Professional Cloud Architect flashcards
137 free flashcards. Tap a card to flip it.
Dataflow for Batch Analytics
Flip cardGoogle Cloud Dataflow is a fully managed, serverless service for executing Apache Beam pipelines, suitable for large-scale batch and stream data processing.
- Serverless and autoscaling
- Unified model for batch and streaming (Apache Beam)
- Cost-effective for intermittent, large-scale jobs
Memory trick: Dataflow flows through your big data, serverlessly.
Compute Engine Confidential VMs
Flip cardConfidential VMs are a type of Compute Engine virtual machine that uses AMD Secure Encrypted Virtualization (SEV) to encrypt data *in-use* (in memory and CPU registers) with hardware-backed keys. This provides a strong isolation boundary, protecting data from unauthorized access even by cloud providers or other tenants.
- Encrypts data while it's being processed (in-use encryption)
- Uses hardware-backed keys (AMD SEV)
- Provides strong workload isolation and verifiable runtime integrity
- Protects against supply chain attacks and insider threats
Memory trick: Confidential VMs keep secrets even while they're thinking.
Cloud Firestore
Flip cardA flexible, scalable NoSQL document database for mobile, web, and server development, offering real-time data synchronization and offline support.
- NoSQL document model, flexible schema.
- Real-time data synchronization.
- Massive scalability for concurrent users.
- Low-latency access globally.
Memory trick: Firestore is for fast, flexible, real-time game worlds.
External HTTP(S) Load Balancing (Global)
Flip cardA global, application-layer (Layer 7) load balancer that distributes HTTP(S) traffic to backends across multiple regions, providing low latency and high availability.
- Uses a single global IP address.
- Directs traffic to the nearest healthy backend.
- Supports advanced traffic management features (e.g., URL maps, path-based routing).
Memory trick: External HTTP(S) makes global apps fast and stable.
DLP & Default Encryption in Transit
Flip cardGoogle Cloud's Data Loss Prevention (DLP) API identifies and de-identifies sensitive data (like PII). Google Cloud services encrypt data in transit by default using TLS/HTTPS for communication between services.
- DLP offers various de-identification techniques (redaction, tokenization, masking).
- All data moving between Google Cloud services is encrypted by default.
- External traffic to GCP services typically uses HTTPS/TLS for secure transit.
Memory trick: Data on its journey must always be locked (encrypted) and then wear a disguise (de-identified) before resting.
Google Cloud Error Reporting
Flip cardError Reporting is a Google Cloud service that aggregates and displays errors produced by your running cloud services, providing a centralized view for analysis and alerting.
- Automatically analyzes crash reports and exceptions.
- Groups similar errors, highlighting new errors and increasing error rates.
- Integrates with other Google Cloud services like Cloud Logging.
Memory trick: When serverless apps bug out, we need a 'bug reporter' to tell us what's wrong and group the similar issues.
GCP Native CI/CD for GKE
Flip cardA fully managed CI/CD pipeline on Google Cloud for GKE, leveraging Cloud Build for integration, Artifact Registry for artifacts, and Cloud Deploy for continuous delivery and release management.
- Automates build, test, and deployment processes.
- Provides traceability and roll-back capabilities.
- Integrates seamlessly with GKE and other Google Cloud services.
Memory trick: To build and ship to GKE, Cloud Build makes the box, Artifact Registry stores it, and Cloud Deploy sends it off with a tracking number.
Cloud SQL Read Replicas
Flip cardCloud SQL read replicas are copies of a primary Cloud SQL instance that handle read queries, distributing the read workload and improving the performance and availability of the primary instance.
- Supports MySQL, PostgreSQL, and SQL Server.
- Asynchronous replication from primary instance.
- Ideal for read-heavy applications to scale performance.
Memory trick: When the main book is too busy, make copies for everyone to read.
Cloud Storage Lifecycle Management
Flip cardA Google Cloud Storage feature that automates actions on objects, such as transitioning to different storage classes or deleting objects, based on predefined rules (e.g., age or version count).
- Automates cost optimization by moving data to cheaper storage.
- Enhances data governance by automating deletion.
- Rules can be based on object age, creation date, or version count.
- Applies at the bucket level.
Memory trick: Life's cycles save storage money.
Cloud Audit Logs & Monitoring
Flip cardCloud Audit Logs records administrative activities and data access events for Google Cloud resources. Cloud Monitoring allows setting up alerts based on metrics and log patterns, including those from audit logs.
- Cloud Audit Logs are immutable and retained for a specific period.
- Includes Admin Activity, Data Access, and System Event logs.
- Cloud Monitoring can trigger notifications (email, SMS, PagerDuty) based on audit log events.
Memory trick: For HIPAA, we must log every step and yell if someone steps out of line.
Data Encryption & Key Management on Google Cloud
Flip cardGoogle Cloud provides various options for encrypting data in transit and at rest, including default encryption, customer-managed encryption keys (CMEK), and customer-supplied encryption keys (CSEK).
- Data in transit is encrypted by default using TLS/SSL.
- Data at rest is encrypted by default using Google-managed encryption keys.
- CMEK provides control over encryption keys for data at rest via Cloud KMS.
- CSEK allows users to provide their own encryption keys directly to services.
Memory trick: TLS secures PHI transit, CMEK locks its rest.
Regional Data Sovereignty
Flip cardRegional data sovereignty requires that data be stored and processed within the geographic borders of a specific country or continent, often due to legal or regulatory mandates.
- Achieved by selecting specific regional locations for cloud resources.
- Critical for compliance with regulations like GDPR (Europe) and various Asian data protection laws.
- Requires careful planning of data storage and processing locations.
Memory trick: Data sovereignty means data must 'live' where its passport says it can.
Google Cloud Dataproc
Flip cardDataproc is a fully managed service for running Apache Spark, Hadoop, Presto, and other open-source data tools on Google Cloud, simplifying cluster management.
- Provides ephemeral or long-running clusters.
- Compatible with existing open-source tools and APIs.
- Offers auto-scaling and cost-effective resource management.
Memory trick: When the elephant of Hadoop needs to sparkle in the cloud, Dataproc is the shepherd.
IAM for Service-to-Service Auth
Flip cardGoogle Cloud Identity and Access Management (IAM) utilizes service accounts and roles to define and enforce fine-grained permissions for how services interact with each other, ensuring secure authentication and authorization.
- Service accounts represent non-human users (services/applications).
- IAM roles grant specific permissions to service accounts.
- Allows secure communication across projects and organizations.
Memory trick: Services shaking hands need an ID and a guest list, which is IAM's job.
Cloud Load Balancing & Autoscaling
Flip cardCloud Load Balancing distributes user traffic across multiple instances of applications, while autoscaling automatically adds or removes instances based on demand.
- Ensures high availability and fault tolerance.
- Improves application performance by preventing overload.
- Optimizes costs by scaling resources only when needed.
Memory trick: Reliability means balancing the load and scaling up, just like a cloud stretching for more tasks.
Google Cloud Filestore
Flip cardA fully managed, high-performance file storage service for Google Cloud, offering Network File System (NFS) protocol support, ideal for workloads requiring shared filesystems.
- Provides POSIX-compliant shared file systems.
- Offers different service tiers (Basic, High Scale, Enterprise) for varying performance needs.
- Suitable for HPC, GKE Persistent Volumes, media rendering, and general file sharing.
- Enterprise tier provides multi-zone availability and higher performance.
Memory trick: Files for fast, shared science.
Anthos Service Mesh (ASM)
Flip cardA managed service mesh for Google Kubernetes Engine (GKE) that simplifies the management, security, and observability of microservices.
- Provides mTLS for service-to-service authentication.
- Enables fine-grained traffic management (routing, policies).
- Offers advanced telemetry and observability for microservices.
- Based on Istio open-source project.
Memory trick: Mesh secures and controls micro-pieces.