All certifications / Associate Cloud Engineer / Lessons
Associate Cloud Engineer Associate Cloud Engineer lessons
Study Associate Cloud Engineer for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Associate Cloud Engineer study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Setting up a cloud solution environment
- Resource hierarchy: organization, folders and projects, and how IAM and organization policies are inherited
- Creating projects: project name, project ID and project number, and enabling APIs
- Organization Policy Service: constraints such as resource locations and disabling service account key creation
- Managing users and groups with Cloud Identity or Google Workspace, and Google Cloud Directory Sync
- Granting IAM roles to users and groups at the organization, folder and project levels
- Cloud Billing accounts: linking projects to billing and the billing IAM roles
- Budgets, budget alerts and exporting billing data to BigQuery
- Installing and configuring the Google Cloud CLI: gcloud init, named configurations, default project, region and zone
- Cloud Shell, the Google Cloud console and Cloud Shell Editor
- Quotas: viewing usage, understanding quota errors and requesting increases
- Regions, zones and labels: placing resources and organizing them for cost reporting
Domain 2: Planning and implementing a cloud solution
- Choosing a compute option: Compute Engine, GKE, Cloud Run, Cloud Run functions and App Engine
- Compute Engine instances: machine families, custom machine types, images and Spot VMs
- Compute Engine disks: Persistent Disk and Hyperdisk types, regional disks and local SSD
- Instance templates and managed instance groups: autoscaling, autohealing and rolling updates
- Google Kubernetes Engine clusters: Autopilot vs Standard, zonal vs regional, and node pools
- Deploying workloads to GKE with kubectl: Deployments, Services and Ingress
- Cloud Run services and Cloud Run functions: deploying containers and event-driven code with Eventarc and Pub/Sub
- Choosing a data product: Cloud SQL, AlloyDB, Spanner, Firestore, Bigtable and BigQuery
- Cloud Storage buckets: storage classes, locations, lifecycle rules and Object Versioning
- VPC networks: auto vs custom mode, subnets, firewall rules, Shared VPC and VPC Network Peering
- Load balancing, Cloud NAT and hybrid connectivity with Cloud VPN and Cloud Interconnect
- Infrastructure as code with Terraform and Cloud Marketplace solutions
Domain 3: Ensuring successful operation of a cloud solution
- Managing Compute Engine VMs: start, stop, resize, SSH with OS Login and IAP TCP forwarding
- Snapshots, snapshot schedules, custom images and image families
- Managing GKE: scaling Deployments, node pool autoscaling, rollouts and rollbacks, and cluster upgrades
- Managing Cloud Run: revisions, traffic splitting, minimum and maximum instances
- Managing Cloud Storage objects with gcloud storage and moving data with Storage Transfer Service
- Operating databases: Cloud SQL backups, high availability and read replicas, and BigQuery dry runs
- Operating networks: expanding subnets, static IP addresses and Cloud DNS
- Cloud Monitoring: metrics, dashboards, alerting policies, uptime checks and the Ops Agent
- Cloud Logging: Logs Explorer, log-based metrics, log buckets and sinks
- Cloud Audit Logs: Admin Activity, Data Access, System Event and Policy Denied logs
- Troubleshooting with Error Reporting, Cloud Trace and Cloud Profiler
Domain 4: Configuring access and security
- IAM roles: basic, predefined and custom roles, and least privilege
- Viewing and changing IAM allow policies with gcloud, and IAM Conditions
- Service accounts: creating them, granting roles, attaching them to resources, and default service accounts
- Service account impersonation, short-lived credentials and avoiding service account keys
- Workload Identity Federation for GKE and for workloads outside Google Cloud
- Identity-Aware Proxy and OS Login for secure administrative access
- Encryption: Google default encryption, Cloud KMS customer-managed keys and customer-supplied keys
- Secret Manager for passwords, API keys and certificates
- Cloud Storage access: uniform bucket-level access, public access prevention and signed URLs
- Policy Troubleshooter, IAM recommendations and audit roles for reviewing access