Associate Cloud Engineer (ACE)
Google Cloud certification for fundamental cloud engineering tasks.
Getting Started: How the Exam Works
Free knowledge base
Everything from the course in one searchable place: 255 entries. Use it to review before a practice test or look up a word you forgot.
255 results
Google Cloud certification for fundamental cloud engineering tasks.
Getting Started: How the Exam Works
Official document detailing exam objectives and content.
Getting Started: How the Exam Works
Major section of exam objectives, grouping related topics.
Getting Started: How the Exam Works
Question type with one correct answer from several options.
Getting Started: How the Exam Works
Question type requiring selection of all correct answers.
Getting Started: How the Exam Works
Supervisor who monitors exam integrity during testing.
Getting Started: How the Exam Works
Platform offering labs and courses for Google Cloud learning.
Getting Started: How the Exam Works
To remember the five domains, think 'E.P.D.O.S.': Environment, Planning, Deployment, Operations, Security!
Getting Started: How the Exam Works
The exam focuses heavily on IAM roles and policies, especially understanding the principle of least privilege. Memorize common predefined roles like 'Viewer', 'Editor', 'Owner', and service-specific roles like 'Compute Instance Admin (v1)'. Look for keywords like 'minimum necessary permissions'.
Getting Started: How the Exam Works
Underestimating the importance of hands-on practice; theoretical knowledge alone is insufficient.
Getting Started: How the Exam Works
Not reviewing the official exam guide regularly for updates or changes to objectives.
Getting Started: How the Exam Works
Focusing too much on niche services instead of the core compute, storage, and networking services.
Getting Started: How the Exam Works
Web-based GUI for managing Google Cloud resources.
Getting Started: How the Exam Works
Command-line interface for Google Cloud resource management.
Getting Started: How the Exam Works
Browser-based command-line environment with pre-installed tools.
Getting Started: How the Exam Works
Storage that retains data even after a VM instance is stopped.
Getting Started: How the Exam Works
Identity and Access Management, controlling resource access.
Getting Started: How the Exam Works
Organizational unit for Google Cloud resources and billing.
Getting Started: How the Exam Works
Any entity in Google Cloud, e.g., VM, storage bucket, network.
Getting Started: How the Exam Works
Console is for 'See,' CLI is for 'Script.' If you need to see it, use the Console. If you need to script it, use the CLI.
Getting Started: How the Exam Works
The exam often presents scenarios and asks which tool (Console or gcloud) is most appropriate. Look for keywords like 'automate,' 'script,' 'many resources,' or 'programmatic' for gcloud. Look for 'visualize,' 'quick check,' 'one-off,' or 'first time' for the Console.
Getting Started: How the Exam Works
Trying to perform complex, repetitive tasks manually through the Console instead of scripting with gcloud.
Getting Started: How the Exam Works
Forgetting that Cloud Shell provides a pre-configured gcloud environment, saving local installation time.
Getting Started: How the Exam Works
Not understanding the consistent gcloud command structure, leading to syntax errors.
Getting Started: How the Exam Works
Unique, user-defined identifier for a project.
Setting Up Your Cloud Environment
Unique, automatically generated identifier for a project.
Setting Up Your Cloud Environment
Defines who pays for Google Cloud resource usage.
Setting Up Your Cloud Environment
Non-human account for applications to access resources.
Setting Up Your Cloud Environment
Root node for enterprise Google Cloud resources.
Setting Up Your Cloud Environment
Container within an Organization to group projects.
Setting Up Your Cloud Environment
P.A.S.S. for Projects: Project ID, Account (Billing), Service Account, Structure (Hierarchy).
Setting Up Your Cloud Environment
The exam frequently tests your understanding of the Google Cloud resource hierarchy. Remember the order: Organization > Folders > Projects > Resources. Also, know that every resource must belong to a project, and every project must be linked to a billing account.
Setting Up Your Cloud Environment
Forgetting to link a project to a billing account, which prevents you from using billable services.
Setting Up Your Cloud Environment
Granting overly broad permissions to a service account, leading to potential security vulnerabilities.
Setting Up Your Cloud Environment
Accidentally deleting a project without understanding that it removes all contained resources permanently after a grace period.
Setting Up Your Cloud Environment
A set spending limit for Google Cloud resources.
Setting Up Your Cloud Environment
Notification when spending approaches/exceeds budget.
Setting Up Your Cloud Environment
Method used to pay for Google Cloud services.
Setting Up Your Cloud Environment
Practices to control and optimize cloud spending.
Setting Up Your Cloud Environment
Key-value pair for organizing and tracking resources.
Setting Up Your Cloud Environment
BILLS (Billing, Identify, Link, Labels, Set) helps you remember the steps: Billing account, Identify projects, Link payment, Use Labels, Set budgets.
Setting Up Your Cloud Environment
The exam often tests your understanding of the billing hierarchy and how to create budget alerts. Look for keywords like 'control costs', 'prevent overspending', or 'notify stakeholders'. Remember that budgets can be set for a billing account or specific projects within it.
Setting Up Your Cloud Environment
Forgetting to link a project to a billing account, which prevents resource creation.
Setting Up Your Cloud Environment
Not setting up budget alerts, leading to unexpected high bills.
Setting Up Your Cloud Environment
Assigning overly broad IAM roles for billing management, creating security risks.
Setting Up Your Cloud Environment
A set of tools for managing Google Cloud resources.
Setting Up Your Cloud Environment
A command-line tool for managing Cloud Storage buckets and objects.
Setting Up Your Cloud Environment
A command-line tool for interacting with BigQuery.
Setting Up Your Cloud Environment
Command to initialize and configure the gcloud CLI.
Setting Up Your Cloud Environment
Command group for managing gcloud properties and configurations.
Setting Up Your Cloud Environment
A named set of gcloud properties, including account and project.
Setting Up Your Cloud Environment
The process of verifying your identity to Google Cloud.
Setting Up Your Cloud Environment
SDK: 'S'etup 'D'eveloper 'K'it. Remember the three main tools: gcloud (general), gsutil (storage), bq (BigQuery).
Setting Up Your Cloud Environment
The exam expects you to know how to install the Cloud SDK on common operating systems and use `gcloud init` for initial setup. Pay attention to commands for setting default projects and managing configurations, as these are frequently tested.
Setting Up Your Cloud Environment
Forgetting to run `gcloud init` after installation, leading to authentication errors.
Setting Up Your Cloud Environment
Not setting a default project, requiring `--project` flag on every command.
Setting Up Your Cloud Environment
Confusing `gcloud config set project` with `gcloud config configurations activate`.
Setting Up Your Cloud Environment
Set of tools for interacting with Google Cloud services.
Setting Up Your Cloud Environment
Persistent 5GB storage in Cloud Shell for user files.
Setting Up Your Cloud Environment
Arguments that modify gcloud command behavior (e.g., --project).
Setting Up Your Cloud Environment
gcloud flag to specify output format (e.g., json, yaml, table).
Setting Up Your Cloud Environment
gcloud flag to specify the target Google Cloud project.
Setting Up Your Cloud Environment
GCP Commands: 'G'et 'C'onfig, 'P'roject, 'C'ompute, 'S'torage. Remember the main categories!
Setting Up Your Cloud Environment
The exam frequently tests your knowledge of common gcloud commands for listing, creating, and deleting resources. Pay close attention to the hierarchical structure (e.g., 'gcloud compute instances create') and essential flags like '--project', '--zone', and '--format'. Memorize the basic commands for IAM, Compute Engine, and Cloud Storage.
Setting Up Your Cloud Environment
Forgetting to specify '--project' when working in a multi-project environment, leading to commands executing against the wrong project.
Setting Up Your Cloud Environment
Not using '--format=json' when scripting, making it difficult to parse command output programmatically.
Setting Up Your Cloud Environment
Trying to use Cloud Shell for long-running, resource-intensive tasks instead of dedicated Compute Engine instances.
Setting Up Your Cloud Environment
Google's web tool for estimating cloud service costs.
Planning Your Cloud Solution Architecture
Data leaving Google Cloud, typically incurs charges.
Planning Your Cloud Solution Architecture
Data entering Google Cloud, generally free of charge.
Planning Your Cloud Solution Architecture
Automatic discounts for running Compute Engine VMs for long periods.
Planning Your Cloud Solution Architecture
Stock Keeping Unit, a specific billable item or service.
Planning Your Cloud Solution Architecture
Process of reducing cloud spending while maintaining performance.
Planning Your Cloud Solution Architecture
To remember cost factors: C-S-N. Compute, Storage, Network. These are the big three!
Planning Your Cloud Solution Architecture
The exam often tests your understanding of which factors contribute to costs for common services like Compute Engine (machine type, vCPUs, memory, uptime) and Cloud Storage (storage class, data stored, network egress). Be aware that ingress is generally free, and egress is usually charged.
Planning Your Cloud Solution Architecture
Forgetting to account for network egress costs, especially for applications with high outbound data traffic.
Planning Your Cloud Solution Architecture
Not considering the different pricing tiers or storage classes (e.g., Standard vs. Coldline) which can significantly impact costs.
Planning Your Cloud Solution Architecture
Assuming the calculator provides exact final costs instead of estimates, which can vary based on actual usage or specific contracts.
Planning Your Cloud Solution Architecture
A virtualized computer instance with its own OS and resources.
Planning Your Cloud Solution Architecture
Google Cloud service for running virtual machines.
Planning Your Cloud Solution Architecture
A lightweight, portable package of an application and its dependencies.
Planning Your Cloud Solution Architecture
Open-source system for automating deployment, scaling, and management of containerized applications.
Planning Your Cloud Solution Architecture
Managed Kubernetes service on Google Cloud.
Planning Your Cloud Solution Architecture
A cloud execution model where the cloud provider dynamically manages server allocation.
Planning Your Cloud Solution Architecture
Google Cloud's event-driven serverless compute platform for functions.
Planning Your Cloud Solution Architecture
Google Cloud's serverless platform for running stateless containers.
Planning Your Cloud Solution Architecture
Remember 'VCS': VMs are for Control, Containers for Consistency, Serverless for Simplicity. Each has its sweet spot!
Planning Your Cloud Solution Architecture
The exam often tests your ability to choose the 'best' compute option for a given scenario. Look for keywords like 'full control', 'lift and shift' (VMs/Compute Engine), 'containerized', 'orchestration', 'microservices' (GKE), 'stateless', 'event-driven', 'pay-per-use', 'no server management' (Cloud Functions/Cloud Run).
Planning Your Cloud Solution Architecture
Choosing VMs for highly scalable, event-driven workloads, leading to over-provisioning and higher costs.
Planning Your Cloud Solution Architecture
Trying to run stateful, complex applications directly on Cloud Functions, which are designed for single-purpose, stateless functions.
Planning Your Cloud Solution Architecture
Underestimating the management overhead of GKE without prior Kubernetes experience, when Cloud Run might be simpler for stateless containers.
Planning Your Cloud Solution Architecture
Stores data as objects; highly scalable, durable, unstructured data.
Planning Your Cloud Solution Architecture
Raw storage volumes for VMs; low-latency, high-performance.
Planning Your Cloud Solution Architecture
Shared file system (NFS); multiple instances access data.
Planning Your Cloud Solution Architecture
Google's object storage service; global, scalable, various classes.
Planning Your Cloud Solution Architecture
Managed NFS file service; shared access for VMs/GKE.
Planning Your Cloud Solution Architecture
Tiers in GCS (Standard, Nearline, Coldline, Archive) for cost/access.
Planning Your Cloud Solution Architecture
Input/Output Operations Per Second; measure of disk performance.
Planning Your Cloud Solution Architecture
O-B-F: Objects for Big Files (Cloud Storage), Blocks for Booting (Persistent Disk), Files for Friends (Filestore shared access).
Planning Your Cloud Solution Architecture
The exam frequently presents scenarios asking you to choose the best storage option. Pay close attention to keywords like 'unstructured data,' 'global access,' 'cost-effective archiving' (Cloud Storage); 'VM boot disk,' 'database,' 'low-latency' (Persistent Disk); and 'shared file system,' 'NFS,' 'GKE' (Filestore). Remember the different GCS storage classes and their access patterns/costs.
Planning Your Cloud Solution Architecture
Using Persistent Disk for highly unstructured, globally distributed data when Cloud Storage would be more cost-effective and scalable.
Planning Your Cloud Solution Architecture
Trying to use Cloud Storage as a shared file system for multiple VMs, which it is not designed for.
Planning Your Cloud Solution Architecture
Ignoring storage classes in Cloud Storage, leading to higher costs for infrequently accessed data.
Planning Your Cloud Solution Architecture
A global, software-defined network for Google Cloud resources.
Planning Your Cloud Solution Architecture
A regional IP address range within a VPC network.
Planning Your Cloud Solution Architecture
Controls ingress and egress traffic to/from network resources.
Planning Your Cloud Solution Architecture
Used for communication between resources within the same or peered VPC.
Planning Your Cloud Solution Architecture
Allows resources to communicate with the internet.
Planning Your Cloud Solution Architecture
Connects resources from multiple projects to a common VPC network.
Planning Your Cloud Solution Architecture
Creates security perimeters to prevent data exfiltration.
Planning Your Cloud Solution Architecture
Think of a VPC as your entire 'Virtual Private City' (global). Inside, you have 'Sub-neighborhoods' (subnets, regional) with specific address ranges. 'Firewall Fighters' (firewall rules) protect the city's entrances and exits.
Planning Your Cloud Solution Architecture
The exam often asks about the scope of VPCs (global) versus subnets (regional). Remember that firewall rules are applied at the VPC level and are stateful. Know the default behavior for firewall rules (deny all ingress, allow all egress unless otherwise specified).
Planning Your Cloud Solution Architecture
Forgetting that VPCs are global but subnets are regional, leading to incorrect resource placement.
Planning Your Cloud Solution Architecture
Creating overly permissive firewall rules (e.g., allowing all traffic from 0.0.0.0/0) which compromises security.
Planning Your Cloud Solution Architecture
Not understanding the priority of firewall rules, causing unexpected traffic blocking or allowing.
Planning Your Cloud Solution Architecture
A resource defining VM configuration for creating identical instances.
Deploying Your Cloud Solutions
A collection of identical VMs managed as a single entity for scalability and resilience.
Deploying Your Cloud Solutions
Automatic replacement of unhealthy instances in a MIG based on health checks.
Deploying Your Cloud Solutions
Dynamically adjusting the number of instances in a MIG based on demand.
Deploying Your Cloud Solutions
A MIG distributing instances across multiple zones within a region for high availability.
Deploying Your Cloud Solutions
A mechanism to monitor the health and responsiveness of application instances.
Deploying Your Cloud Solutions
A script executed when a VM instance starts, used for initial setup.
Deploying Your Cloud Solutions
MIGs: My Instances Grow (autoscaling) and Get Healthy (autohealing)!
Deploying Your Cloud Solutions
The exam frequently tests your understanding of MIGs, especially autohealing and autoscaling. Pay attention to scenarios where high availability, fault tolerance, and cost optimization are key. Keywords like 'unpredictable traffic,' 'resilience,' or 'no downtime' often point to MIGs.
Deploying Your Cloud Solutions
Forgetting to configure health checks for MIGs, leading to unhealthy instances not being replaced.
Deploying Your Cloud Solutions
Not using instance templates, resulting in inconsistent VM configurations and manual errors.
Deploying Your Cloud Solutions
Choosing a Zonal MIG when a Regional MIG is needed for higher availability across multiple zones.
Deploying Your Cloud Solutions
A fundamental container in Cloud Storage that holds data objects.
Deploying Your Cloud Solutions
A database that stores data in tables with predefined schemas and relationships.
Deploying Your Cloud Solutions
A non-relational database offering flexible schemas and high scalability for varied data.
Deploying Your Cloud Solutions
Atomicity, Consistency, Isolation, Durability; guarantees for reliable database transactions.
Deploying Your Cloud Solutions
A system for storing and analyzing large amounts of historical data for business intelligence.
Deploying Your Cloud Solutions
To remember the database types: 'SQL Spanner, Fire Big Tables, Big Query.' SQL for relational, Spanner for global relational, Fire for Firestore (documents), Big Tables for Bigtable (wide-column), and Big Query for data warehousing.
Deploying Your Cloud Solutions
Memorize the primary use cases for Cloud Storage (unstructured, objects), Cloud SQL (managed relational), Cloud Spanner (globally scaled relational), Firestore (mobile/web NoSQL), Bigtable (analytical NoSQL), and BigQuery (data warehouse). The exam frequently tests your ability to match a scenario to the correct service.
Deploying Your Cloud Solutions
Using Cloud SQL for petabyte-scale analytical workloads; BigQuery or Bigtable would be more appropriate.
Deploying Your Cloud Solutions
Storing frequently accessed application configuration in Cloud Storage; a database like Firestore or Cloud SQL would provide better performance and queryability.
Deploying Your Cloud Solutions
Not implementing lifecycle management for Cloud Storage, leading to higher costs for infrequently accessed data.
Deploying Your Cloud Solutions
Connects two separate VPC networks for private communication.
Deploying Your Cloud Solutions
Distributes incoming traffic across multiple backend instances.
Deploying Your Cloud Solutions
A global, high-performance DNS service for domain name resolution.
Deploying Your Cloud Solutions
A DNS record type that maps a domain name to an IPv4 address.
Deploying Your Cloud Solutions
A DNS record type that creates an alias for another domain name.
Deploying Your Cloud Solutions
Think of a VPC as a 'Virtual Private City' with 'Subnets' as neighborhoods. 'Shared VPC' is like multiple families (projects) living in the same city. 'VPC Peering' is like two different cities building a private highway between them.
Deploying Your Cloud Solutions
The exam frequently asks about the differences between Shared VPC and VPC Network Peering, and when to use each. Remember Shared VPC is for projects within the same organization sharing a central network, while Peering connects two distinct VPCs (potentially across organizations) that remain separate.
Deploying Your Cloud Solutions
Confusing Shared VPC with VPC Network Peering; they serve different organizational and connectivity needs.
Deploying Your Cloud Solutions
Incorrectly configuring firewall rules, leading to unintended access or blocked legitimate traffic.
Deploying Your Cloud Solutions
Forgetting to update DNS records after changing an application's IP address or load balancer, causing service outages.
Deploying Your Cloud Solutions
A digital storefront for pre-configured software solutions on Google Cloud.
Deploying Your Cloud Solutions
Google Cloud's infrastructure-as-code service used for automated resource provisioning.
Deploying Your Cloud Solutions
A collection of software components that work together to form a complete application.
Deploying Your Cloud Solutions
An external company providing software or services on Cloud Marketplace.
Deploying Your Cloud Solutions
Software that comes with default settings and components already set up.
Deploying Your Cloud Solutions
Marketplace is for 'Quick Solutions' – Q for Quality, U for Unified billing, I for Integrated, C for Convenience, K for Knowledgeable support.
Deploying Your Cloud Solutions
For the exam, remember that Cloud Marketplace deployments often use Deployment Manager templates behind the scenes. Look for keywords like 'pre-configured solution,' 'quick deployment,' or 'third-party software' as indicators for Marketplace.
Deploying Your Cloud Solutions
Assuming Marketplace solutions are always free; many have associated Google Cloud infrastructure costs or vendor licensing fees.
Deploying Your Cloud Solutions
Not reviewing the underlying resources created by a Marketplace deployment, which can lead to unexpected costs or security misconfigurations.
Deploying Your Cloud Solutions
Thinking Marketplace is only for simple applications; many complex enterprise solutions are available.
Deploying Your Cloud Solutions
Managing infrastructure through code, not manual processes.
Deploying Your Cloud Solutions
Google Cloud's native service for declarative IaC.
Deploying Your Cloud Solutions
Reusable Python/Jinja2 files defining resource patterns.
Deploying Your Cloud Solutions
Specifying desired state, not steps to achieve it.
Deploying Your Cloud Solutions
Specifying step-by-step commands to achieve a state.
Deploying Your Cloud Solutions
A collection of resources managed by Deployment Manager.
Deploying Your Cloud Solutions
Imagine a 'Deployment Manager' as a movie 'Director.' You give the Director a 'Script' (your configuration and templates) describing the 'Scene' (your desired infrastructure), and the Director handles all the 'Actors' (resources) and 'Crew' (underlying APIs) to make it happen, exactly as scripted. No need to tell them how to hold the camera!
Deploying Your Cloud Solutions
The exam often tests your understanding of Deployment Manager's role in automation and consistency. Look for keywords like 'declarative configuration,' 'reproducible environments,' and 'version control for infrastructure.' Remember it's Google's native IaC tool.
Deploying Your Cloud Solutions
Confusing declarative (what you want) with imperative (how to do it). Deployment Manager is declarative.
Deploying Your Cloud Solutions
Trying to use Deployment Manager for application code deployment; it's for infrastructure.
Deploying Your Cloud Solutions
Forgetting that templates are reusable and can be parameterized, leading to repetitive configurations.
Deploying Your Cloud Solutions
A collection of disparate VM instances managed together, without autoscaling or autohealing features.
Ensuring Operational Success
A strategy to gradually replace old instances with new ones in a managed instance group.
Ensuring Operational Success
Deploying a new version to a small subset of instances first, then progressively rolling out.
Ensuring Operational Success
A point-in-time, incremental backup of a persistent disk, used for recovery or cloning.
Ensuring Operational Success
Think of MIGs as 'My Incredible Group' of VMs, always ready to 'Scale Up' or 'Scale Down' like a flexible rubber band, and 'Snap'shots are like taking a quick 'Photo' of your disk for safekeeping!
Ensuring Operational Success
The exam frequently tests your understanding of MIGs, especially their autoscaling policies (CPU utilization, HTTP load balancing, custom metrics) and update strategies (rolling, canary). Know that disk snapshots are incremental and global.
Ensuring Operational Success
Confusing unmanaged instance groups with managed instance groups and expecting autoscaling from unmanaged ones.
Ensuring Operational Success
Forgetting to configure health checks for MIGs, which can lead to unhealthy instances not being replaced.
Ensuring Operational Success
Not regularly testing snapshot restoration, leading to surprises during actual disaster recovery.
Ensuring Operational Success
Automatically saves previous versions of an object when it's overwritten or deleted.
Ensuring Operational Success
Automated rules to transition objects between storage classes or delete them based on age.
Ensuring Operational Success
A bucket-level policy that prevents objects from being deleted or overwritten for a set period.
Ensuring Operational Success
A Cloud Storage bucket that stores data redundantly across multiple zones within a single region.
Ensuring Operational Success
A Cloud Storage bucket that stores data redundantly across multiple geographically separated regions.
Ensuring Operational Success
GCS storage class for frequently accessed data, highest cost per GB, lowest access cost.
Ensuring Operational Success
GCS storage class for long-term data archiving, lowest cost per GB, highest access cost.
Ensuring Operational Success
S.N.C.A. - 'So Nifty, Cloud's Awesome!' for Standard, Nearline, Coldline, Archive. Remember it for cost and access frequency.
Ensuring Operational Success
The exam often asks about the appropriate storage class for different access patterns and cost requirements. Remember the hierarchy: Standard (frequent access, higher cost), Nearline (monthly access), Coldline (quarterly access), Archive (yearly/rare access, lowest cost, highest retrieval cost). Also, know that Object Versioning protects against accidental deletion, while Retention Policies enforce immutability for compliance.
Ensuring Operational Success
Forgetting that GCS is highly durable by default, but versioning and retention policies add extra layers of protection against user error or compliance issues.
Ensuring Operational Success
Confusing the purpose of Object Versioning (rollback) with Retention Policies (immutability/compliance).
Ensuring Operational Success
Not understanding that multi-regional buckets provide automatic cross-region replication for disaster recovery, unlike regional buckets.
Ensuring Operational Success
A suite of tools for monitoring and diagnosing Google Cloud network health.
Ensuring Operational Success
Identifies network misconfigurations and provides actionable insights.
Ensuring Operational Success
Simulates packet paths to verify network reachability between endpoints.
Ensuring Operational Success
Records samples of network traffic flows to and from VM instances.
Ensuring Operational Success
Visualizes latency and call paths across distributed systems.
Ensuring Operational Success
A centralized service for collecting and storing logs from Google Cloud resources.
Ensuring Operational Success
NIC-e Network Insights: Network Intelligence Center helps you get NIC-e insights into your network. Analyzer ANALYZES, Tests TESTS.
Ensuring Operational Success
The exam frequently tests your knowledge of Network Intelligence Center, specifically Network Analyzer and Connectivity Tests. Memorize their primary functions and when to use each.
Ensuring Operational Success
Forgetting to enable VPC Flow Logs when troubleshooting network issues, missing critical traffic data.
Ensuring Operational Success
Not utilizing Network Intelligence Center's automated insights, leading to manual and time-consuming diagnostics.
Ensuring Operational Success
Confusing the purpose of Network Analyzer (diagnosing misconfigurations) with Connectivity Tests (verifying reachability).
Ensuring Operational Success
Service for collecting, visualizing, and alerting on metrics.
Ensuring Operational Success
Numerical data points recorded over time, like CPU usage.
Ensuring Operational Success
Records of events, crucial for debugging and auditing.
Ensuring Operational Success
Defines conditions for notifications based on metrics or logs.
Ensuring Operational Success
Metrics derived from log entries, e.g., error counts.
Ensuring Operational Success
Routes log entries to destinations like Cloud Storage or BigQuery.
Ensuring Operational Success
To remember the difference: **M**onitoring is for **M**etrics, **L**ogging is for **L**ogs. M&M's and L&L Hawaiian BBQ!
Ensuring Operational Success
The exam frequently tests your ability to choose the correct Google Cloud service for monitoring vs. logging. Remember: Monitoring is for 'what's happening now' (metrics, health), and Logging is for 'what happened' (events, details). Pay attention to keywords like 'performance trends' (Monitoring) versus 'troubleshooting errors' (Logging).
Ensuring Operational Success
Confusing Cloud Monitoring with Cloud Logging: Monitoring is about performance metrics and health, Logging is about event records and debugging details.
Ensuring Operational Success
Not configuring alerts: Relying only on dashboards means you'll only know about problems when you're actively looking.
Ensuring Operational Success
Ignoring log sinks: Not exporting logs can lead to data loss or inability to perform long-term analysis and compliance checks.
Ensuring Operational Success
An identity (user, service account, group) that can be granted access.
Configuring Access and Security
A collection of permissions that can be granted to a member.
Configuring Access and Security
A specific authorization to perform an action on a resource.
Configuring Access and Security
A collection of role bindings attached to a resource.
Configuring Access and Security
Broad roles (Owner, Editor, Viewer) applying to all resources in a project.
Configuring Access and Security
Specific roles for a particular Google Cloud service or resource.
Configuring Access and Security
A user-defined role with a specific set of permissions.
Configuring Access and Security
Remember 'M-R-P' for Members, Roles, Permissions – the building blocks of IAM. Then add 'R' for Resources and 'P' for Policy to complete the picture!
Configuring Access and Security
The exam frequently tests your understanding of the IAM hierarchy and how policies are inherited. Pay close attention to the difference between primitive, predefined, and custom roles, and when to use each. Keywords like 'least privilege' and 'resource hierarchy' are important.
Configuring Access and Security
Granting primitive roles (Owner, Editor) instead of more specific predefined roles, leading to over-permissioning.
Configuring Access and Security
Not understanding the IAM hierarchy, resulting in unintended access or lack of access due to policy inheritance.
Configuring Access and Security
Forgetting to use Google Groups for managing permissions for teams, making administration cumbersome.
Configuring Access and Security
A JSON/P12 file for service account authentication, managed by you.
Configuring Access and Security
A service account key automatically managed and rotated by Google.
Configuring Access and Security
Granting only the minimum permissions required for a task.
Configuring Access and Security
A collection of permissions granted to a principal.
Configuring Access and Security
An identity that can be granted access to a resource (user, group, service account).
Configuring Access and Security
The process of regularly replacing cryptographic keys with new ones.
Configuring Access and Security
S.A.F.E. Keys: Service Accounts For Everything. Always use Least privilege. For External apps, manage keys carefully. For internal GCP, use Google-managed keys.
Configuring Access and Security
The exam often tests the difference between user accounts and service accounts, and when to use each. Pay attention to scenarios involving automation or applications needing GCP access. Also, know the security implications of user-managed keys versus Google-managed keys.
Configuring Access and Security
Granting service accounts overly broad permissions (e.g., 'Editor' role instead of specific roles).
Configuring Access and Security
Hardcoding user-managed service account keys directly into application code or committing them to public repositories.
Configuring Access and Security
Not rotating user-managed service account keys regularly, increasing the risk of compromise.
Configuring Access and Security
Standardized IAM roles managed by Google Cloud for common functions.
Configuring Access and Security
User-defined IAM roles with specific, granular permissions.
Configuring Access and Security
The organizational structure of Google Cloud resources (Org > Folders > Projects).
Configuring Access and Security
Permissions set at higher levels apply to resources below them.
Configuring Access and Security
Records of administrative and data access activities in Google Cloud.
Configuring Access and Security
L.A.S.T. P.A.I.R. - Least privilege, Audit, Service accounts, Three (resource hierarchy), Predefined roles, Always review, Inheritance, Role types.
Configuring Access and Security
The exam frequently tests your understanding of the principle of least privilege and when to use predefined roles versus custom roles. Pay attention to questions asking about the most secure or recommended approach for granting permissions.
Configuring Access and Security
Granting the 'Owner' or 'Editor' role unnecessarily, leading to over-privileged accounts.
Configuring Access and Security
Using default service accounts with broad permissions for production applications.
Configuring Access and Security
Creating too many custom roles when predefined roles would suffice, complicating management.
Configuring Access and Security
Records actions modifying resource configuration.
Configuring Access and Security
Records operations on user-provided data and metadata reads.
Configuring Access and Security
Records Google Cloud administrative actions affecting resources.
Configuring Access and Security
Records when access is denied due to an IAM policy.
Configuring Access and Security
Interface in Cloud Logging to view and filter logs.
Configuring Access and Security
Mechanism to export logs to other destinations.
Configuring Access and Security
Remember 'ADS' for Admin, Data, System logs. 'A' and 'S' are long (400 days), 'D' is short (30 days).
Configuring Access and Security
Memorize the three main Cloud Audit Log types (Admin Activity, Data Access, System Event) and their default retention periods. The exam often asks about which log type records specific actions or how long logs are kept.
Configuring Access and Security
Forgetting to enable Data Access logs for specific services, leading to a lack of visibility into data operations.
Configuring Access and Security
Not understanding the difference between Admin Activity and Data Access logs, which can lead to incorrect filtering or analysis.
Configuring Access and Security
Failing to set up log sinks for long-term retention or compliance, resulting in logs being deleted after their default retention period.
Configuring Access and Security