StudyToCert

All certifications / Associate Cloud Engineer / Cheat sheet

Associate Cloud Engineer Associate Cloud Engineer cheat sheet

Every exam tip and key term from the free Associate Cloud Engineer lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Setting up a cloud solution environment (23%)

Exam tips

Key terms

Organization node
The root of the hierarchy, tied to a Cloud Identity or Google Workspace domain.
Folder
A grouping of projects and other folders that lets you apply IAM and organization policies to all of them.
Project
The container that every resource belongs to, with its own APIs, quotas, IAM policy and billing link.
Policy inheritance
IAM and organization policies set on a node apply to every folder, project and resource beneath it.
Project ID
The permanent, globally unique identifier you choose at creation and use in commands and APIs.
Project number
A permanent numeric identifier Google assigns, used in some service account names.
Project name
A changeable display label that doesn't need to be unique.
Service agent
A Google-managed service account that a Google Cloud service uses to act on resources in your project.
Constraint
A definition of a restriction on a Google Cloud service's behavior, such as allowed locations.
Organization Policy Administrator
The role that lets someone set organization policies; it is granted at the organization level.
Resource locations constraint
gcp.resourceLocations, which limits where location-based resources can be created.
Domain restricted sharing
A constraint that allows IAM grants only to identities from listed Cloud Identity or Workspace customers.
Cloud Identity
Google's identity-as-a-service product for managing users, groups and devices for a domain, available in a free edition.
Google Cloud Directory Sync
A tool that one-way syncs users and groups from Active Directory or LDAP into Cloud Identity or Google Workspace.
SAML single sign-on
Federation that lets users sign in to Google with their existing identity provider's credentials.
Google group
A collection of identities with its own email address that can be granted IAM roles.
Principal
An identity that can be granted access: a user, group, service account, domain or special identifier.
Role binding
The pairing of a role with one or more principals in an allow policy.
Allow policy
The set of role bindings attached to a resource, also called an IAM policy.
add-iam-policy-binding
The gcloud subcommand that adds one member-role binding to a resource's policy.
Cloud Billing account
The account that pays for usage in the projects linked to it.
Billing Account User
A role that allows linking projects to a billing account without managing it.
Billing Account Administrator
A role that manages a billing account's payment settings, users and links.
Project Billing Manager
A project-level role that allows attaching or detaching the project's billing.
Budget
An amount and set of threshold rules that trigger alerts as actual or forecasted spend grows.
Threshold rule
A percentage of the budget that sends a notification when crossed.
Billing export
A continuous feed of detailed Cloud Billing data into a BigQuery dataset.
Forecasted spend
Google's estimate of what the month's total will be, which budgets can alert on.
gcloud init
An interactive command that authorizes an account and sets up a configuration with defaults.
Named configuration
A saved set of gcloud properties, such as account, project, region and zone, that you can switch between.
Application Default Credentials
Credentials that client libraries find automatically; set locally with gcloud auth application-default login.
gcloud config set
The command to set a property, such as compute/zone, in the active configuration.
Cloud Shell
A free, preauthenticated browser terminal on a temporary VM with Google Cloud tools preinstalled.
Cloud Shell Editor
A browser-based code editor built on Code OSS that works on the Cloud Shell home directory.
Persistent home directory
Cloud Shell storage that survives between sessions, unlike the rest of the VM.
Web preview
A Cloud Shell feature that opens a web server running in the session on a chosen port.
Allocation quota
A limit on how much of a resource a project can hold, such as regional CPUs.
Rate quota
A limit on how many API requests can be made in a time period.
System limit
A fixed maximum that can't be increased by request.
Quota increase request
A request made from the Quotas page to raise a limit, sometimes approved automatically.
Region
An independent geographic area, such as us-central1, made up of zones.
Zone
An isolated deployment area within a region, such as us-central1-a.
Label
A key-value pair on a resource used to organize, filter and report costs.
Network tag
A string on a VM used to apply firewall rules and routes to it.

Domain 2: Planning and implementing a cloud solution (30%)

Exam tips

Key terms

Compute Engine
Google Cloud's IaaS virtual machines, where you manage the operating system.
GKE
Google Kubernetes Engine, a managed Kubernetes service for running containers.
Cloud Run
A serverless platform that runs stateless containers and scales automatically, including to zero.
Cloud Run functions
Event-driven or HTTP-triggered functions deployed as source code, formerly Cloud Functions.
Machine family
A group of machine types optimized for a workload class, such as general-purpose or memory-optimized.
Custom machine type
A VM shape where you choose the number of vCPUs and amount of memory.
Image family
A name that always resolves to the newest image in a series, such as debian-12.
Spot VM
A discounted VM that Google can preempt at any time when it needs the capacity.
Persistent Disk
Durable network-attached block storage for VMs, in standard, balanced, SSD and extreme types.
Hyperdisk
Network block storage where capacity and performance are provisioned separately.
Regional persistent disk
A disk replicated synchronously across two zones in one region.
Local SSD
High-performance storage physically attached to the host, whose data doesn't persist when the VM stops.
Instance template
An immutable definition of VM properties used to create VMs in a managed instance group.
Managed instance group
A group of identical VMs created from a template that supports autoscaling, autohealing and rolling updates.
Autohealing
Recreating VMs that fail an application health check.
Rolling update
Gradually replacing a group's VMs with ones from a new template, governed by maxSurge and maxUnavailable.
Autopilot
A GKE mode where Google manages nodes and billing is based mainly on pod resource requests.
Standard cluster
A GKE mode where you configure and pay for node pools.
Regional cluster
A cluster with control plane replicas and nodes spread across multiple zones in a region.
Node pool
A group of nodes in a cluster that share the same configuration.
Deployment
A Kubernetes object that keeps a set number of identical pod replicas running and handles rolling updates.
Service
A stable IP and DNS name that load-balances traffic to a set of pods.
LoadBalancer Service
A Service type that provisions a Google Cloud network load balancer with an external or internal IP.
Ingress
A Kubernetes object that routes HTTP(S) traffic by host and path; on GKE it creates an Application Load Balancer.
Revision
An immutable snapshot of a Cloud Run service's image and configuration created on each deployment.
Concurrency
The maximum number of requests one Cloud Run instance handles at the same time.
Eventarc
A service that routes events from Google Cloud sources to Cloud Run services and functions.
Pub/Sub
A managed messaging service where publishers send messages to topics and subscribers receive them through subscriptions.
Cloud SQL
Managed MySQL, PostgreSQL and SQL Server for regional relational workloads.
Spanner
A horizontally scalable, strongly consistent relational database that can span regions.
Bigtable
A wide-column NoSQL database for massive, low-latency key-based workloads such as time series.
BigQuery
A serverless data warehouse for SQL analytics at very large scale.
Storage class
The Standard, Nearline, Coldline or Archive setting that sets storage price, access cost and minimum duration.
Lifecycle rule
An automatic action, such as changing class or deleting, applied when an object meets conditions.
Object Versioning
A bucket setting that keeps noncurrent versions of overwritten or deleted objects.
Retention policy
A minimum time objects must be kept before they can be deleted or replaced, lockable with Bucket Lock.
Custom mode VPC
A VPC where you create subnets and choose their ranges yourself.
Firewall rule priority
A number from 0 to 65535 where the lowest-numbered matching rule takes effect.
Shared VPC
A model where service projects use subnets from a centrally managed host project's VPC.
VPC Network Peering
A private, non-transitive connection between two VPC networks that exchanges subnet routes.
Application Load Balancer
A layer 7 proxy load balancer for HTTP(S) with URL-based routing.
Passthrough Network Load Balancer
A layer 4 load balancer that forwards packets and preserves client IP addresses.
Cloud NAT
Managed network address translation that gives private resources outbound internet access.
HA VPN
Highly available IPsec VPN to Google Cloud using two interfaces and BGP through Cloud Router.
Infrastructure as code
Managing infrastructure through versioned, declarative configuration files.
terraform plan
Shows the changes Terraform would make without applying them.
Terraform state
A file that records which real resources correspond to the configuration.
Cloud Marketplace
A catalog of ready-to-deploy solutions from Google and partners.

Domain 3: Ensuring successful operation of a cloud solution (27%)

Exam tips

Key terms

OS Login
A feature that ties Linux accounts on VMs to Google identities and controls SSH access with IAM roles.
IAP TCP forwarding
Tunneling SSH, RDP or other TCP traffic through Identity-Aware Proxy to VMs without external IPs.
35.235.240.0/20
The source range IAP TCP forwarding uses, which firewall rules must allow.
Serial console
Interactive access to a VM's serial port for troubleshooting when normal login fails.
Snapshot
An incremental, point-in-time backup of one disk that can be restored to a new disk.
Snapshot schedule
A resource policy that creates and deletes disk snapshots automatically on a schedule.
Custom image
A boot disk template made from your own disk, used to create identical VMs.
Machine image
A capture of a whole VM, including its configuration and all its disks.
Horizontal Pod Autoscaler
Kubernetes object that changes a workload's number of pod replicas based on metrics.
Cluster autoscaler
GKE feature that adds or removes nodes in a node pool based on pending pods and utilization.
kubectl rollout undo
Reverts a Deployment to its previous revision.
Release channel
A GKE setting that controls how quickly a cluster receives new Kubernetes versions.
Revision
An immutable version of a Cloud Run service created by each deployment.
Traffic split
Percentages of requests sent to different revisions of one service.
Minimum instances
A setting that keeps instances warm to reduce cold starts, billed while idle.
Cold start
The delay when Cloud Run starts a new container instance to handle a request.
gcloud storage
The current gcloud command group for managing buckets and objects.
gcloud storage rsync
A command that makes a bucket prefix match a local directory or another location.
Storage Transfer Service
A managed service for copying data into Cloud Storage from other clouds, URLs, buckets or on-premises.
Transfer Appliance
A physical device shipped by Google for offline transfer of very large datasets.
Point-in-time recovery
Restoring a database to a specific moment using backups plus transaction logs.
Cloud SQL high availability
A primary and a standby in different zones of a region with automatic failover.
Read replica
An asynchronously updated copy that serves read-only traffic and can be promoted manually.
Dry run
A BigQuery query validation that reports bytes to be processed without running or charging.
expand-ip-range
The gcloud subcommand that enlarges a subnet's primary range in place.
Static external IP
A reserved public address that stays with your project until released.
Private DNS zone
A Cloud DNS zone visible only to authorized VPC networks.
Internal DNS
Automatic names that let VMs in a network reach each other by name.
Ops Agent
Google's agent that collects guest OS metrics, such as memory and disk usage, and logs from VMs.
Alerting policy
Conditions plus notification channels that open incidents when a metric or log condition is met.
Uptime check
A probe of a URL, IP or resource from multiple global locations to test availability.
Metrics scope
The set of projects whose metrics a scoping project can view together.
Logs Explorer
The console tool for querying and viewing log entries.
Log-based metric
A Cloud Monitoring metric derived from log entries that match a filter.
Sink
A Log Router rule that sends matching log entries to a destination such as BigQuery or Pub/Sub.
Aggregated sink
A sink on an organization or folder that routes logs from all child projects.
Admin Activity audit logs
Always-on logs of API calls that change resource configuration or metadata.
Data Access audit logs
Logs of reads of configuration and reads or writes of user data, off by default for most services.
System Event audit logs
Logs of actions taken by Google systems, such as live migration.
Private Logs Viewer
The role needed to view Data Access audit logs.
Error Reporting
A service that groups and counts application exceptions from logs and alerts on new ones.
Cloud Trace
A distributed tracing service that shows request latency broken into spans.
Cloud Profiler
A low-overhead continuous profiler that shows CPU and memory use by function.
Span
One timed operation within a trace, such as a call to another service.

Domain 4: Configuring access and security (20%)

Exam tips

Key terms

Basic roles
The broad Owner, Editor and Viewer roles that apply across nearly all services.
Predefined role
A Google-maintained role for a specific service and job, such as Storage Object Viewer.
Custom role
A role you define with an exact list of permissions, at the organization or project level.
Least privilege
Granting only the permissions needed, at the narrowest scope.
Binding
One role and the list of members that hold it in an allow policy.
etag
A version marker that prevents overwriting a policy someone else changed.
set-iam-policy
A command that replaces a resource's entire allow policy with a file's contents.
IAM Condition
A CEL expression that makes a role binding apply only in certain cases, such as before a date.
Service account
An identity for applications and workloads, identified by an email address.
Service Account User
A role that allows attaching or acting as a service account.
Metadata server
An endpoint on each VM that provides short-lived tokens for the attached service account.
Compute Engine default service account
An automatically created service account that VMs use unless another is specified.
Service account key
A long-lived private key that lets anyone holding it authenticate as the service account.
Impersonation
Using your own identity to obtain short-lived credentials for a service account.
Service Account Token Creator
The role that allows generating short-lived credentials for a service account.
Short-lived credentials
Access or ID tokens that expire quickly, typically after about an hour.
Workload Identity Federation for GKE
A GKE feature that gives each Kubernetes service account its own IAM identity and short-lived credentials.
Workload identity pool
A container for external identities that Google Cloud trusts.
Workload identity pool provider
The configuration that trusts a specific external identity provider, such as GitHub's OIDC issuer.
Security Token Service
The Google service that exchanges external tokens for short-lived federated tokens.
Identity-Aware Proxy
A service that authorizes each request based on user identity and context before it reaches an app or VM.
IAP-secured Web App User
The role that allows a user through IAP to a protected web app.
IAP-secured Tunnel User
The role that allows TCP forwarding through IAP to VMs.
Compute OS Admin Login
The OS Login role that grants login with sudo privileges.
Default encryption
Automatic encryption at rest of all data with Google-managed keys.
CMEK
Customer-managed encryption keys in Cloud KMS that you control and Google services use.
CSEK
Customer-supplied encryption keys that you provide with each request and Google doesn't store.
Key ring
A grouping of Cloud KMS keys in one location.
Secret
A named container in Secret Manager that holds versions of a sensitive value.
Secret version
An immutable value of a secret; new versions are added to rotate.
Secret Manager Secret Accessor
The IAM role that allows reading a secret's value.
Replication policy
Whether a secret's data is replicated automatically or only to regions you choose.
Uniform bucket-level access
A bucket setting that disables ACLs so only IAM controls access.
Public access prevention
A setting or organization policy that blocks access grants to allUsers and allAuthenticatedUsers.
Signed URL
A URL that grants time-limited access to an object without requiring a Google identity.
allUsers
A special principal meaning anyone on the internet.
Policy Troubleshooter
A tool that explains whether a principal has a permission on a resource and why.
Policy Analyzer
A tool that finds which principals have which access across the hierarchy.
IAM recommender
An Active Assist feature that suggests removing or reducing roles based on permission usage.
Security Reviewer
A read-only role for listing resources and viewing IAM policies.
Study Associate Cloud Engineer for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Associate Cloud Engineer study plan