All certifications / Cloud Digital Leader / Cheat sheet
Cloud Digital Leader Cloud Digital Leader cheat sheet
Domain 1: Digital transformation with Google Cloud (17%)
Exam tips
- If an answer only changes where servers run but not how the business works, it is migration, not transformation. Look for answers about speed, experimentation, data-driven decisions and new customer value.
- Scalability is about being able to grow; elasticity is growing and shrinking automatically with demand. A question that mentions short spikes followed by quiet periods is pointing at elasticity.
- The cloud moves spending from CapEx to OpEx, not the reverse. When a question mentions hidden costs such as power, cooling or staff, it is testing TCO.
- Look for the words 'on-premises' or 'our own data center' in the scenario. If they appear alongside a public cloud, the answer is hybrid; if only several public clouds appear, it is multicloud.
- Map products to models: Compute Engine is IaaS, App Engine is PaaS, Cloud Run and Cloud Run functions are serverless, Google Workspace is SaaS. The customer always manages its data and access, in every model.
- Any answer that says the provider becomes responsible for customer data or access decisions is wrong. The question usually tests which layer moves to the provider as you go from IaaS to PaaS to SaaS.
- Zones protect against a data center failure; regions protect against a larger regional disaster and help with latency and data location. Edge PoPs are about getting traffic onto Google's network close to users, not about running your VMs.
- Slow response with low server load usually points to latency from distance, fixed by choosing closer regions or a CDN. Slow bulk transfers point to limited bandwidth.
- When a question mentions portability, flexibility across environments or avoiding lock-in, look for open source, open standards or Kubernetes in the answers.
- When the technology is in place but results are poor, the answer is usually about culture, skills, team structure or processes, not about buying more cloud resources.
Key terms
- Cloud computing
- On-demand access to shared computing resources over a network, paid for by use.
- Digital transformation
- Using digital technology to change how an organization operates, serves customers and creates value.
- On-demand self-service
- Users provision resources themselves, when needed, without human interaction with the provider.
- Measured service
- Resource use is metered and reported, which enables pay-as-you-go billing.
- Scalability
- The ability to increase capacity to handle more load, by scaling up or out.
- Elasticity
- Automatically adding and removing resources as demand changes, so capacity follows load.
- Agility
- The ability to move quickly: provision, experiment and change direction with little delay or cost.
- Reliability
- The ability of a service to keep working correctly when components fail.
- Capital expenditure (CapEx)
- Up-front spending on long-lived assets that are depreciated over time.
- Operating expenditure (OpEx)
- Ongoing spending on services and running costs, expensed as it is used.
- Total cost of ownership (TCO)
- All direct and indirect costs of a system over its life, including facilities, power, staff and refresh.
- Depreciation
- Spreading the cost of an asset over its useful life for accounting.
- On-premises
- Infrastructure the organization runs in its own or leased facilities.
- Private cloud
- Cloud-style infrastructure dedicated to a single organization.
- Hybrid cloud
- A combination of on-premises or private cloud with a public cloud, working together.
- Multicloud
- Using services from two or more public cloud providers.
- IaaS
- Infrastructure as a service: virtual machines, storage and networks, with the customer managing the OS and above.
- PaaS
- Platform as a service: a managed runtime where the customer brings code and data.
- SaaS
- Software as a service: a complete application delivered over the internet.
- Serverless
- Services with no servers to manage, automatic scaling and pay-per-use billing.
- Shared responsibility model
- The division of security and operational duties between the cloud provider and the customer.
- Shared fate
- Google Cloud's approach of actively helping customers secure their part through defaults, tools and guidance.
- Security of the cloud
- The provider's duty: physical facilities, hardware, network and virtualization.
- Security in the cloud
- The customer's duty: data, identities, access and configuration.
- Region
- An independent geographic area containing multiple zones, such as us-central1.
- Zone
- An isolated deployment area within a region; a failure domain for zonal resources.
- Point of presence (PoP)
- An edge location where Google's network connects to other networks near users.
- Multi-region
- A large geographic area, such as US or EU, containing several regions, used by some storage and database services.
- Bandwidth
- The maximum amount of data that can be carried per second on a connection.
- Latency
- The delay for data to travel between two points, usually measured in milliseconds.
- Cloud CDN
- Google Cloud's content delivery network, which caches content at edge locations near users.
- Cloud Interconnect
- Private, high-bandwidth connectivity between an on-premises network and Google Cloud.
- Vendor lock-in
- Dependence on one provider that makes switching costly or difficult.
- Open source
- Software whose code is openly available to use, modify and share under a license.
- Open standard
- A publicly available specification that anyone can implement, such as SQL.
- Portability
- The ability to move applications and data between environments with little change.
- Cloud center of excellence
- A cross-functional team that sets cloud standards, builds shared foundations and helps other teams adopt the cloud.
- Silo
- A team or department that works in isolation from others, slowing hand-offs and decisions.
- Change management
- A structured approach to helping people and organizations adopt new ways of working.
- Blameless culture
- Reviewing failures to learn and improve systems rather than to punish individuals.
Domain 2: Exploring data transformation with Google Cloud (16%)
Exam tips
- Exam scenarios about 'unlocking value from data' usually point to breaking down silos, bringing data together in the cloud and making it accessible, not simply storing more of it.
- Images, video, audio and documents are unstructured and usually go in Cloud Storage. JSON and logs are semi-structured. Tables with fixed columns are structured.
- If the scenario is about an application's day-to-day transactions, choose a database. If it is about analysis and reporting across sources, choose a warehouse (BigQuery). If it is about storing raw data of mixed types cheaply, choose a lake (Cloud Storage).
- Match access frequency: daily use is Standard, monthly is Nearline, quarterly is Coldline, less than yearly is Archive. Remember that Archive still returns data in milliseconds; the trade-off is cost, not speed.
- Keywords: 'existing MySQL/PostgreSQL/SQL Server, minimal changes' means Cloud SQL; 'global, horizontal scale, strong consistency' means Spanner; 'PostgreSQL-compatible, high performance' means AlloyDB.
- Mobile or web app, real-time sync, offline: Firestore. Massive time-series or IoT data with high throughput and low latency: Bigtable. Neither is the answer for SQL analytics, which is BigQuery.
- For large-scale SQL analytics without managing infrastructure, the answer is BigQuery. Cloud SQL runs applications' transactions; BigQuery analyzes data across the business.
- Ingesting events: Pub/Sub. Transforming data in real time without managing servers: Dataflow. Existing Spark or Hadoop code: Dataproc.
- Consistent, governed metrics across the enterprise point to Looker and its semantic model. A quick, free dashboard from many sources points to Looker Studio.
- Watch for clues about network speed and data size. 'Slow connection' and 'hundreds of terabytes' mean Transfer Appliance. 'Minimal downtime database move' means Database Migration Service.
- Questions about finding trusted data, knowing who owns it, tracking where it came from and limiting who sees sensitive fields are all about data governance.
Key terms
- Data-driven decision
- A choice based on analysis of data rather than intuition or habit alone.
- Data silo
- Data held by one team or system that others cannot easily access or combine.
- Data pipeline
- The automated flow that moves data from sources through processing to where it is used.
- Insight
- An understanding gained from data that can guide an action.
- Structured data
- Data organized in a fixed schema of rows and columns, easily queried with SQL.
- Semi-structured data
- Data with tags or keys but a flexible schema, such as JSON or XML.
- Unstructured data
- Data with no predefined model, such as images, video, audio and free text.
- Schema
- The definition of the fields, types and relationships in a data set.
- Database (OLTP)
- A store optimized for many small, fast transactions that run an application.
- Data warehouse (OLAP)
- A store optimized for analytical queries over large amounts of structured, historical data.
- Data lake
- A repository of raw data of any type, stored in its original format for later processing.
- Lakehouse
- An approach combining data lake storage with warehouse-style management and SQL analytics.
- Bucket
- A container for objects in Cloud Storage, with a name, location and default storage class.
- Storage class
- A setting that trades storage price against access cost: Standard, Nearline, Coldline or Archive.
- Minimum storage duration
- The period you are billed for even if you delete an object earlier: 30, 90 and 365 days for Nearline, Coldline and Archive.
- Object Lifecycle Management
- Rules that automatically change the storage class of objects or delete them based on conditions such as age.
- Relational database
- A database that stores data in related tables and uses SQL and transactions.
- Cloud SQL
- Managed MySQL, PostgreSQL and SQL Server databases.
- AlloyDB
- A managed, high-performance PostgreSQL-compatible database.
- Spanner
- A horizontally scalable, strongly consistent relational database that can span regions.
- NoSQL
- Databases that use models other than relational tables, such as documents, key-value or wide columns.
- Firestore
- A serverless NoSQL document database with real-time updates and offline support for apps.
- Bigtable
- A wide-column NoSQL database for very large, low-latency, high-throughput workloads.
- Row key
- The single identifier used to store and retrieve rows in Bigtable, which determines how data is organized.
- Data warehouse
- A central store of cleaned, structured data optimized for analytical queries.
- Serverless
- No infrastructure to provision or manage; capacity is allocated automatically.
- Columnar storage
- Storing data by column, so queries read only the columns they need.
- BigQuery sandbox
- A no-cost way to try BigQuery within free monthly limits, without a billing account.
- Pub/Sub
- A global messaging service where publishers send messages to topics and subscribers receive them asynchronously.
- Dataflow
- A serverless service that runs Apache Beam pipelines for streaming and batch data processing.
- Dataproc
- A managed service for Apache Spark, Hadoop and related open source tools.
- Streaming data
- Data processed continuously as events arrive, rather than in scheduled batches.
- Business intelligence (BI)
- Tools and practices that turn data into reports and dashboards for decision making.
- Semantic layer
- A shared definition of business metrics and data relationships used by all reports.
- LookML
- Looker's modeling language for defining dimensions, measures and relationships.
- Looker Studio
- Google's free, self-service dashboard and reporting tool.
- Database Migration Service
- A managed service that migrates databases into Cloud SQL or AlloyDB with minimal downtime.
- BigQuery Data Transfer Service
- Scheduled, managed data loads into BigQuery from Google, SaaS and other sources.
- Storage Transfer Service
- Online transfers of object and file data into Cloud Storage from other clouds, HTTP or on-premises.
- Transfer Appliance
- A physical device shipped to a customer to move very large data sets offline into Google Cloud.
- Data governance
- Policies, roles and tools that keep data accurate, secure, discoverable and properly used.
- Data lineage
- A record of where data came from and how it was transformed.
- Data catalog
- An inventory of data assets with descriptions, owners and classifications so people can find them.
- Column-level security
- Restricting access to specific columns, such as sensitive fields, in a table.
Domain 3: Innovating with Google Cloud artificial intelligence (16%)
Exam tips
- If the system produces new content from a prompt, it is generative AI. If it predicts a category or number from past examples, it is traditional (predictive) ML. If it follows fixed if-then logic, it is not ML at all.
- Exam distractors often suggest ML for tasks with exact rules. Choose ML when patterns are complex and data is plentiful; choose ordinary code when the logic is known.
- When a model works well for one group but poorly for another, the most likely cause is unrepresentative training data, not a lack of computing power.
- Match the scenario to the principle: 'why did the model decide this' is explainability, 'different results for different groups' is fairness, 'who is responsible' is accountability, 'personal data' is privacy.
- Common task plus no ML skills plus need it quickly equals a pre-trained API. The Vision API reads text in images; the Natural Language API analyzes meaning in text; Translation converts between languages.
- SQL-skilled analysts plus data already in BigQuery plus a common prediction task equals BigQuery ML. It avoids moving data and needs no Python.
- Own labeled data plus little ML expertise points to AutoML. Unique, differentiating problem plus skilled data scientists points to custom training. Both run on Vertex AI.
- Read the clues: 'no ML expertise, common task' is a pre-trained API; 'SQL analysts, data in BigQuery' is BigQuery ML; 'own labeled data, little expertise' is AutoML; 'unique, full control, data scientists' is custom training.
- Model Garden is for finding and choosing models; Vertex AI Studio is for testing prompts and prototyping; Gemini is the model family. Multimodal means text plus images, audio or video in the same model.
- When a scenario describes made-up or outdated answers from a chatbot about company information, the fix is grounding the model in trusted company data, not adding more compute.
- TPUs are Google's custom-designed ML chips. If a question asks what Google built specifically to accelerate machine learning, the answer is TPUs, not GPUs.
Key terms
- Artificial intelligence (AI)
- The field of building systems that perform tasks that normally need human intelligence.
- Machine learning (ML)
- A subset of AI where systems learn patterns from data instead of following hand-written rules.
- Generative AI
- AI that creates new content, such as text, images or code, from a prompt.
- Foundation model
- A large model trained on broad data that can be adapted to many tasks; LLMs are one kind.
- Classification
- Predicting which category an item belongs to, such as fraud or not fraud.
- Forecasting
- Predicting future numeric values, such as demand next month.
- Anomaly detection
- Finding data points that differ significantly from normal patterns.
- Model drift
- A drop in model accuracy over time as real-world data changes from the training data.
- Training data
- The examples a model learns from.
- Representative data
- Data that covers the full range of cases and groups the model will face in real use.
- Bias (in ML)
- Systematic errors in a model's output that unfairly favor or disadvantage certain groups.
- Label
- The correct answer attached to a training example in supervised learning.
- Responsible AI
- Designing and using AI so that it is fair, safe, private, explainable and accountable.
- Fairness
- Avoiding unjust differences in outcomes for different groups of people.
- Explainability
- The ability to describe why a model produced a given output.
- Human in the loop
- A design where a person reviews or approves AI outputs before important actions.
- Pre-trained model
- A model already trained by the provider that you can use immediately without your own training data.
- OCR
- Optical character recognition: extracting text from images of printed or handwritten documents.
- Sentiment analysis
- Determining whether text expresses a positive, negative or neutral opinion.
- Entity extraction
- Identifying names of people, places, organizations and other items in text.
- BigQuery ML
- A BigQuery feature for creating, training and using ML models with SQL.
- CREATE MODEL
- The SQL statement that defines and trains a model in BigQuery ML.
- ML.PREDICT
- The BigQuery ML function that applies a trained model to data to produce predictions.
- Logistic regression
- A model type that predicts the probability of a yes-or-no outcome.
- Vertex AI
- Google Cloud's unified platform for building, deploying and managing ML and generative AI.
- AutoML
- Training a custom model on your own data with little or no code; the service handles model design and tuning.
- Custom training
- Training with your own code and framework for full control over the model.
- MLOps
- Practices and tools for deploying, monitoring and maintaining ML models in production.
- Build vs buy
- Deciding whether to develop a solution in-house or use an existing product or service.
- Customization
- How much a model can be adapted to an organization's specific data and needs.
- Time to value
- How quickly an approach starts delivering business results.
- Tuning
- Adapting a pre-trained or foundation model with additional examples for a specific task.
- Gemini
- Google's family of multimodal foundation models.
- Multimodal
- Able to process more than one type of data, such as text, images and audio, together.
- Vertex AI Model Garden
- A catalog in Vertex AI for discovering, testing and deploying Google, partner and open models.
- Prompt engineering
- Designing inputs to a generative model to get more useful and reliable outputs.
- Hallucination
- A confident but incorrect or made-up output from a generative model.
- Grounding
- Connecting model outputs to trusted sources so responses are based on real information.
- Retrieval-augmented generation (RAG)
- Retrieving relevant content from a knowledge source and giving it to the model with the question.
- AI agent
- A system that uses a model to plan and take actions through tools to achieve a goal.
- Accelerator
- Specialized hardware, such as a GPU or TPU, that speeds up ML computation.
- GPU
- Graphics processing unit: a processor with many parallel cores, widely used for ML.
- TPU
- Tensor Processing Unit: Google's custom ASIC designed for machine learning workloads.
- ASIC
- Application-specific integrated circuit: a chip designed for one type of task.
Domain 4: Modernize infrastructure and applications with Google Cloud (17%)
Exam tips
- Infrastructure modernization changes where things run; application modernization changes how they are built and delivered. The biggest agility gains come from the second.
- Deadline and no time for changes: rehost. Small changes to use managed services: replatform. Rewrite for cloud-native benefits: refactor. Unused: retire. Not moving yet: retain.
- Automatic scaling and replacement of failed VMs points to a managed instance group. Full control of the OS points to Compute Engine rather than serverless options.
- The words 'VMware', 'existing tools and processes' and 'fast migration' point to Google Cloud VMware Engine. 'Oracle' or 'dedicated physical hardware' point to Bare Metal Solution.
- Portability and consistency across environments are the key container benefits. Containers share the host kernel, so they are lighter and faster to start than VMs, which each carry a full guest OS.
- Want Kubernetes without managing nodes: GKE Autopilot. Want control over node configuration: GKE Standard. Remember that Kubernetes itself is open source and started at Google.
- Containerized web app or API with no infrastructure to manage and scale to zero: Cloud Run. Small piece of code triggered by an event: Cloud Run functions. Code-based web app platform: App Engine.
- Use the most managed service that meets the need. Full OS control or unchanged legacy app: Compute Engine. Kubernetes features and portability: GKE. Stateless, spiky, minimal operations: Cloud Run.
- Independent deployment, independent scaling and fault isolation are the key microservices benefits. The trade-off is more operational complexity, so they suit large, fast-changing applications.
- APIs unlock legacy data and enable partner ecosystems. Apigee manages them: security, quotas, analytics, developer portals and monetization.
- Consistent management, policy and security across on-premises, Google Cloud and other clouds is GKE Enterprise. The older name Anthos may still appear in study materials.
Key terms
- Modernization
- Updating infrastructure and applications to use cloud capabilities such as managed services, containers and automation.
- Technical debt
- The future cost created by outdated technology or shortcuts that make change harder.
- CI/CD
- Continuous integration and continuous delivery: automating build, test and deployment of code.
- Migration Center
- A Google Cloud tool for discovering current infrastructure, assessing it and planning a migration.
- Rehost (lift and shift)
- Moving an application to the cloud without changing it, usually onto VMs.
- Replatform (move and improve)
- Making targeted changes, such as adopting a managed database, while migrating.
- Refactor
- Changing an application's code and architecture to be cloud native.
- Retire
- Decommissioning an application that is no longer needed instead of migrating it.
- Compute Engine
- Google Cloud's IaaS service for running virtual machines.
- Machine type
- The vCPU and memory configuration of a VM, predefined or custom.
- Managed instance group (MIG)
- A group of identical VMs created from a template with autoscaling, autohealing and rolling updates.
- Instance template
- A reusable definition of a VM's configuration used to create VMs in a MIG.
- Google Cloud VMware Engine
- A managed service running a native VMware environment in Google Cloud.
- Bare Metal Solution
- Dedicated physical servers near Google Cloud regions for specialized workloads such as Oracle databases.
- Hypervisor
- Software that creates and runs virtual machines on physical hardware.
- Bare metal
- A physical server used directly, without a virtualization layer shared with others.
- Container
- A lightweight package of an application and its dependencies that runs consistently in any environment.
- Container image
- A read-only, versioned template from which containers are started.
- Artifact Registry
- Google Cloud's service for storing and managing container images and other build artifacts.
- Orchestration
- Automated scheduling, scaling, networking and healing of many containers across machines.
- Kubernetes
- An open source system for automating deployment, scaling and management of containers.
- GKE
- Google Kubernetes Engine, Google Cloud's managed Kubernetes service.
- Autopilot
- A GKE mode where Google manages nodes and infrastructure and billing is based on pod resource requests.
- Pod
- The smallest deployable unit in Kubernetes, containing one or more containers.
- Serverless
- Running code without managing servers, with automatic scaling and pay-per-use pricing.
- Cloud Run
- A managed serverless platform for running containers that scales automatically, including to zero.
- Cloud Run functions
- Event-driven serverless functions that run in response to triggers such as HTTP requests or new files.
- Scale to zero
- Running no instances, and incurring no compute cost, when there is no traffic.
- Compute spectrum
- The range from IaaS VMs (most control) to serverless (least management).
- Stateless
- An application that stores no session data locally, so any instance can handle any request.
- Operational overhead
- The work needed to run, patch, scale and secure infrastructure.
- Portability
- The ability to run the same workload in different environments.
- Monolith
- An application built and deployed as a single unit.
- Microservices
- An architecture of small, independently deployable services that communicate through APIs.
- Strangler pattern
- Gradually replacing parts of a legacy system with new services until the old system can be retired.
- Infrastructure as code
- Defining and managing infrastructure through version-controlled configuration files.
- API
- Application programming interface: a defined way for software to request data or actions from other software.
- API management
- Securing, controlling, monitoring and publishing APIs as products.
- Apigee
- Google Cloud's API management platform.
- Rate limiting
- Restricting how many requests a consumer can make in a period to protect back-end systems.
- GKE Enterprise
- Google Cloud's platform for managing Kubernetes clusters across Google Cloud, on-premises, other clouds and edge (formerly Anthos).
- Fleet
- A logical group of Kubernetes clusters managed together.
- Service mesh
- A layer that manages secure communication, traffic and observability between services.
- Policy as code
- Defining configuration and security policies in version-controlled files applied automatically.
Domain 5: Trust and security with Google Cloud (17%)
Exam tips
- Map the incident to the property: data seen by the wrong people is confidentiality, data changed is integrity, service down is availability. Being compliant does not mean being secure.
- Moving to the cloud shifts infrastructure security to Google, but data, identities, access and configuration stay with the customer in every model.
- Most cloud breaches trace back to customer-side issues: misconfiguration and stolen credentials. The strongest defenses are secure configuration, least privilege and phishing-resistant multi-factor authentication.
- Zero trust: verify every request by identity and context, not network location. Defense in depth: several layers of controls. If a question describes 'trusting everything inside the network', it describes the old perimeter model.
- Know the layers: physical data center security, custom hardware with Titan chips, encrypted and authenticated service communication, a private global network, and strict operational controls. Customers inherit all of these.
- Encryption at rest is on by default; customers do not need to enable it. Choose CMEK in Cloud KMS when a question stresses customer control over key rotation, disabling or destroying keys.
- Grant roles, not permissions, to groups rather than individuals, on the smallest scope. Basic roles (Owner, Editor, Viewer) are almost never the least-privilege answer.
- DDoS and web attacks against a public site: Cloud Armor. Data being copied out of managed services even with valid credentials: VPC Service Controls. Allowing or denying traffic to VMs by port and address: firewall rules.
- Posture and threats across Google Cloud projects: Security Command Center. Who did what and when: Cloud Audit Logs (Admin Activity is always on). Enterprise-wide SIEM and SOAR: Google Security Operations.
- Residency is about where data sits, set by choosing regions and enforced with the resource locations policy. Sovereignty adds who controls and can access it under which laws. Regulated workloads with location and personnel controls point to Assured Workloads.
- Audit reports and certificates: Compliance Reports Manager. Logs of Google staff access: Access Transparency. Approving access before it happens: Access Approval. Provider certifications do not make the customer compliant automatically.
Key terms
- Confidentiality
- Ensuring information is only accessible to authorized people.
- Integrity
- Ensuring information is accurate and not altered without authorization.
- Availability
- Ensuring systems and data are accessible when needed.
- Compliance
- Meeting the requirements of laws, regulations, standards and contracts.
- Shared responsibility
- The division of security duties between the cloud provider and the customer.
- Shared fate
- Google Cloud's approach of actively helping customers secure their workloads with defaults, tools and guidance.
- Attack surface
- All the points where an attacker could try to get into a system.
- Identity perimeter
- Treating identity and access checks, rather than the network edge, as the main security boundary.
- Misconfiguration
- An insecure setting, such as public access or overly broad permissions, often made by mistake.
- Phishing
- Deceptive messages designed to trick people into revealing credentials or running malware.
- Ransomware
- Malware that encrypts data and demands payment to restore access.
- Compromised credentials
- Passwords, keys or tokens obtained by an attacker and used to impersonate a legitimate user.
- Zero trust
- A model that grants no implicit trust based on network location and verifies every request.
- BeyondCorp
- Google's implementation of zero trust, allowing access based on user and device rather than network.
- Defense in depth
- Layering multiple independent security controls so one failure does not expose the system.
- Identity-Aware Proxy (IAP)
- A Google Cloud service that checks identity and context before granting access to applications and VMs.
- Titan chip
- A Google-designed security chip that verifies machines boot with trusted firmware and software.
- Hardware root of trust
- A trusted hardware component that verifies the integrity of the system from start-up.
- Shielded VM
- A Compute Engine VM with secure boot and integrity monitoring against boot-level tampering.
- Defense at scale
- Using the size of Google's network and security operations to detect and absorb attacks.
- Encryption at rest
- Encrypting stored data; on by default for all customer data in Google Cloud.
- Encryption in transit
- Encrypting data as it moves across networks, for example with TLS.
- CMEK
- Customer-managed encryption keys: keys the customer creates and controls in Cloud KMS.
- Cloud KMS
- Google Cloud's service for creating, managing, rotating and using cryptographic keys.
- Principal
- An identity that can be granted access, such as a user, group or service account.
- Role
- A collection of permissions that can be granted to a principal on a resource.
- Least privilege
- Granting only the permissions needed, on the narrowest scope, for only as long as needed.
- Service account
- An identity used by applications and workloads rather than people.
- VPC firewall rules
- Rules that allow or deny network traffic to and from resources in a VPC network.
- Cloud Armor
- Google Cloud's DDoS protection and web application firewall for applications behind external load balancers.
- Web application firewall (WAF)
- A filter that blocks common web attacks such as SQL injection and cross-site scripting.
- VPC Service Controls
- Service perimeters around Google Cloud services that reduce the risk of data exfiltration.
- Security Command Center
- Google Cloud's central platform for security posture, vulnerabilities, misconfigurations and threat detection.
- Cloud Audit Logs
- Logs recording administrative actions and data access in Google Cloud.
- SIEM
- Security information and event management: collecting and analyzing security logs to detect threats.
- SOAR
- Security orchestration, automation and response: automating investigation and response steps.
- Data residency
- The geographic location where data is stored and processed.
- Data sovereignty
- The principle that data is subject to the laws of the country where it is located, including control over who can access it.
- Assured Workloads
- A Google Cloud service that applies controls, such as data location and personnel access, for regulated workloads.
- Resource locations constraint
- An organization policy that restricts the locations where resources can be created.
- Compliance Reports Manager
- Google's portal for downloading certifications and third-party audit reports.
- Access Transparency
- Logs of actions Google personnel take on customer content, with justifications.
- Access Approval
- A feature that requires customer approval before Google personnel access customer content.
- SOC 2 report
- An independent audit report on a service provider's controls for security, availability, confidentiality and related criteria.
Domain 6: Scaling with Google Cloud operations (17%)
Exam tips
- FinOps is about shared accountability and maximizing business value, not only cutting cost. Look for answers that involve visibility and collaboration between finance and engineering.
- Remember the order: organization, folders, projects, resources. Every resource lives in exactly one project, and projects are where APIs are enabled and billing is linked.
- IAM controls who can do what; organization policies control what can be configured, for everyone. IAM allow grants are additive, so a grant at a folder cannot be removed at a project below it.
- Budgets alert, they do not cap. Quotas limit resource use. Labels allocate cost. Billing export to BigQuery enables detailed analysis. Know which tool fits each goal.
- Steady and predictable for years: committed use discounts. Fault-tolerant and interruptible: Spot VMs. Automatic, no commitment: sustained use discounts. Unpredictable: pay-as-you-go.
- SRE is Google's implementation of DevOps principles. Key words to recognize: SLOs, error budgets, toil reduction, automation and blameless postmortems.
- SLI is what you measure, SLO is your internal target, SLA is the external contract with penalties. Error budget = 100% minus SLO. SLAs are usually looser than SLOs.
- RPO is about data loss (how far back you restore to); RTO is about downtime (how long until you are running). Multiple zones protect against zone failure; multiple regions protect against regional disasters.
- Metrics, dashboards and alerts: Cloud Monitoring. Searching and storing logs: Cloud Logging. Finding latency across microservices: Cloud Trace. Grouping application errors: Error Reporting.
- Business-critical workloads that need the fastest response and a named adviser point to the top tier (Premium Support with a Technical Account Manager). Do not memorize response times; they change.
- Know the tools: the Carbon Footprint tool reports customer emissions; low CO2 region indicators and CFE% help choose regions. Google's 2030 goal is 24/7 carbon-free energy.
Key terms
- FinOps
- A practice that brings finance, technology and business together to manage cloud costs and maximize value.
- Cost allocation
- Assigning cloud costs to the teams, products or projects that incur them.
- Rightsizing
- Changing resources to the size that actually matches their workload.
- Active Assist recommendations
- Google Cloud suggestions, such as removing idle VMs or resizing machines, to reduce cost and improve security.
- Organization node
- The root of the resource hierarchy, representing the company.
- Folder
- A grouping of projects and other folders, often by department, team or environment.
- Project
- The basic unit for enabling services, billing, IAM and grouping resources; every resource belongs to one.
- Project ID
- A globally unique, permanent identifier for a project.
- Policy inheritance
- Policies set on a node apply to all descendants in the hierarchy.
- IAM allow policy
- A policy that grants roles to principals on a resource.
- Organization policy
- A constraint that restricts how resources can be configured, regardless of who acts.
- Additive access
- Effective permissions are the union of all grants at a resource and its ancestors.
- Cloud Billing account
- The account that pays for Google Cloud usage, linked to projects and a payment method.
- Budget alert
- A notification sent when actual or forecast spend reaches a threshold; it does not stop spending.
- Quota
- A limit on how much of a resource or API a project can use.
- Label
- A key-value pair attached to resources, used to organize and allocate costs.
- Pay-as-you-go
- Paying only for resources used, with no up-front commitment.
- Sustained use discount
- An automatic discount for certain Compute Engine resources that run for much of a month.
- Committed use discount (CUD)
- A lower price in exchange for a one- or three-year commitment to resources or spend.
- Spot VM
- A heavily discounted VM using spare capacity that Google can stop at any time.
- DevOps
- A culture and practices uniting development and operations to deliver changes quickly and reliably.
- Site Reliability Engineering (SRE)
- Google's approach to running reliable systems by applying software engineering to operations.
- Toil
- Manual, repetitive operational work that scales with the service and can be automated.
- Blameless postmortem
- An incident review that focuses on causes and fixes, not on blaming individuals.
- SLI
- Service level indicator: a measurement of service behavior, such as the percentage of successful requests.
- SLO
- Service level objective: an internal target for an SLI over a period of time.
- SLA
- Service level agreement: a contract with customers stating consequences if a service level is not met.
- Error budget
- The allowed unreliability under an SLO, equal to 100% minus the SLO.
- High availability
- Designing a system to keep running despite component failures, usually through redundancy.
- Disaster recovery
- Plans and systems for restoring service after a major failure.
- RTO
- Recovery time objective: the maximum acceptable downtime before service is restored.
- RPO
- Recovery point objective: the maximum acceptable data loss, measured in time.
- Observability
- The ability to understand a system's internal state from its metrics, logs and traces.
- Cloud Monitoring
- Collects metrics and provides dashboards, uptime checks and alerts.
- Cloud Logging
- Collects, stores, searches and routes log data.
- Cloud Trace
- Distributed tracing that shows how long each step of a request takes across services.
- Customer Care
- Google Cloud's support offering, with basic and paid plans.
- Technical Account Manager (TAM)
- A named Google adviser for Premium Support customers who knows their environment.
- Case priority
- The urgency level set on a support case, based on business impact.
- Proactive support
- Guidance such as architecture reviews and event planning offered before problems happen.
- 24/7 carbon-free energy
- Matching every hour of electricity use with carbon-free sources on the same grid; Google's 2030 goal.
- Carbon-free energy percentage (CFE%)
- The share of a region's hourly electricity use that comes from carbon-free sources.
- Carbon Footprint tool
- A console tool that reports the estimated emissions of a customer's Google Cloud usage.
- Low CO2 region
- A region marked in the console as having low grid carbon intensity.
Study Cloud Digital Leader for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Cloud Digital Leader study planLessons, quizzes, exam simulations and hands-on labs.