Google Cloud Digital Leader flashcards
109 free flashcards. Tap a card to flip it.
VPC Service Controls
Flip cardVPC Service Controls helps mitigate the risk of data exfiltration from Google Cloud services by allowing you to define security perimeters around your sensitive resources.
- Creates security perimeters to isolate sensitive data and resources.
- Restricts operations to only authorized networks and identities.
- Prevents data exfiltration even if credentials are compromised.
- Protects against misconfigured IAM policies.
Memory trick: VPC Service Controls builds an unbreachable fence around your data.
Container Analysis
Flip cardContainer Analysis is a service that provides vulnerability scanning, metadata management, and policy enforcement for container images stored in Container Registry or Artifact Registry.
- Automatically scans images for known vulnerabilities.
- Integrates with CI/CD pipelines to block deployments of vulnerable images.
- Provides insights into image provenance and software bill of materials (SBOM).
Memory trick: Analyze containers to find hidden threats.
Cloud Load Balancing with Cloud Armor
Flip cardGoogle Cloud Load Balancing distributes incoming traffic across multiple instances, and when combined with Cloud Armor, it provides robust DDoS protection and Web Application Firewall (WAF) capabilities.
- Distributes traffic efficiently.
- Protects against DDoS attacks.
- WAF defends against common web exploits like SQLi and XSS.
- Scalable and integrated with other Google Cloud services.
Memory trick: Load Balancer Armor for web app shore.
Cloud Firewall
Flip cardCloud Firewall provides stateful firewall rules for your Virtual Private Cloud (VPC) network, allowing you to control traffic to and from your virtual machine (VM) instances.
- Operates at Layer 4 (TCP/UDP) and Layer 3 (IP).
- Rules can be ingress (incoming) or egress (outgoing).
- Can filter by IP range, protocol, ports, and service accounts/tags.
Memory trick: Firewalls Guard VPC Traffic Internally.
Cloud Monitoring
Flip cardCloud Monitoring collects and visualizes metrics, events, and metadata from Google Cloud services, hosted uptime probes, and application instrumentation.
- Provides dashboards and charts for data visualization.
- Enables setting up alerts based on metric thresholds.
- Integrates with various Google Cloud services for comprehensive insights.
Memory trick: Logs Trace Monitored Audits.
Cloud Logging
Flip cardCloud Logging is a fully managed service that allows you to store, search, analyze, and monitor log data from Google Cloud and external sources.
- Collects logs from all Google Cloud services automatically.
- Provides powerful querying and filtering capabilities.
- Can export logs to other services like BigQuery, Cloud Storage, or Pub/Sub for further analysis.
Memory trick: Logging Collects All Security Evidence.
Security Command Center (SCC)
Flip cardSecurity Command Center is a centralized security and risk management platform for Google Cloud that helps prevent, detect, and respond to threats.
- Aggregates security findings from Google Cloud services and third parties.
- Identifies misconfigurations, vulnerabilities, and threats.
- Provides asset inventory and compliance reporting capabilities.
- Offers a unified dashboard for security posture management.
Memory trick: SCC is the security dashboard for your entire cloud.
Google Cloud Armor
Flip cardGoogle Cloud Armor is a DDoS and WAF service that protects internet-facing applications and services from various types of attacks, offering custom rules and preconfigured policies.
- Protects against L3/L4 and L7 DDoS attacks.
- Provides WAF capabilities against common web exploits.
- Allows custom rules based on IP addresses, geographic regions, headers, and more.
- Integrates with Cloud Load Balancing.
Memory trick: Armor shields the API's gate.
Cloud Key Management Service (KMS)
Flip cardCloud KMS is a cloud-hosted key management service that lets you manage cryptographic keys for your cloud services in a single, centralized cloud service.
- Manages symmetric and asymmetric encryption keys.
- Integrates with other Google Cloud services for data encryption.
- Offers hardware security module (HSM) and external key management options.
- Supports audit logging for key usage.
Memory trick: KMS keeps your keys safe and sound.
Confidential VMs
Flip cardConfidential VMs are a Google Compute Engine offering that keeps data encrypted in memory during processing, providing enhanced isolation from the cloud provider's infrastructure.
- Encrypts VM memory with hardware-based keys.
- Protects data in use from the hypervisor and host infrastructure.
- Leverages AMD Secure Encrypted Virtualization - Encrypted State (SEV-ES).
- Maintains data confidentiality even if the host is compromised.
Memory trick: Confidential VMs keep secrets even in RAM.
Cloud Armor
Flip cardCloud Armor is a DDoS protection and Web Application Firewall (WAF) service that helps protect your Google Cloud applications and websites from various types of attacks.
- Protects against L3/L4 volumetric DDoS attacks.
- Provides WAF capabilities for L7 application-layer attacks.
- Integrates with Google Cloud Load Balancing for edge protection.
Memory trick: Armor Shields Apps from DDoS and WAF.
Kubernetes Network Policies
Flip cardSpecifications that define how groups of pods are allowed to communicate with each other and with other network endpoints.
- Operate at Layer 3 (IP) and Layer 4 (TCP/UDP).
- Apply to pods based on labels.
- Are enforced by the network plugin running in the cluster.
Memory trick: Policies Police Pod Pathways.
Google Cloud Coldline Storage
Flip cardA low-cost storage class for data accessed less than once a month, with a minimum storage duration of 90 days and a 90-second retrieval SLA.
- Optimized for data accessed less than once a month.
- 90-day minimum storage duration.
- 90-second retrieval SLA, suitable for 'immediate' access.
Memory trick: Standard is quick, Nearline is near, Coldline is cold, Archive's far.
Infrastructure as a Service (IaaS)
Flip cardA cloud computing model that provides virtualized computing resources over the internet. Users manage operating systems, applications, and data, while the provider manages the underlying infrastructure.
- High control over infrastructure components.
- Pay-as-you-go pricing.
- Scalable and flexible resources.
Memory trick: Control your cloud, or let the cloud control you!
Google Cloud Archive Storage
Flip cardThe lowest-cost storage class in Google Cloud Storage, designed for long-term digital preservation and disaster recovery, with retrieval times typically measured in hours.
- Lowest storage cost per GB
- Suitable for data accessed less than once a year
- Retrieval latency typically in hours
- Minimum storage duration of 365 days
Memory trick: Archive: Your digital time capsule, opened rarely, stored cheaply.
Virtual Private Cloud (VPC)
Flip cardA global private network in Google Cloud that provides networking functionality for your Google Cloud resources.
- Logically isolated network.
- Enables secure internal communication using private IP addresses.
- Configurable with subnets, firewall rules, and routes.
Memory trick: VPC: Your Private Cloud network.
IaaS (Infrastructure as a Service)
Flip cardA cloud computing model that provides virtualized computing resources (VMs, storage, networks) over the internet. Users manage operating systems, applications, and data.
- Highest level of control over cloud infrastructure.
- Pay-as-you-go pricing model.
- Scalable and flexible resources.
- Requires more management than PaaS or SaaS.
Memory trick: Cloud models, choose your control, and reach your goal!
Firestore
Flip cardA flexible, scalable NoSQL document database for mobile, web, and server development from Firebase and Google Cloud, offering real-time data synchronization.
- NoSQL document model (flexible schema)
- Real-time data synchronization
- Fully managed, serverless, automatic scaling
Memory trick: Firestore: Your flexible friend for mobile apps, real-time and free from ops.
Platform as a Service (PaaS)
Flip cardA cloud computing model where a third-party provider delivers hardware and software tools, usually for application development, to users over the internet.
- Developers focus on code, not infrastructure.
- Automatic scaling and maintenance.
- Reduced operational overhead.
Memory trick: Choose your compute, then your code will commute!
Dataproc
Flip cardA fully managed, highly scalable service for running Apache Spark, Apache Hadoop, Apache Flink, and other open-source data processing frameworks on Google Cloud.
- Managed service for big data processing.
- Supports Spark, Hadoop, Flink, Presto, etc.
- Scalable from small clusters to hundreds of nodes.
- Cost-effective with per-second billing.
Memory trick: Big data needs big compute, to make sense of the loot!
Cloud Bigtable
Flip cardA fully managed NoSQL wide-column database service built for large analytical and operational workloads with extremely high throughput and low latency.
- Massively scalable for petabytes of data.
- Extremely low latency reads/writes.
- Supports high throughput for millions of operations per second.
- Ideal for time-series data, operational analytics, and gaming.
Memory trick: NoSQL, no limits, just scalability!
Google Cloud Storage Archive storage
Flip cardA highly cost-effective storage class for long-term data archiving with very infrequent access (less than once a year). It is ideal for regulatory compliance, disaster recovery, and digital preservation.
- Lowest cost storage class
- High availability and durability
- Designed for access less than once a year
- Retrieval times are generally longer than other classes
Memory trick: Storage classes: 'Standard' for speed, 'Nearline' for monthly, 'Coldline' for quarterly, 'Archive' for forever.
App Engine Standard
Flip cardA fully managed, serverless platform for building and deploying scalable web applications and mobile backends. It automatically scales to meet demand and minimizes operational overhead.
- Platform as a Service (PaaS)
- Automatic scaling and load balancing
- Zero server management required
- Supports various programming languages
Memory trick: Compute options: Each has a unique 'Engine' for your 'App's' 'Functions' or 'Kubes'.
Preemptible VMs
Flip cardLow-cost Compute Engine virtual machines that can be terminated by Google Cloud if resources are needed elsewhere, making them suitable for fault-tolerant batch jobs.
- Up to 80% cheaper than standard VMs
- Maximum run time of 24 hours
- Automatically terminate if resources are scarce (preempted)
Memory trick: Preemptible VMs: cheap, powerful, but can vanish like a cloud.
Rehost (Lift and Shift)
Flip cardA cloud migration strategy where applications and data are moved from on-premises to cloud infrastructure (typically IaaS) with minimal or no changes.
- Fastest migration path.
- Minimizes code changes.
- Leverages existing operational expertise with VMs.
Memory trick: The 6 Rs: Rehost, Replatform, Refactor, Repurchase, Retire, Retain.
Pub/Sub and Dataflow
Flip cardPub/Sub is a global, real-time messaging service for ingesting data streams, and Dataflow is a fully managed service for executing Apache Beam pipelines for stream or batch data processing.
- Pub/Sub: Scalable, asynchronous messaging for event ingestion
- Dataflow: Unified programming model for batch and stream processing
- Together, they form a robust real-time data pipeline
Memory trick: Pub/Sub takes the stream, Dataflow processes the dream.
Google Compute Engine (GCE)
Flip cardGoogle Cloud's Infrastructure as a Service (IaaS) offering that provides virtual machines running on Google's global infrastructure.
- Offers granular control over VM configuration (CPU, memory, storage)
- Users manage the operating system, patching, and software
- Supports various OS images, including custom ones
Memory trick: Compute Engine: Your virtual data center, you're the boss.
Cloud Storage Archive Class
Flip cardThe lowest-cost storage class within Google Cloud Storage, optimized for long-term archiving of data that is accessed less than once a year. It has the highest retrieval costs and latency.
- Lowest storage cost per GB.
- Highest data retrieval cost and latency (minutes to hours).
- Ideal for compliance, backup, and long-term archiving.
- Data available for analysis when needed, with flexible retrieval.
Memory trick: Storage costs: Match access to save your assets!
Cloud Pub/Sub & Dataflow
Flip cardCloud Pub/Sub is a messaging service for ingesting real-time events, while Dataflow is a service for processing streaming and batch data.
- Pub/Sub provides scalable, asynchronous messaging.
- Dataflow offers unified stream and batch processing (Apache Beam).
- Commonly used together for real-time data pipelines.
Memory trick: Publish data, flow it through.
Lift and Shift (Rehost)
Flip cardA cloud migration strategy where applications and data are moved from an on-premises environment to the cloud with minimal or no changes to the application code or architecture.
- Fastest way to get to the cloud.
- Minimal code changes required.
- Benefits from cloud infrastructure (e.g., scalability, cost savings).
- May not fully optimize for cloud-native features.
Memory trick: Migrate to cloud, leave no app unmoved!
Graph Database
Flip cardA database that uses graph structures for semantic queries with nodes, edges, and properties to represent and store data.
- Optimized for traversing complex relationships
- Ideal for social networks, recommendation engines, fraud detection
- Neo4j is a popular example, available on GCP Marketplace
Memory trick: Graphs reveal hidden connections, like a web of insights.
Vertex AI Platform
Flip cardA unified machine learning platform on Google Cloud that provides all the tools needed to build, deploy, and scale ML models across the entire ML lifecycle.
- Supports custom code with open-source ML frameworks.
- Managed services for training, deployment, monitoring.
- A single platform for MLOps.
Memory trick: Vertex AI is the 'Vertex' (peak) of your ML journey.
Vertex AI Training
Flip cardA managed service on Google Cloud for training custom machine learning models at scale, using various frameworks.
- Supports custom training code and popular ML frameworks
- Manages infrastructure for distributed training
- Integrates with other Vertex AI services for end-to-end MLOps
Memory trick: To reach the Vertex of ML, you need strong Training.
BigQuery Omni
Flip cardA multi-cloud analytics solution that allows BigQuery users to analyze data stored in Google Cloud, AWS, and Azure without moving the data.
- Extends BigQuery's query engine to external data sources.
- Enables querying data in Cloud Storage directly.
- Serverless and uses standard SQL.
Memory trick: BigQuery Omni queries 'Omni' (all) your data, wherever it lives.
Vertex AI Workbench
Flip cardA fully managed, enterprise-ready development environment for machine learning, providing Jupyter notebooks integrated with Google Cloud services.
- Supports open-source ML frameworks (TensorFlow, PyTorch).
- Offers integrated tools for data exploration and experiment tracking.
- Enables collaborative development for data scientists.
Memory trick: Vertex AI Workbench is the 'workbench' for all your ML creations.
Cloud Natural Language API
Flip cardA Google Cloud service offering pre-trained machine learning models for understanding text structure and meaning, including sentiment analysis.
- Provides sentiment analysis, entity extraction, syntax analysis, and content classification
- Uses pre-trained models, no training required
- Ideal for quick insights from text data
Memory trick: Natural Language API understands the feelings in words.
Speech-to-Text API & Natural Language API
Flip cardA combination of Google Cloud APIs for converting spoken audio into text and then analyzing that text for insights.
- Speech-to-Text: Accurate transcription of audio files.
- Natural Language API: Entity extraction, sentiment analysis, syntax analysis, content classification.
- Commonly used together for processing spoken language data.
Memory trick: Speak to Text, then Natural Language understands.
Elasticsearch
Flip cardA distributed, open-source search and analytics engine known for its full-text search capabilities, scalability, and real-time data analysis.
- Provides full-text search, auto-completion, and faceted search
- Highly scalable and offers near real-time indexing
- Often used with Kibana for visualization and Logstash for data ingestion (ELK Stack)
Memory trick: Elastic search makes finding things flexible and fast.
Vertex AI Prediction
Flip cardA Google Cloud service for deploying trained machine learning models and serving real-time predictions.
- Supports various model frameworks (TensorFlow, scikit-learn, XGBoost, etc.)
- Scales automatically to handle varying prediction loads
- Provides endpoints for real-time (online) predictions
Memory trick: To get predictions, you need a Vertex to stand on.
AutoML Video Intelligence
Flip cardA Google Cloud service that enables developers to automatically train and deploy custom machine learning models for video content analysis.
- Uses your own labeled video data for training
- No deep ML expertise required
- Supports various video analysis tasks like classification, object tracking, action recognition
Memory trick: AutoML makes video analysis automatic and smart.
Recommendation AI
Flip cardA fully managed Google Cloud service for building personalized recommendation engines, leveraging Google's advanced machine learning models.
- Specialized for recommending items (products, content).
- Customizable with business-specific data.
- Offers pre-trained models and optimized algorithms.
Memory trick: AI recommends what you'll like, like a smart TV guide.
BigQuery ML
Flip cardA feature of BigQuery that allows users to create and execute machine learning models using standard SQL queries.
- Leverages existing SQL skills for ML
- No data export required, models trained directly in BigQuery
- Supports various model types like linear regression, logistic regression, k-means, ARIMA
Memory trick: Big data needs BigQuery ML for SQL-powered insights.
Cloud Data Fusion
Flip cardA fully managed, cloud-native data integration service built on open-source CDAP for building and managing ETL/ELT pipelines.
- Graphical interface for pipeline development
- Connects to a wide range of data sources and sinks
- Supports ETL (Extract, Transform, Load) and ELT (Extract, Load, Transform) patterns
Memory trick: Data Fusion brings all data pieces together.
Firestore for Mobile/Web Apps
Flip cardFirestore is a flexible, scalable NoSQL document database for mobile, web, and server development from Google Cloud. It keeps your data in sync across client apps in real-time and offers offline support.
- Real-time data synchronization across connected devices.
- Offline mode for mobile apps.
- Flexible, document-based data model.
- Automatic scaling and high availability.
Memory trick: Firestore: It's the 'Fire' of real-time updates, making your app's 'Store' of data blaze fast.
Elasticsearch for Log Analytics
Flip cardElasticsearch is a distributed, RESTful search and analytics engine capable of solving a growing number of use cases. It's commonly used for log analytics, full-text search, security intelligence, and operational monitoring.
- Provides real-time full-text search and analytical capabilities.
- Scales horizontally to handle massive data volumes.
- Ideal for semi-structured data like logs and events.
- Often deployed with Kibana for visualization (ELK stack).
Memory trick: For 'Elastic' search on 'logs', think of 'Elasticsearch' stretching to cover all your data.
Cloud Storage for Unstructured Data
Flip cardGoogle Cloud Storage is an object storage service designed for storing and accessing unstructured data, such as images, videos, and documents, at any scale.
- Offers multiple storage classes (Standard, Nearline, Coldline, Archive) to optimize cost based on access frequency.
- Provides high durability (11 nines) and availability.
- Scales automatically to petabytes and beyond.
Memory trick: Remember, Cloud Storage is like a giant digital closet for all your unstructured stuff.
Video Intelligence API
Flip cardThe Video Intelligence API is a powerful machine learning service that enables developers to analyze video content, extracting metadata about entities, sentiments, and events within the video.
- Detects objects, places, and actions within video frames and segments.
- Identifies explicit content for moderation.
- Detects scene changes and shot boundaries.
- Offers both pre-trained models and custom AutoML capabilities for video.
Memory trick: For 'Video' content, use the 'Video Intelligence' API.
Google Cloud Regions
Flip cardGoogle Cloud Regions are independent geographic areas that contain multiple Zones, designed for high availability and disaster recovery.
- Each Region is a collection of physically isolated data centers (Zones).
- Provides fault tolerance against an entire data center failure.
- Offers low-latency access to users within its geographic area.
Memory trick: Regions are like continents, holding many Zones like cities, ensuring global reach and resilience.
Google Cloud Security & Compliance
Flip cardGoogle Cloud offers a robust, multi-layered security model and adheres to numerous global and industry-specific compliance certifications (e.g., HIPAA, GDPR, ISO 27001) to protect customer data and meet regulatory requirements.
- Security built into every layer, from infrastructure to operations.
- Extensive list of compliance certifications and attestations.
- Data encryption at rest and in transit by default.
- Dedicated security teams and advanced threat detection.
Memory trick: Value: Cost, Security, Innovation, Global.