-scaling for batch and stream processing
- Pay-per-use, integrates with Cloud Storage
Memory trick: Dataflow flows through your big data, effortlessly scaling.
Instance Template
Flip cardA global resource in Google Cloud that defines the configuration for Compute Engine instances, including machine type, boot disk, network, and other properties.
- Ensures consistent VM deployments
- Used by Managed Instance Groups (MIGs)
- Can include boot disk image, machine type, network, metadata, firewall tags
- Does not create instances itself, but defines how they are created
Memory trick: Instance Template: The blueprint for your perfect VM.
Cloud NAT
Flip cardA managed service that enables instances without external IP addresses to connect to the internet, providing a centralized egress point for outbound traffic.
- Enables internet access for private VMs
- Centralized egress point
- No external IPs needed for instances
Memory trick: NAT is the gatekeeper for private VMs to talk to the net.
MIG Autohealing
Flip cardA feature of Managed Instance Groups (MIGs) that automatically replaces or restarts unhealthy instances based on configured health checks, ensuring application availability.
- Requires a Managed Instance Group
- Uses health checks (HTTP, TCP, SSL) to determine instance health
- Automatically replaces or restarts unhealthy instances
- Ensures application-level availability, not just VM uptime
Memory trick: MIGs are like doctors for your VMs, always checking heartbeats.
Regional storage
Flip cardA Cloud Storage class that stores data redundantly across at least three zones within a single geographic region, suitable for data residency requirements.
- Data stays within one geographic region
- Redundant across multiple zones
- Suitable for high-performance and data residency needs
Memory trick: Regional storage clamps your data to one region, tight and right.
Cloud Monitoring Alert Policy
Flip cardA configuration in Google Cloud Monitoring that defines conditions under which an alert should be triggered and how notifications should be sent.
- Monitors specific metrics
- Triggers when a threshold is crossed
- Uses notification channels for delivery
Memory trick: Measure the Metric, hit the Threshold, send the Notification.
Filestore
Flip cardA fully managed Network File System (NFS) file storage service for applications running on Google Compute Engine and Google Kubernetes Engine.
- Managed NFS service
- Shared file system access
- Low-latency for Compute Engine/GKE
Memory trick: Filestore files, shared and fast, for your VMs to last.
Cloud Run
Flip cardA fully managed serverless platform that allows you to run stateless containers via web requests or Pub/Sub events.
- Serverless and fully managed
- Scales automatically (even to zero)
- Pay-per-use billing
Memory trick: Run the stateless container, let Cloud Run handle the rest.
Secret Manager
Flip cardA fully managed Google Cloud service for securely storing, managing, and accessing secrets such as API keys, passwords, and certificates.
- Stores secrets securely with strong encryption
- Provides automatic versioning for secrets
- Offers fine-grained access control (IAM)
- Integrates with other Google Cloud services
Memory trick: Secret Manager is the vault for your app's hidden treasures.
Cloud Functions with Storage Triggers
Flip cardA serverless compute service that runs code in response to events, including file uploads (object finalization) in Cloud Storage buckets.
- Event-driven execution model
- Serverless and scales automatically
- Supports various programming languages
- Ideal for lightweight, short-lived tasks triggered by cloud events
Memory trick: Event-Driven: 'When this happens, do that' – a cloud reaction system.
VPC Flow Logs
Flip cardA feature that records a sample of network flows sent from and received by VM instances in your Virtual Private Cloud (VPC) network.
- Captures network flow metadata
- No agents required on VMs
- Useful for security analysis and network monitoring
Memory trick: Flow Logs show the network's secrets, without touching a VM.
Bigtable
Flip cardA fully managed, highly scalable NoSQL wide-column database service designed for large analytical and operational workloads, offering petabyte scale and low latency.
- NoSQL wide-column store
- Petabyte scale and high throughput
- Single-digit millisecond latency
- Ideal for time-series data, marketing data, IoT data
Memory trick: NoSQL means 'No Schema, Often Scalable, Quick Lookups'.
Custom mode VPC network
Flip cardA type of Virtual Private Cloud (VPC) network that gives users full control over subnet creation, IP address ranges, and routing.
- Manual subnet creation
- Custom IP ranges
- Fine-grained firewall control
Memory trick: Custom VPC gives you the keys to your network's castle.
VPC Firewall Rules
Flip cardNetwork rules that control ingress and egress traffic to and from Compute Engine instances within a Virtual Private Cloud (VPC) network.
- Stateless, applied at the instance level
- Default deny for ingress, default allow for egress
- Can specify source/destination, protocols, ports, and targets
Memory trick: Firewall: Your network's bouncer, deciding who gets in or out.
Memorystore for Redis
Flip cardA fully managed in-memory data store service built on open-source Redis, offering extremely high performance for caching and real-time use cases.
- Fully managed in-memory data store
- Extremely low latency, high throughput
- Ideal for caching, session management, real-time data
Memory trick: Redis remembers fast, for microservices that can't wait.
Firestore
Flip cardA flexible, scalable NoSQL document database for mobile, web, and server development that offers real-time synchronization and offline support.
- NoSQL document database
- Flexible schema (semi-structured data)
- High read/write throughput and low latency
- Automatic scaling and fully managed
Memory trick: Firestore: The 'flexible diary' for your app's data.
Managed Instance Groups (MIGs) with Autohealing
Flip cardA Compute Engine feature that automatically maintains the health and availability of a group of instances, replacing unhealthy instances based on configured health checks.
- Automatically maintains instance health
- Uses health checks to detect failures
- Enables automated rollbacks for deployments
Memory trick: MIGs heal your instances, keeping your app alive and well.
Cloud Interconnect
Flip cardA Google Cloud networking service that provides direct, high-bandwidth, low-latency connections between an on-premises data center and Google Cloud VPC networks.
- Dedicated connectivity to Google Cloud
- Higher bandwidth and lower latency than VPN over public internet
- Offers both Dedicated Interconnect and Partner Interconnect options
- Ideal for hybrid cloud environments with critical workloads
Memory trick: Interconnect is the 'direct highway' to the cloud, VPN is the 'scenic route'.
Cloud Spanner
Flip cardA fully managed, mission-critical relational database service that offers transactional consistency, high availability, and global scale.
- Globally distributed
- Strongly consistent
- Relational database
Memory trick: Spanner stretches across zones, keeping data tight.
VPC Firewall Rule
Flip cardA resource in Google Cloud that allows or denies traffic to and from Compute Engine instances in a VPC network based on specified criteria.
- Can be ingress (inbound) or egress (outbound).
- Rules are stateful, meaning return traffic is automatically allowed.
- Can target instances by tags, service accounts, or all instances in the network.
Memory trick: Firewall Rules Guard VM Gates.
Application Default Credentials (ADC) for Users
Flip cardApplication Default Credentials (ADC) allow Google Cloud client libraries to automatically find and use credentials, often generated via `gcloud auth application-default login` for user accounts, providing secure, short-lived authentication.
- Provides credentials for client libraries.
- Uses short-lived tokens from user's Google account.
- Avoids storing long-lived service account keys locally.
- Simplifies authentication for local development.
Memory trick: For 'ADC' with 'Developers', 'Auth App-Default Login' is the 'C'hoice.
Service Accounts for GCP Instances
Flip cardService accounts are identities used by applications or Compute Engine instances to make authenticated API calls to Google Cloud services without user intervention. They are the recommended secure way to grant permissions to workloads running on GCP.
- Recommended for applications on Compute Engine, GKE, Cloud Run, etc.
- Credentials provided by instance metadata server (automatically rotated).
- Permissions granted via IAM roles to the service account.
Memory trick: Assign a service account to your instance for secure, automatic access.
GCP Project Creation
Flip cardA Google Cloud Project is the fundamental container for all Google Cloud resources. It organizes resources, enables billing, and manages permissions.
- Every resource belongs to a project.
- Projects have a name, ID, and number.
- Billing is linked at the project level.
Memory trick: Projects are the foundational building blocks, like starting a new construction site.
Organization Policy Service (Resource Location)
Flip cardThe Google Cloud Organization Policy Service allows administrators to define constraints across their resource hierarchy, including restricting resource deployment to specific geographic locations.
- Applies to Organization, Folder, or Project levels.
- Uses `constraints/gcp.resourceLocations`.
- Prevents resource creation in disallowed regions/zones.
Memory trick: For company-wide rules, use the Organization's policy scroll.
MIG Schedule-based Autoscaling
Flip cardA feature of Managed Instance Groups (MIGs) that allows configuring scaling policies to increase or decrease the number of instances at predefined times or intervals.
- Enables proactive scaling for anticipated traffic patterns.
- Can be combined with other autoscaling signals (e.g., CPU) for dynamic adjustments.
- Helps ensure resources are ready before peak demand, improving application performance.
Memory trick: Schedule for Predictable Peaks.
Pub/Sub + Dataflow
Flip cardA common Google Cloud architecture pattern for building real-time streaming data pipelines, where Pub/Sub handles message ingestion and Dataflow performs scalable transformations.
- Pub/Sub provides durable, low-latency message delivery.
- Dataflow offers fully managed, auto-scaling execution of Apache Beam pipelines.
- Ideal for real-time analytics, IoT data processing, and event-driven architectures.
Memory trick: Pub/Sub Feeds Dataflow Stream.
gcloud auth login
Flip cardThe `gcloud auth login` command authenticates the Google Cloud CLI with a user's Google account, granting it access to Google Cloud resources.
- Initiates a browser-based authentication flow.
- Stores user credentials locally.
- Required for most `gcloud` operations as a user.
Memory trick: To log in to gcloud, you need to 'auth login'.
GCP Folder Hierarchy
Flip cardFolders in Google Cloud provide an additional grouping mechanism for projects within an organization, allowing for the application of IAM policies and organizational policies that are inherited by contained projects.
- Organizes projects into logical groups.
- Enables policy inheritance from folders to projects.
- Useful for departmental or environment segregation.
Memory trick: Policies flow down the tree, from organization to individual resources.
Cloud Storage Archive
Flip cardA Google Cloud Storage class optimized for long-term data archiving with very infrequent access (e.g., once a year or less).
- Lowest cost for storing data.
- Highest cost for data retrieval and operations.
- Minimum storage duration of 365 days.
Memory trick: Storage Tiers: Standard, Near, Cold, Archive - SNCA.
gcloud config set project
Flip cardThe `gcloud config set project [PROJECT_ID]` command sets the default Google Cloud project for the active Cloud SDK configuration, allowing subsequent commands to operate within that project without explicit specification.
- Applies to the active configuration.
- Can be overridden by `--project` flag.
- Useful for quickly switching working contexts.
Memory trick: Configure your gcloud path, then target your project.
Cloud HSM
Flip cardA fully managed cloud-hosted hardware security module (HSM) service that allows you to generate, store, and manage cryptographic keys in FIPS 140-2 Level 3 validated HSMs.
- Integrates with Cloud KMS for key management.
- Provides the highest level of key protection and regulatory compliance.
- Keys are stored in dedicated hardware modules, not software.
Memory trick: HSM: Hardware Secures Mandated Keys.
GCP Billing Account Requirement
Flip cardAn active Google Cloud billing account is mandatory for creating and using billable resources within a project, even when the user has the necessary IAM permissions.
- No billing account = no resource creation (for most services).
- IAM permissions grant 'what you can do', billing account enables 'if you can do it'.
- Essential for project functionality beyond free-tier services.
Memory trick: No 'B'illing 'A'ccount, no 'B'ucket 'A'ctivity.
GCP Billing Budget Alerts
Flip cardGoogle Cloud Billing allows users to create budgets and set up alerts that notify them when their spending (actual or forecasted) approaches or exceeds a specified threshold.
- Can be set at the billing account or project level.
- Alerts can be based on actual or forecasted spend.
- Notifications sent via email or Pub/Sub.
Memory trick: To manage your money, you need a budget and a bell.
GCP Resource Hierarchy & Policy Inheritance
Flip cardGoogle Cloud's resource hierarchy (Organization > Folders > Projects > Resources) allows policies set at higher levels to be inherited by lower-level resources, enabling centralized control and delegated management.
- Policies flow down the hierarchy.
- Folders are key for organizing projects and applying policies.
- Organization is the root of the hierarchy.
Memory trick: Hierarchy is key: Organize with folders, then policies flow down, and creators build within.
gcloud CLI Authentication
Flip cardThe 'gcloud auth login' command authenticates the Cloud SDK with a Google account, allowing the CLI to interact with Google Cloud resources on behalf of that user.
- Opens a browser for Google account selection.
- Establishes user credentials for gcloud commands.
- Required before most gcloud operations.
Memory trick: First, you build the tools, then you unlock the cloud.
Project Creator Role
Flip cardThe 'Project Creator' IAM role grants permissions to create new Google Cloud projects within an organization or folder.
- Scoped to an organization or folder.
- Allows 'resourcemanager.projects.create' permission.
- Does not grant permissions to manage existing projects.
Memory trick: To create a project, you need the 'Creator' key, not the master key.
gcloud Named Configurations
Flip cardNamed configurations in `gcloud` allow users to define and switch between multiple sets of `gcloud` properties (like default project, account, region), streamlining workflows for different environments or projects.
- Store different `gcloud` settings.
- Activated using `gcloud config configurations activate`.
- Useful for switching between projects or accounts.
Memory trick: Configure your named settings, then activate to switch projects with ease.
gcloud Link Project to Billing Account
Flip cardThe `gcloud billing projects link` command is used to associate a Google Cloud project with a specific billing account, which is a prerequisite for deploying most resources.
- Connects a project to a billing account.
- Requires project ID and billing account ID.
- Necessary before resources can consume billable services.
Memory trick: Billing projects link is the command you need, to make your project's billing succeed.
Cloud Storage
Flip cardA highly scalable and durable object storage service for storing any type of unstructured data (objects) in Google Cloud.
- Offers different storage classes (Standard, Nearline, Coldline, Archive) for cost optimization.
- Objects are stored in buckets, which can be global or regional.
- Provides strong consistency and high availability.
Memory trick: Cloud Storage: Objects Everywhere.
Billing Account Creator Role
Flip cardThe 'Billing Account Creator' role grants permission to create new Google Cloud billing accounts.
- Required for establishing new billing accounts.
- Typically assigned at the organization level.
- Adheres to the principle of least privilege for billing management.
Memory trick: Creating a new bill? You need the 'Creator' role, not just a 'User' or 'Admin'.
IAM: Service Account Deployment Strategy
Flip cardTo enforce service account-only deployment in Google Cloud, create custom IAM roles with specific deployment permissions and assign them exclusively to approved service accounts, while granting user accounts only view-level access.
- Leverages custom roles for granular permission control.
- Service accounts perform automated deployments.
- User accounts are restricted to monitoring and management, not direct deployment.
- Adheres to the principle of least privilege.
Memory trick: Custom 'R'oles for 'R'obots, 'R'estricted 'R'ights for 'R'eal people.
Organization Policy for Naming Conventions
Flip cardThe Organization Policy Service, leveraging custom constraints with regular expressions, is used to enforce naming conventions for Google Cloud project IDs and other resources, preventing the creation of non-compliant resources.
- Prevents creation of non-compliant resources.
- Uses custom constraints with regex patterns.
- Applied at the Organization, Folder, or Project level.
- Constraint ID example: `constraints/resourcemanager.allowedProjectIds`.
Memory trick: Organization Policies are the only way to constrain project names from the start.
GCP Project Deletion Lock
Flip cardA Google Cloud project deletion lock is a type of resource lock that prevents a project from being deleted until the lock is explicitly removed, even by project owners.
- Protects against accidental project deletion.
- Must be explicitly removed before project deletion is possible.
- Applies to the entire project resource.
Memory trick: To 'lock' a project from 'deletion', use the 'deletion lock'.
Compute Engine
Flip cardGoogle Cloud's Infrastructure as a Service (IaaS) offering that allows users to create and run virtual machines on Google's infrastructure.
- Provides full control over the operating system and software stack.
- Supports various machine types, including those with GPUs and custom configurations.
- Billing is per second for most resources, offering cost flexibility.
Memory trick: Compute Engine: Control Everything.