Google Associate Cloud Engineer flashcards
134 free flashcards. Tap a card to flip it.
Service Accounts for Compute Engine
Flip cardSpecial Google Cloud accounts used by applications or Compute Engine instances to make authorized API calls.
- Credentials are automatically managed by Google Cloud (instance metadata).
- Allows granting granular permissions using IAM roles.
- Adheres to the principle of least privilege by assigning only necessary roles.
Memory trick: Service account for secure access, no keys needed.
Workload Identity
Flip cardA feature in GKE that allows Kubernetes service accounts to act as Google Cloud service accounts. This enables Pods to securely access Google Cloud services without needing to store or manage service account keys.
- Binds Kubernetes SA to Google Cloud SA.
- Eliminates need for explicit service account keys.
- Provides fine-grained authorization.
- Enhances security posture for GKE workloads.
Memory trick: Workload Identity: Your Pods wear a GCP badge, no key needed.
Google Cloud Custom Static Routes
Flip cardUser-defined routes in a Google Cloud VPC network that specify how traffic should be forwarded, often used to direct traffic through network virtual appliances.
- Overrides default routes for specific destinations.
- Can specify a next hop as a VM instance, VPN tunnel, or internal IP.
- Essential for implementing network security patterns like centralized egress inspection.
Memory trick: Custom Routes 'route' traffic through 'custom' appliances.
Google Cloud Filestore
Flip cardA fully managed Network Attached Storage (NAS) service for applications that require a file system interface and a shared file system for data.
- Offers NFSv3 and NFSv4.1 protocol support.
- Can be integrated with GKE as PersistentVolumes.
- Provides high performance and low latency for file-based workloads.
Memory trick: Filestore is the 'file store' for GKE's persistent needs.
Vertex AI Prediction
Flip cardA managed service within Vertex AI that enables deploying machine learning models as scalable, highly available endpoints for real-time online predictions.
- Supports custom containerized models.
- Provides automatic scaling and load balancing.
- Offers integrated monitoring, logging, and explainability features.
Memory trick: Vertex AI for managed ML, GKE for custom control, Functions for simple tasks.
Compute Engine with MIGs
Flip cardCompute Engine offers Infrastructure as a Service (IaaS) with full control over virtual machines. Managed Instance Groups (MIGs) automate the deployment, management, and scaling of multiple VMs.
- Full OS and software control.
- MIGs provide auto-scaling and auto-healing.
- Ideal for custom configurations and lift-and-shift migrations.
- Requires more management overhead than PaaS/serverless.
Memory trick: Compute Engine with MIGs gives you the VM keys and a scaling crew.
App Engine Standard
Flip cardA serverless Platform as a Service (PaaS) that runs applications in a fully managed environment with specific language runtimes.
- Supports automatic scaling, including to zero instances.
- Provides built-in services like load balancing, security, and logging.
- Pay-per-use pricing model, only for resources consumed.
Memory trick: App Engine for code, Cloud Run for containers, Functions for events.
Cloud Deployment Manager
Flip cardAn infrastructure-as-code service that enables you to specify all the resources needed for your application in a declarative format using configuration files. It automates the deployment and management of these resources.
- Infrastructure as Code (IaC).
- Uses YAML for configuration files.
- Deploys resources as a single unit.
- Ensures consistency and repeatability.
Memory trick: Deployment Manager builds your Cloud castle from a blueprint.
Cloud Storage Standard Storage
Flip cardThe default storage class for frequently accessed data, offering high availability, durability, and low-latency access.
- Ideal for data accessed multiple times a month.
- Lowest access costs among all classes.
- Suitable for websites, mobile apps, streaming data, and interactive workloads.
- Offers regional, multi-regional, and dual-regional locations.
Memory trick: Remember the 'temperature' of your data: Hot for frequent, Cold for rare, Archive for frozen.
Google Cloud Service Accounts
Flip cardA special type of Google account used by non-human components (like VMs, applications, or other services) to authenticate and authorize access to Google Cloud resources.
- Represent an application or VM identity.
- Permissions granted via IAM roles.
- Avoids the need to store sensitive user credentials or API keys on VMs/in code.
Memory trick: Service Accounts 'serve' the 'account' for VMs.
Google Cloud Functions
Flip cardA serverless execution environment for building and connecting cloud services through event-driven functions.
- Executes code in response to events (e.g., Cloud Storage uploads, Pub/Sub messages).
- Fully managed and scales automatically.
- Supports various programming languages (Node.js, Python, Go, Java, .NET, Ruby, PHP).
Memory trick: Functions are 'functional' for event triggers.
Google Cloud AI Platform Prediction
Flip cardA fully managed service for deploying machine learning models into production at scale, handling infrastructure, scaling, and model serving.
- Supports models from various ML frameworks.
- Manages infrastructure, scaling, and high availability.
- Can leverage GPUs for accelerated inference.
Memory trick: AI Platform is the 'AI' for 'platform' deployment.
Cloud SQL High Availability (HA)
Flip cardA configuration for Cloud SQL instances that provides automatic failover to a standby replica in a different zone, ensuring continuous database operation.
- Primary instance and a standby replica are in separate zones.
- Synchronous replication ensures data consistency.
- Automatic failover in case of primary instance or zone failure.
- Reduces downtime for critical applications.
Memory trick: Cloud SQL: The easy button for your relational databases, especially when you need it always on.
Google Cloud Interconnect (Dedicated)
Flip cardA physical, direct connection between an on-premises network and Google Cloud, bypassing the public internet.
- Offers high bandwidth and low latency.
- Provides enhanced security and compliance by avoiding the public internet.
- Requires physical provisioning and a Google Cloud partner or colocation facility.
Memory trick: To 'interconnect' your private 'cloud' with Google, 'dedicated' means *no public internet*.