All certifications / Associate Cloud Engineer / Cheat sheet
Associate Cloud Engineer Associate Cloud Engineer cheat sheet
Domain 1: Setting up a cloud solution environment (23%)
Exam tips
- IAM allow policies are additive and can't be revoked lower in the tree. If a question says a user still has access after you removed a project-level grant, look for a grant on a folder or the organization above it.
- If a question says the team wants to change a project ID, the answer is that it can't be done; only the display name can change. An 'API not enabled' error is fixed by enabling the API, not by granting more IAM roles.
- Read the requirement: 'nobody, including owners' points to an organization policy; 'only this group may' points to IAM. Service account key creation, external IPs and allowed regions are classic organization policy questions.
- Existing AD users plus 'without re-creating them' means Google Cloud Directory Sync (often with SAML SSO). IAM doesn't create users, and service accounts are for workloads, not employees.
- Choose the lowest level that meets the requirement, grant to a group, and use a predefined role before a basic role. If the question mentions 'all projects in the department', a folder-level grant is usually the intended answer.
- 'Link projects but not change the billing account' is Billing Account User. 'View costs only' is Billing Account Viewer. 'Manage everything' is Billing Account Administrator.
- If a question expects spending to stop automatically, a budget alone is wrong; it needs Pub/Sub notifications and code. For SQL analysis of costs, the answer is billing export to BigQuery, not audit logs.
- Know the exact syntax:
gcloud config set compute/zone ZONE,gcloud config set project IDandgcloud config configurations activate NAME. Distractors often invent commands likegcloud compute zones set. - 'Can't install software locally' or 'quickest way to run gcloud and kubectl' points to Cloud Shell. Remember only the home directory persists.
- Quota errors are fixed by requesting an increase for the named metric and region (or deploying elsewhere). Re-enabling APIs, changing IAM or moving folders doesn't change quotas.
- Zone failure means spread across zones in a region; region failure means another region. For cost by application, choose labels, not network tags.
Key terms
- Organization node
- The root of the hierarchy, tied to a Cloud Identity or Google Workspace domain.
- Folder
- A grouping of projects and other folders that lets you apply IAM and organization policies to all of them.
- Project
- The container that every resource belongs to, with its own APIs, quotas, IAM policy and billing link.
- Policy inheritance
- IAM and organization policies set on a node apply to every folder, project and resource beneath it.
- Project ID
- The permanent, globally unique identifier you choose at creation and use in commands and APIs.
- Project number
- A permanent numeric identifier Google assigns, used in some service account names.
- Project name
- A changeable display label that doesn't need to be unique.
- Service agent
- A Google-managed service account that a Google Cloud service uses to act on resources in your project.
- Constraint
- A definition of a restriction on a Google Cloud service's behavior, such as allowed locations.
- Organization Policy Administrator
- The role that lets someone set organization policies; it is granted at the organization level.
- Resource locations constraint
- gcp.resourceLocations, which limits where location-based resources can be created.
- Domain restricted sharing
- A constraint that allows IAM grants only to identities from listed Cloud Identity or Workspace customers.
- Cloud Identity
- Google's identity-as-a-service product for managing users, groups and devices for a domain, available in a free edition.
- Google Cloud Directory Sync
- A tool that one-way syncs users and groups from Active Directory or LDAP into Cloud Identity or Google Workspace.
- SAML single sign-on
- Federation that lets users sign in to Google with their existing identity provider's credentials.
- Google group
- A collection of identities with its own email address that can be granted IAM roles.
- Principal
- An identity that can be granted access: a user, group, service account, domain or special identifier.
- Role binding
- The pairing of a role with one or more principals in an allow policy.
- Allow policy
- The set of role bindings attached to a resource, also called an IAM policy.
- add-iam-policy-binding
- The gcloud subcommand that adds one member-role binding to a resource's policy.
- Cloud Billing account
- The account that pays for usage in the projects linked to it.
- Billing Account User
- A role that allows linking projects to a billing account without managing it.
- Billing Account Administrator
- A role that manages a billing account's payment settings, users and links.
- Project Billing Manager
- A project-level role that allows attaching or detaching the project's billing.
- Budget
- An amount and set of threshold rules that trigger alerts as actual or forecasted spend grows.
- Threshold rule
- A percentage of the budget that sends a notification when crossed.
- Billing export
- A continuous feed of detailed Cloud Billing data into a BigQuery dataset.
- Forecasted spend
- Google's estimate of what the month's total will be, which budgets can alert on.
- gcloud init
- An interactive command that authorizes an account and sets up a configuration with defaults.
- Named configuration
- A saved set of gcloud properties, such as account, project, region and zone, that you can switch between.
- Application Default Credentials
- Credentials that client libraries find automatically; set locally with gcloud auth application-default login.
- gcloud config set
- The command to set a property, such as compute/zone, in the active configuration.
- Cloud Shell
- A free, preauthenticated browser terminal on a temporary VM with Google Cloud tools preinstalled.
- Cloud Shell Editor
- A browser-based code editor built on Code OSS that works on the Cloud Shell home directory.
- Persistent home directory
- Cloud Shell storage that survives between sessions, unlike the rest of the VM.
- Web preview
- A Cloud Shell feature that opens a web server running in the session on a chosen port.
- Allocation quota
- A limit on how much of a resource a project can hold, such as regional CPUs.
- Rate quota
- A limit on how many API requests can be made in a time period.
- System limit
- A fixed maximum that can't be increased by request.
- Quota increase request
- A request made from the Quotas page to raise a limit, sometimes approved automatically.
- Region
- An independent geographic area, such as us-central1, made up of zones.
- Zone
- An isolated deployment area within a region, such as us-central1-a.
- Label
- A key-value pair on a resource used to organize, filter and report costs.
- Network tag
- A string on a VM used to apply firewall rules and routes to it.
Domain 2: Planning and implementing a cloud solution (30%)
Exam tips
- Keywords decide it: 'kernel', 'OS control', 'license' mean Compute Engine; 'Kubernetes' or 'Helm' mean GKE; 'stateless container, scale to zero, no infrastructure' means Cloud Run; 'run code when a file is uploaded' means Cloud Run functions.
- 'Can be interrupted' plus 'lowest cost' means Spot VMs. 'Needs an unusual CPU-to-memory ratio' means a custom machine type. Spot VMs are not a fit for databases.
- Survive a zone failure without losing writes: regional disk. Fastest scratch storage and data loss is acceptable: local SSD. Cheapest bulk block storage: standard persistent disk.
- You can't edit a template: new template, then rolling update. Autohealing needs a health check. Unmanaged groups don't autoscale.
- 'Don't manage nodes' means Autopilot. 'Control plane must survive a zone outage' means a regional cluster. 'Different machine types in one cluster' means node pools.
- Internal only: ClusterIP. One external IP for one service: LoadBalancer. URL-based routing to several services: Ingress. Don't forget get-credentials before kubectl works.
- 'Run code when a file lands in a bucket' is an event-driven function via Eventarc. 'Only specific services may call it' means require authentication and grant Cloud Run Invoker to those identities.
- Relational and regional: Cloud SQL. Relational and global scale: Spanner. Time series or IoT at huge scale: Bigtable. Mobile or web documents: Firestore. Analytics with SQL: BigQuery.
- Match access frequency to the class: monthly is Nearline, quarterly is Coldline, yearly or less is Archive. Remember the 30, 90 and 365-day minimums, and that a bucket's location can't be changed later.
- Central team manages the network for many projects: Shared VPC. Connecting two separately managed VPCs: peering. Peering isn't transitive and ranges can't overlap. Lower priority numbers win.
- HTTP(S) plus global plus URL routing or CDN: global external Application Load Balancer. Private VMs needing outbound internet: Cloud NAT. Fast to set up over the internet: HA VPN. Private, high bandwidth: Interconnect.
- 'Preview changes before applying', 'version-controlled', 'reusable modules' all point to Terraform. 'Deploy a common third-party product quickly' points to Cloud Marketplace.
Key terms
- Compute Engine
- Google Cloud's IaaS virtual machines, where you manage the operating system.
- GKE
- Google Kubernetes Engine, a managed Kubernetes service for running containers.
- Cloud Run
- A serverless platform that runs stateless containers and scales automatically, including to zero.
- Cloud Run functions
- Event-driven or HTTP-triggered functions deployed as source code, formerly Cloud Functions.
- Machine family
- A group of machine types optimized for a workload class, such as general-purpose or memory-optimized.
- Custom machine type
- A VM shape where you choose the number of vCPUs and amount of memory.
- Image family
- A name that always resolves to the newest image in a series, such as debian-12.
- Spot VM
- A discounted VM that Google can preempt at any time when it needs the capacity.
- Persistent Disk
- Durable network-attached block storage for VMs, in standard, balanced, SSD and extreme types.
- Hyperdisk
- Network block storage where capacity and performance are provisioned separately.
- Regional persistent disk
- A disk replicated synchronously across two zones in one region.
- Local SSD
- High-performance storage physically attached to the host, whose data doesn't persist when the VM stops.
- Instance template
- An immutable definition of VM properties used to create VMs in a managed instance group.
- Managed instance group
- A group of identical VMs created from a template that supports autoscaling, autohealing and rolling updates.
- Autohealing
- Recreating VMs that fail an application health check.
- Rolling update
- Gradually replacing a group's VMs with ones from a new template, governed by maxSurge and maxUnavailable.
- Autopilot
- A GKE mode where Google manages nodes and billing is based mainly on pod resource requests.
- Standard cluster
- A GKE mode where you configure and pay for node pools.
- Regional cluster
- A cluster with control plane replicas and nodes spread across multiple zones in a region.
- Node pool
- A group of nodes in a cluster that share the same configuration.
- Deployment
- A Kubernetes object that keeps a set number of identical pod replicas running and handles rolling updates.
- Service
- A stable IP and DNS name that load-balances traffic to a set of pods.
- LoadBalancer Service
- A Service type that provisions a Google Cloud network load balancer with an external or internal IP.
- Ingress
- A Kubernetes object that routes HTTP(S) traffic by host and path; on GKE it creates an Application Load Balancer.
- Revision
- An immutable snapshot of a Cloud Run service's image and configuration created on each deployment.
- Concurrency
- The maximum number of requests one Cloud Run instance handles at the same time.
- Eventarc
- A service that routes events from Google Cloud sources to Cloud Run services and functions.
- Pub/Sub
- A managed messaging service where publishers send messages to topics and subscribers receive them through subscriptions.
- Cloud SQL
- Managed MySQL, PostgreSQL and SQL Server for regional relational workloads.
- Spanner
- A horizontally scalable, strongly consistent relational database that can span regions.
- Bigtable
- A wide-column NoSQL database for massive, low-latency key-based workloads such as time series.
- BigQuery
- A serverless data warehouse for SQL analytics at very large scale.
- Storage class
- The Standard, Nearline, Coldline or Archive setting that sets storage price, access cost and minimum duration.
- Lifecycle rule
- An automatic action, such as changing class or deleting, applied when an object meets conditions.
- Object Versioning
- A bucket setting that keeps noncurrent versions of overwritten or deleted objects.
- Retention policy
- A minimum time objects must be kept before they can be deleted or replaced, lockable with Bucket Lock.
- Custom mode VPC
- A VPC where you create subnets and choose their ranges yourself.
- Firewall rule priority
- A number from 0 to 65535 where the lowest-numbered matching rule takes effect.
- Shared VPC
- A model where service projects use subnets from a centrally managed host project's VPC.
- VPC Network Peering
- A private, non-transitive connection between two VPC networks that exchanges subnet routes.
- Application Load Balancer
- A layer 7 proxy load balancer for HTTP(S) with URL-based routing.
- Passthrough Network Load Balancer
- A layer 4 load balancer that forwards packets and preserves client IP addresses.
- Cloud NAT
- Managed network address translation that gives private resources outbound internet access.
- HA VPN
- Highly available IPsec VPN to Google Cloud using two interfaces and BGP through Cloud Router.
- Infrastructure as code
- Managing infrastructure through versioned, declarative configuration files.
- terraform plan
- Shows the changes Terraform would make without applying them.
- Terraform state
- A file that records which real resources correspond to the configuration.
- Cloud Marketplace
- A catalog of ready-to-deploy solutions from Google and partners.
Domain 3: Ensuring successful operation of a cloud solution (27%)
Exam tips
- No external IP and no bastion: IAP TCP forwarding with a firewall rule for 35.235.240.0/20. Access tied to IAM and removed automatically: OS Login. Changing the machine type requires stopping the VM.
- Backup of a disk: snapshot. Automatic backups without scripts: snapshot schedule. Template for many identical VMs: custom image in an image family. Whole VM with its settings: machine image.
- More pods: kubectl scale or HPA. More nodes: cluster autoscaler or resize the node pool. Bad release: kubectl rollout undo. Don't autoscale GKE's underlying instance groups directly.
- Gradual release on Cloud Run is traffic splitting between revisions of the same service. Slow first request is fixed with minimum instances; protecting a database is done with maximum instances.
- Other cloud to Cloud Storage, scheduled and managed: Storage Transfer Service. Hundreds of terabytes over a slow link: Transfer Appliance. Into BigQuery from SaaS: BigQuery Data Transfer Service.
- Automatic zone failover: HA. Offload reads: read replica. Undo a bad change: point-in-time recovery. Estimate BigQuery cost: dry run. LIMIT doesn't reduce bytes scanned.
- Subnets grow, never shrink. A changing public IP is fixed by reserving or promoting a static address. Internal-only names: private DNS zone.
- Memory and disk-space metrics need the Ops Agent. 'Notify when a metric crosses a threshold' is an alerting policy. 'Is my website reachable from around the world' is an uptime check.
- Count or chart something that appears in logs: log-based metric. Send logs somewhere else: sink (and grant its writer identity access). All projects in the organization: aggregated sink with include-children.
- Who changed or deleted something: Admin Activity (always on). Who read data: Data Access, which must be enabled first (except BigQuery). Viewing Data Access logs needs Private Logs Viewer.
- Grouped exceptions: Error Reporting. Slow requests across services: Cloud Trace. Code-level CPU or memory hot spots: Cloud Profiler.
Key terms
- OS Login
- A feature that ties Linux accounts on VMs to Google identities and controls SSH access with IAM roles.
- IAP TCP forwarding
- Tunneling SSH, RDP or other TCP traffic through Identity-Aware Proxy to VMs without external IPs.
- 35.235.240.0/20
- The source range IAP TCP forwarding uses, which firewall rules must allow.
- Serial console
- Interactive access to a VM's serial port for troubleshooting when normal login fails.
- Snapshot
- An incremental, point-in-time backup of one disk that can be restored to a new disk.
- Snapshot schedule
- A resource policy that creates and deletes disk snapshots automatically on a schedule.
- Custom image
- A boot disk template made from your own disk, used to create identical VMs.
- Machine image
- A capture of a whole VM, including its configuration and all its disks.
- Horizontal Pod Autoscaler
- Kubernetes object that changes a workload's number of pod replicas based on metrics.
- Cluster autoscaler
- GKE feature that adds or removes nodes in a node pool based on pending pods and utilization.
- kubectl rollout undo
- Reverts a Deployment to its previous revision.
- Release channel
- A GKE setting that controls how quickly a cluster receives new Kubernetes versions.
- Revision
- An immutable version of a Cloud Run service created by each deployment.
- Traffic split
- Percentages of requests sent to different revisions of one service.
- Minimum instances
- A setting that keeps instances warm to reduce cold starts, billed while idle.
- Cold start
- The delay when Cloud Run starts a new container instance to handle a request.
- gcloud storage
- The current gcloud command group for managing buckets and objects.
- gcloud storage rsync
- A command that makes a bucket prefix match a local directory or another location.
- Storage Transfer Service
- A managed service for copying data into Cloud Storage from other clouds, URLs, buckets or on-premises.
- Transfer Appliance
- A physical device shipped by Google for offline transfer of very large datasets.
- Point-in-time recovery
- Restoring a database to a specific moment using backups plus transaction logs.
- Cloud SQL high availability
- A primary and a standby in different zones of a region with automatic failover.
- Read replica
- An asynchronously updated copy that serves read-only traffic and can be promoted manually.
- Dry run
- A BigQuery query validation that reports bytes to be processed without running or charging.
- expand-ip-range
- The gcloud subcommand that enlarges a subnet's primary range in place.
- Static external IP
- A reserved public address that stays with your project until released.
- Private DNS zone
- A Cloud DNS zone visible only to authorized VPC networks.
- Internal DNS
- Automatic names that let VMs in a network reach each other by name.
- Ops Agent
- Google's agent that collects guest OS metrics, such as memory and disk usage, and logs from VMs.
- Alerting policy
- Conditions plus notification channels that open incidents when a metric or log condition is met.
- Uptime check
- A probe of a URL, IP or resource from multiple global locations to test availability.
- Metrics scope
- The set of projects whose metrics a scoping project can view together.
- Logs Explorer
- The console tool for querying and viewing log entries.
- Log-based metric
- A Cloud Monitoring metric derived from log entries that match a filter.
- Sink
- A Log Router rule that sends matching log entries to a destination such as BigQuery or Pub/Sub.
- Aggregated sink
- A sink on an organization or folder that routes logs from all child projects.
- Admin Activity audit logs
- Always-on logs of API calls that change resource configuration or metadata.
- Data Access audit logs
- Logs of reads of configuration and reads or writes of user data, off by default for most services.
- System Event audit logs
- Logs of actions taken by Google systems, such as live migration.
- Private Logs Viewer
- The role needed to view Data Access audit logs.
- Error Reporting
- A service that groups and counts application exceptions from logs and alerts on new ones.
- Cloud Trace
- A distributed tracing service that shows request latency broken into spans.
- Cloud Profiler
- A low-overhead continuous profiler that shows CPU and memory use by function.
- Span
- One timed operation within a trace, such as a call to another service.
Domain 4: Configuring access and security (20%)
Exam tips
- Prefer predefined roles; use custom roles only when no predefined role fits; avoid basic roles. Custom roles can't be created on folders and aren't updated automatically by Google.
- For one change, use add- or remove-iam-policy-binding. set-iam-policy overwrites everything. Temporary access is an IAM Condition on request.time.
- Workloads should use attached, dedicated service accounts, not keys and not the default Editor account. Permission errors when attaching a service account mean the user lacks Service Account User on it.
- 'Without creating a key' plus 'act as a service account' means Token Creator and impersonation. A leaked key must be disabled or deleted; deleting the commit isn't enough.
- Pods needing their own Google identity: Workload Identity Federation for GKE. CI/CD or other clouds without keys: Workload Identity Federation with a pool and provider. Keys in secrets are the wrong answer.
- Identity-based access to an internal web app without VPN: IAP. SSH without external IPs: IAP TCP forwarding. SSH access controlled by IAM: OS Login.
- 'Control rotation and be able to disable the key, but Google does the encryption' is CMEK. 'Google must never store the key' is CSEK. Nothing required means default encryption.
- Passwords and API keys belong in Secret Manager with Secret Accessor granted to the workload's service account. Cloud KMS is for encryption keys, not for storing app passwords.
- Only IAM, no ACLs: uniform bucket-level access. Never public, even by mistake: enforce public access prevention (org policy for everything). Temporary access for someone without an account: signed URL.
- 'Why is this user denied' is Policy Troubleshooter. 'Who can access this resource' is Policy Analyzer. 'Which roles are unused' is the IAM recommender. 'Auditor can view but not change' is Security Reviewer.
Key terms
- Basic roles
- The broad Owner, Editor and Viewer roles that apply across nearly all services.
- Predefined role
- A Google-maintained role for a specific service and job, such as Storage Object Viewer.
- Custom role
- A role you define with an exact list of permissions, at the organization or project level.
- Least privilege
- Granting only the permissions needed, at the narrowest scope.
- Binding
- One role and the list of members that hold it in an allow policy.
- etag
- A version marker that prevents overwriting a policy someone else changed.
- set-iam-policy
- A command that replaces a resource's entire allow policy with a file's contents.
- IAM Condition
- A CEL expression that makes a role binding apply only in certain cases, such as before a date.
- Service account
- An identity for applications and workloads, identified by an email address.
- Service Account User
- A role that allows attaching or acting as a service account.
- Metadata server
- An endpoint on each VM that provides short-lived tokens for the attached service account.
- Compute Engine default service account
- An automatically created service account that VMs use unless another is specified.
- Service account key
- A long-lived private key that lets anyone holding it authenticate as the service account.
- Impersonation
- Using your own identity to obtain short-lived credentials for a service account.
- Service Account Token Creator
- The role that allows generating short-lived credentials for a service account.
- Short-lived credentials
- Access or ID tokens that expire quickly, typically after about an hour.
- Workload Identity Federation for GKE
- A GKE feature that gives each Kubernetes service account its own IAM identity and short-lived credentials.
- Workload identity pool
- A container for external identities that Google Cloud trusts.
- Workload identity pool provider
- The configuration that trusts a specific external identity provider, such as GitHub's OIDC issuer.
- Security Token Service
- The Google service that exchanges external tokens for short-lived federated tokens.
- Identity-Aware Proxy
- A service that authorizes each request based on user identity and context before it reaches an app or VM.
- IAP-secured Web App User
- The role that allows a user through IAP to a protected web app.
- IAP-secured Tunnel User
- The role that allows TCP forwarding through IAP to VMs.
- Compute OS Admin Login
- The OS Login role that grants login with sudo privileges.
- Default encryption
- Automatic encryption at rest of all data with Google-managed keys.
- CMEK
- Customer-managed encryption keys in Cloud KMS that you control and Google services use.
- CSEK
- Customer-supplied encryption keys that you provide with each request and Google doesn't store.
- Key ring
- A grouping of Cloud KMS keys in one location.
- Secret
- A named container in Secret Manager that holds versions of a sensitive value.
- Secret version
- An immutable value of a secret; new versions are added to rotate.
- Secret Manager Secret Accessor
- The IAM role that allows reading a secret's value.
- Replication policy
- Whether a secret's data is replicated automatically or only to regions you choose.
- Uniform bucket-level access
- A bucket setting that disables ACLs so only IAM controls access.
- Public access prevention
- A setting or organization policy that blocks access grants to allUsers and allAuthenticatedUsers.
- Signed URL
- A URL that grants time-limited access to an object without requiring a Google identity.
- allUsers
- A special principal meaning anyone on the internet.
- Policy Troubleshooter
- A tool that explains whether a principal has a permission on a resource and why.
- Policy Analyzer
- A tool that finds which principals have which access across the hierarchy.
- IAM recommender
- An Active Assist feature that suggests removing or reducing roles based on permission usage.
- Security Reviewer
- A read-only role for listing resources and viewing IAM policies.
Study Associate Cloud Engineer for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Associate Cloud Engineer study planLessons, quizzes, exam simulations and hands-on labs.