Google Associate Cloud Engineer flashcards
134 free flashcards. Tap a card to flip it.
GCP Project Delete Lock
Flip cardThe Project Delete Lock is a feature that explicitly prevents a Google Cloud project from being deleted, providing an extra layer of protection against accidental or malicious project removal.
- Prevents project deletion until removed.
- Overrides most IAM permissions for deletion.
- Activated via `gcloud beta projects undelete set-policy`.
Memory trick: Lock your project to stop deletion, it's the strongest prevention.
Automated API Enablement on Project Creation
Flip cardAutomatically enabling specific Google Cloud APIs upon new project creation is achieved programmatically, typically using a Cloud Function triggered by Resource Manager events, which then interacts with the Service Usage API.
- Organization Policies restrict, not enable APIs.
- Cloud Functions can react to project creation events.
- Service Usage API is used to enable/disable APIs programmatically.
Memory trick: Function-al triggers enable APIs, not just policies and IAM keys.
Application Default Credentials (ADC)
Flip cardApplication Default Credentials (ADC) is a strategy used by Google Cloud client libraries to automatically find credentials, allowing applications to authenticate to Google Cloud services without explicit credential management.
- Standard authentication for client libraries.
- Finds credentials in a predefined order (environment var, config file, metadata service).
- Setup for local dev via `gcloud auth application-default login`.
Memory trick: For easy app authentication, use ADC, it's the best local key.
GCP Project Lock
Flip cardA Project Lock (or Resource Lock) in Google Cloud is a mechanism to prevent accidental or malicious deletion of a project, even by users with the Project Owner role, until the lock is explicitly removed.
- Requires `resourcemanager.projects.update` permission to apply/remove.
- Protects against accidental deletion.
- Can be applied via gcloud CLI or API.
Memory trick: To stop deletion, put a lock on the project.
Linking Project to Billing Account
Flip cardTo associate a Google Cloud project with a specific billing account, you navigate to the project's billing settings and select an existing billing account to link.
- A project must have an active billing account to use paid services.
- Only users with 'Billing Account User' or 'Billing Account Administrator' can link.
- Can be done via Console or gcloud CLI.
Memory trick: Create your project, then connect its wallet.
Organization Policy Service
Flip cardThe Organization Policy Service allows Google Cloud administrators to programmatically control resources across their entire organization, enforcing constraints like allowed resource locations.
- Applies policies at the Organization, Folder, or Project level.
- Enforces constraints like `constraints/gcp.resourceLocations`.
- Policies are inherited and can prevent non-compliant resource creation.
Memory trick: To organize and enforce policies across the organization, use the Organization Policy Service.
Cloud Interconnect (Dedicated)
Flip cardA Google Cloud networking service that provides a direct, private physical connection between an on-premises data center and Google's network.
- Offers higher bandwidth and lower latency compared to Cloud VPN.
- Provides a more secure and reliable connection as traffic does not traverse the public internet.
- Can be configured for high availability with redundant connections.
Memory trick: Interconnect for Critical Hybrid.
Org Policy for Cloud Storage
Flip cardOrganization Policy Service can enforce mandatory configurations for Google Cloud Storage buckets, such as default encryption settings, across an entire organization.
- Uses constraints like `gcp.restrictCmekCryptoKeys`.
- Prevents creation of non-compliant buckets.
- Enforces organization-wide security and compliance standards.
Memory trick: Org Policy is the 'Boss' for 'Buckets' ensuring 'Compliance'.
Cloud Audit Logs
Flip cardCloud Audit Logs record administrative activities, data access events, and system events across Google Cloud services for security, auditing, and compliance.
- Automatically enabled for Admin Activity logs.
- Data Access logs require explicit configuration.
- Integrates with Cloud Logging for storage and export.
Memory trick: When you need to audit, look for the 'Audit' in the logs.
GCP IAM Permission Denied
Flip cardA 'PERMISSION_DENIED' error in Google Cloud indicates that the authenticated principal (user, service account) lacks the necessary IAM permissions to perform a requested action on a specific resource.
- Requires assigning appropriate IAM roles.
- Permissions are granted via roles.
- Errors often specify the missing permission (e.g., `compute.instances.list`).
Memory trick: If the cloud says 'no', check your key (IAM).
Automated Label Application on Project Creation
Flip cardAutomating the application of specific labels to new Google Cloud projects is typically achieved using a Cloud Function (triggered by Resource Manager events) that calls the Resource Manager API to set the desired labels.
- Organization Policies restrict, but don't auto-apply labels.
- Cloud Functions are event-driven for post-creation actions.
- Resource Manager API is used to manage project labels programmatically.
Memory trick: Function-al triggers are key to label projects automatically, not just policies.
Cloud Billing Budgets and Alerts
Flip cardCloud Billing budgets allow users to set spending limits for Google Cloud projects and receive notifications when actual or forecasted costs approach or exceed these limits.
- Monitors Google Cloud spending.
- Can be set at the billing account or project level.
- Supports custom thresholds and notification channels (e.g., email, Pub/Sub).
Memory trick: For 'B'udgets and 'A'lerts on 'B'illing, use Cloud 'B'illing 'B'udgets and 'A'lerts.
Cloud Build Custom Steps
Flip cardCloud Build allows defining custom build steps using any container image, enabling execution of arbitrary commands within the build process.
- Each step runs in its own container.
- Steps can share data using a shared workspace volume.
- Commonly used for deploying to GKE, running tests, or custom scripting.
Memory trick: Build, Push, then Kube Deploy.
Centralized Billing with Project Tracking
Flip cardGoogle Cloud allows multiple projects to share a single billing account while providing detailed cost breakdowns by project in billing reports, often enhanced with resource labels for granular chargeback.
- One billing account can serve many projects.
- Billing reports show costs per project.
- Labels enable granular cost attribution for chargebacks.
Memory trick: Link all projects to ONE bill, then 'L'abel for 'L'earning costs.
Organization Default Billing
Flip cardA Google Cloud organization can designate a default billing account, which is automatically associated with any new projects created within that organization.
- Simplifies billing for large organizations.
- Applies to all new projects by default.
- Can be overridden at the project level if needed.
Memory trick: The organization is the top of the tree, where billing rules start.
Organization Policy: Resource Location Restriction
Flip cardThe Organization Policy Service, using the `constraints/gcp.resourceLocations` constraint, allows administrators to define and enforce geographic restrictions on where Google Cloud resources can be created, ensuring compliance with data residency requirements.
- Enforces data residency requirements.
- Prevents creation of resources outside specified locations.
- Applied at Organization, Folder, or Project level.
- Uses `constraints/gcp.resourceLocations`.
Memory trick: Org Policies constrain where your resources can be, for geo-compliance, it's the key.
VPC Network
Flip cardA global, private, and isolated network in Google Cloud that allows your resources (e.g., Compute Engine instances) to communicate with each other and with on-premises networks using private IP addresses.
- Global resource
- Private IP communication by default
- Provides network isolation
Memory trick: NETWORK (Networking, Environment, Workload, Options, Resource)
Cloud DNS Failover
Flip cardCloud DNS Failover uses health checks to monitor endpoints and automatically redirects traffic to healthy alternative endpoints (e.g., in another region) by updating DNS records when the primary endpoints fail.
- DNS-based traffic redirection
- Uses health checks to determine endpoint health
- Supports multi-region disaster recovery
Memory trick: DNS Failover: If one region's down, DNS points to the next town.
Cloud DNS with Failover
Flip cardCloud DNS allows configuration of failover policies to automatically redirect traffic to healthy resources in different regions or zones in case of an outage.
- Global DNS service
- Health checks for endpoints
- Automatic traffic redirection during outages
Memory trick: RECOVER (Regional Resilience, Endpoint Checks, Cloud DNS, Outage Management, Versatility)
Cloud Storage Standard
Flip cardThe default storage class for Cloud Storage, designed for frequently accessed data with low latency and high throughput. Suitable for a wide range of use cases.
- Lowest latency and highest throughput
- Highest storage cost per GB
- No retrieval fees or early deletion charges
Memory trick: ACCESS (Access frequency, Cost, Coldness, Efficiency, Storage)
Cloud Pub/Sub
Flip cardA fully managed, asynchronous messaging service that decouples senders and receivers, enabling highly scalable and reliable real-time message delivery.
- Real-time and highly scalable.
- At least once delivery guarantee.
- Decouples microservices and distributed systems.
Memory trick: Pub/Sub publishes messages for subscribers to pick up.
Regional External HTTP(S) Load Balancing
Flip cardA Google Cloud load balancing service that distributes HTTP(S) traffic to backend services within a specific region, providing a regional external IP address.
- Regional external IP address.
- Distributes HTTP(S) traffic.
- Supports health checks and automatic failover.
Memory trick: Regional HTTP(S) Load Balancing keeps regional apps balanced and healthy.
App Engine Standard Environment
Flip cardA serverless platform for building and deploying highly scalable applications. It automatically scales resources up and down, even to zero, based on traffic.
- Fully managed and serverless
- Automatic scaling to zero
- Supports various programming languages
Memory trick: SCALE (Scalability, Cost, Automatic, Low-Ops, Elasticity)
Compute Engine Sole-Tenant Nodes
Flip cardDedicated physical servers within Google Cloud that are allocated exclusively to your project. They allow you to run your Compute Engine VMs on isolated hardware, meeting specific compliance, security, or licensing requirements for single-tenancy.
- Dedicated physical servers
- Ensures single-tenancy and physical isolation
- Addresses specific compliance and licensing needs
- Offers control over host maintenance events
Memory trick: VM Isolation: If your app needs its 'own room', pick the 'key' that fits!
BigQuery
Flip cardA serverless, highly scalable, and cost-effective multi-cloud data warehouse designed for business agility.
- Petabyte-scale analytics.
- SQL query engine.
- Serverless and fully managed.
Memory trick: Big data needs BigQuery for big insights.
Cloud SQL Auth Proxy
Flip cardA proxy client for Cloud SQL that provides secure, encrypted connections to Cloud SQL instances without the need for whitelisted IP addresses or SSL certificates.
- Uses IAM for authentication.
- Encrypts all traffic.
- Connects to Cloud SQL instances privately.
Memory trick: Auth Proxy privately connects securely.
Cloud Bigtable
Flip cardCloud Bigtable is a fully managed, petabyte-scale NoSQL database service ideal for large analytical and operational workloads, including IoT, time-series data, and financial data.
- High throughput and low latency
- Wide-column NoSQL database
- Scales to petabytes of data
Memory trick: Bigtable for Big Data from IoT's Big Stream.
Google Kubernetes Engine (GKE)
Flip cardA managed service for deploying, managing, and scaling containerized applications using Kubernetes on Google Cloud. It automates much of the infrastructure management for container orchestration.
- Managed Kubernetes service
- Container orchestration
- Automatic scaling, load balancing, self-healing
- Service discovery built-in
Memory trick: Containers: If your 'fleet' needs a 'Captain', GKE is the clear choice!
Cloud CDN
Flip cardCloud CDN (Content Delivery Network) leverages Google's global network to serve content closer to users, reducing latency and improving performance for web and video streaming applications.
- Global edge network for caching content
- Reduces latency and improves user experience
- Integrates with Cloud Storage and Compute Engine
Memory trick: CDN makes content zoom across the globe!
GKE Autopilot
Flip cardGKE Autopilot is a mode of Google Kubernetes Engine that provides a fully managed Kubernetes experience, where Google automatically manages the cluster's control plane and data plane (nodes), including provisioning, scaling, and repairing.
- Fully managed control plane and nodes
- Pay-per-pod resource model
- Automatic node provisioning and scaling
Memory trick: Autopilot: Kubernetes on cruise control.
External HTTP(S) Load Balancing (Global)
Flip cardA global, Layer 7 (HTTP/S) load balancer on Google Cloud that provides a single external IP address, distributing traffic to backend services across multiple regions based on proximity and health checks. It's ideal for global web applications requiring high availability and low latency.
- Layer 7 (HTTP/S) load balancing
- Global scope with a single IP address
- Distributes traffic to nearest healthy backend
- Supports SSL termination
Memory trick: Load Balancers: Direct your 'traffic' with the right 'traffic cop'!
Virtual Private Cloud (VPC) Network
Flip cardA global, logically isolated network on Google Cloud that provides networking functionality for Google Cloud resources. It enables resources in different regions to communicate and provides a private IP space.
- Logically isolated network
- Global scope (can span regions)
- Provides private IP addresses for resources
- Enables secure and private communication between resources
Memory trick: Network Isolation: Your cloud 'home' needs a strong 'fence' around it!
Compute Engine Preemptible VMs
Flip cardCompute Engine virtual machine instances that can be shut down (preempted) by Google Cloud if resources are needed elsewhere. They are significantly cheaper than standard VMs and are suitable for fault-tolerant, batch, or non-critical workloads.
- Up to 80% cheaper than standard VMs
- Can be preempted (stopped) by Google Cloud
- Maximum run time of 24 hours (can be restarted)
- Ideal for fault-tolerant batch jobs, stateless applications
Memory trick: VM types: Pick the 'personality' that matches your app's 'life story'!
Multicast in VPC Networks
Flip cardWhile Google Cloud VPC networks do not natively support IP multicast at the network layer, specific configurations or third-party solutions can be implemented to enable multicast communication for legacy applications.
- VPC networks are unicast by default.
- Requires specific configuration (e.g., custom routes, proxy) for multicast support.
- Primarily for migrating legacy applications that depend on multicast.
Memory trick: Multicast routing in VPC makes old apps feel new.
Cloud Functions
Flip cardGoogle Cloud's Function as a Service (FaaS) offering. It allows developers to deploy single-purpose functions that respond to events without managing servers or runtimes. It's fully managed and scales automatically.
- Serverless and fully managed
- Event-driven execution model
- Pay-per-use (billed per invocation and compute time)
- Supports various programming languages
Memory trick: Serverless: If your code is a 'spark', choose the 'cloud' that lets it fly free!
Cloud SQL
Flip cardA fully managed relational database service on Google Cloud that supports MySQL, PostgreSQL, and SQL Server. It handles patching, backups, replication, and provides high availability.
- Managed relational database (MySQL, PostgreSQL, SQL Server)
- Automatic backups and replication
- High availability options
- Encryption at rest and in transit
Memory trick: Storage choices: Match your data's 'personality' to its perfect 'home'!
Cloud SQL for Compliance
Flip cardA managed relational database service on Google Cloud that supports robust security features, including encryption, granular access control, and auditing, making it suitable for regulated workloads like HIPAA.
- Managed relational database (MySQL, PostgreSQL, SQL Server).
- Encryption at rest and in transit.
- IAM for fine-grained access control.
- Cloud Audit Logs for compliance.
Memory trick: Cloud SQL secures sensitive data with strict controls.
Cloud Storage Nearline
Flip cardA Google Cloud Storage class optimized for data that is accessed infrequently (less than once a month) but requires fast retrieval (milliseconds). It balances lower storage costs with slightly higher retrieval costs and a 30-day minimum storage duration.
- Access frequency: less than once a month
- Retrieval time: milliseconds
- Minimum storage duration: 30 days
- Cost: Lower than Standard, higher than Coldline/Archive
Memory trick: Storage classes: Match 'how often' you need it to 'how much' you pay!
Dedicated Interconnect
Flip cardA Google Cloud networking service that provides a direct physical connection from your on-premises data center to Google's global network, offering dedicated bandwidth, high availability, and an SLA.
- Direct physical connection.
- Dedicated bandwidth.
- Offers an SLA for uptime.
- Low latency and high throughput.
Memory trick: Dedicated Interconnect dedicates a direct line to the cloud.
Global External HTTP(S) Load Balancer
Flip cardA Global External HTTP(S) Load Balancer distributes HTTP and HTTPS traffic across multiple regions, providing global load balancing, automatic failover, and high availability for web applications.
- Global Anycast IP address
- Supports multiple regions for backend services
- Automatic failover and health checks
Memory trick: Global Load Balancer: Your traffic's worldwide safety net.
Cloud Storage Coldline
Flip cardCloud Storage Coldline is a low-cost, highly durable storage class optimized for data accessed less than once a month, suitable for backups, disaster recovery, and data archiving.
- Lower storage cost than Standard and Nearline
- Higher retrieval cost and latency than Standard and Nearline
- Minimum storage duration of 90 days
Memory trick: Standard, Near, Cold, Archive: a spectrum of access and cost.
Google Cloud Dataproc
Flip cardA fully managed, highly scalable service for running Apache Spark, Hadoop, Flink, and Presto clusters on Google Cloud.
- Supports on-demand cluster creation and deletion.
- Integrates with Cloud Storage, BigQuery, and other GCP services.
- Cost-effective for ephemeral batch processing workloads.
Memory trick: Dataproc 'processes' data like a 'pro' with Spark.
Google Cloud Multicast Routing
Flip cardA feature within Google Cloud Virtual Private Cloud (VPC) that enables the use of IP multicast traffic within and across VPC networks.
- VPC networks do not support multicast by default.
- Requires explicit configuration of PIM (Protocol Independent Multicast).
- Essential for migrating legacy applications that rely on multicast for service discovery or communication.
Memory trick: Multicast needs a 'multi-cast' configuration in the cloud.
Cloud SQL Private IP
Flip cardCloud SQL instances can be configured with a private IP address, allowing them to connect to Compute Engine VMs, GKE clusters, and other services within the same VPC network without needing public IP addresses.
- Uses internal IP addresses.
- Enhances security by avoiding public exposure.
- Requires VPC Peering for cross-project/network access.
- Ensures low-latency, high-bandwidth connection.
Memory trick: Private IP keeps SQL's secrets safe inside the VPC fence.
Compute Engine with MIGs
Flip cardCompute Engine offers Infrastructure as a Service (IaaS) with full control over virtual machines. Managed Instance Groups (MIGs) automate the deployment, management, and scaling of multiple VMs.
- Full OS and software control.
- MIGs provide auto-scaling and auto-healing.
- Ideal for custom configurations and lift-and-shift migrations.
- Requires more management overhead than PaaS/serverless.
Memory trick: Compute Engine with MIGs gives you the VM keys and a scaling crew.
App Engine Standard
Flip cardA serverless Platform as a Service (PaaS) that runs applications in a fully managed environment with specific language runtimes.
- Supports automatic scaling, including to zero instances.
- Provides built-in services like load balancing, security, and logging.
- Pay-per-use pricing model, only for resources consumed.
Memory trick: App Engine for code, Cloud Run for containers, Functions for events.
Cloud Deployment Manager
Flip cardAn infrastructure-as-code service that enables you to specify all the resources needed for your application in a declarative format using configuration files. It automates the deployment and management of these resources.
- Infrastructure as Code (IaC).
- Uses YAML for configuration files.
- Deploys resources as a single unit.
- Ensures consistency and repeatability.
Memory trick: Deployment Manager builds your Cloud castle from a blueprint.
Cloud Storage Standard Storage
Flip cardThe default storage class for frequently accessed data, offering high availability, durability, and low-latency access.
- Ideal for data accessed multiple times a month.
- Lowest access costs among all classes.
- Suitable for websites, mobile apps, streaming data, and interactive workloads.
- Offers regional, multi-regional, and dual-regional locations.
Memory trick: Remember the 'temperature' of your data: Hot for frequent, Cold for rare, Archive for frozen.
Google Cloud Service Accounts
Flip cardA special type of Google account used by non-human components (like VMs, applications, or other services) to authenticate and authorize access to Google Cloud resources.
- Represent an application or VM identity.
- Permissions granted via IAM roles.
- Avoids the need to store sensitive user credentials or API keys on VMs/in code.
Memory trick: Service Accounts 'serve' the 'account' for VMs.
Google Cloud Functions
Flip cardA serverless execution environment for building and connecting cloud services through event-driven functions.
- Executes code in response to events (e.g., Cloud Storage uploads, Pub/Sub messages).
- Fully managed and scales automatically.
- Supports various programming languages (Node.js, Python, Go, Java, .NET, Ruby, PHP).
Memory trick: Functions are 'functional' for event triggers.
Google Cloud AI Platform Prediction
Flip cardA fully managed service for deploying machine learning models into production at scale, handling infrastructure, scaling, and model serving.
- Supports models from various ML frameworks.
- Manages infrastructure, scaling, and high availability.
- Can leverage GPUs for accelerated inference.
Memory trick: AI Platform is the 'AI' for 'platform' deployment.
Dataproc
Flip cardA fully managed, highly scalable service for running Apache Spark, Hadoop, Flink, and Presto clusters on Google Cloud. It simplifies big data processing with auto-scaling and cost-effectiveness.
- Fully managed Spark, Hadoop, Flink, Presto.
- Auto-scaling clusters.
- Cost-effective (per-second billing).
- Integrates with other GCP services.
Memory trick: Dataproc: Your managed Spark engine for big data's start.
Vertex AI Prediction
Flip cardA fully managed service within Google Cloud's Vertex AI platform for deploying and serving machine learning models for online (real-time) predictions.
- Supports custom containers for model deployment.
- Can leverage GPU acceleration for inference.
- Provides model monitoring and version management.
- Offers auto-scaling based on traffic patterns.
Memory trick: Vertex AI Prediction: It's the 'peak' for putting your machine learning models to work, smart and fast.
Cloud SQL High Availability (HA)
Flip cardA configuration for Cloud SQL instances that provides automatic failover to a standby replica in a different zone, ensuring continuous database operation.
- Primary instance and a standby replica are in separate zones.
- Synchronous replication ensures data consistency.
- Automatic failover in case of primary instance or zone failure.
- Reduces downtime for critical applications.
Memory trick: Cloud SQL: The easy button for your relational databases, especially when you need it always on.
Google Cloud Spanner
Flip cardA globally distributed, strongly consistent, and horizontally scalable relational database service designed for mission-critical applications.
- Combines relational database features with NoSQL scalability.
- Offers global transactional consistency.
- Provides 99.999% availability for multi-region instances.
Memory trick: Spanner 'spans' the 'globe' with 'strong' consistency.
Cloud Deployment Manager `dependsOn`
Flip cardA property used in Cloud Deployment Manager templates to specify that a resource must be created or updated after another specified resource.
- Ensures proper provisioning order for interdependent resources.
- Prevents errors from resources attempting to use non-existent dependencies.
- Can reference other resources within the same template.
- Is a declarative way to manage resource orchestration.
Memory trick: DependsOn: 'This needs that first' – it's all about ordered building.
Custom Static Routes
Flip cardUser-defined routes within a VPC network that specify how traffic should be forwarded to specific destinations, often used to direct traffic through network virtual appliances.
- Define destination IP range and a next hop.
- Next hop can be an instance, internal IP, VPN tunnel, or peering connection.
- Used for routing traffic to firewalls, NAT gateways, or other network appliances.
- Can specify a tag to apply the route only to instances with that tag.
Memory trick: Routes are like road signs for your network, telling traffic exactly where to go, even to a security checkpoint.
Google Cloud Storage
Flip cardA highly scalable and durable object storage service for various data types, from frequently accessed to long-term archives. It's ideal for unstructured data, backups, and large-scale data lakes.
- Object storage (not file or block).
- Global, highly durable, and available.
- Scales infinitely.
- Different storage classes for cost optimization.
Memory trick: Cloud Storage holds all your objects, big and small, without a wall.
Cloud Key Management Service (KMS)
Flip cardA cloud-hosted key management service that lets you manage cryptographic keys for your cloud services and applications.
- Supports symmetric and asymmetric encryption keys.
- Integrates with many Google Cloud services for CMEK.
- Provides key rotation, auditing, and access control.
Memory trick: KMS for encryption keys, Secret Manager for secrets, IAM for access.