Google Cloud ACE Planning and Configuring Solutions

0.0(0)
studied byStudied by 0 people
0.0(0)
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/176

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:57 AM on 2/3/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

177 Terms

1
New cards

GCP Pricing Calculator

The primary tool used to estimate monthly costs for Google Cloud services based on expected usage.

2
New cards

TCO (Total Cost of Ownership)

The comprehensive assessment of all costs—direct and indirect—associated with moving workloads to the cloud vs. on-premises.

3
New cards

Cloud Storage Standard

Best for "hot" data accessed frequently with no retrieval fee.

4
New cards

Cloud Storage Nearline

Best for data accessed less than once a month (e.g., monthly backups); 30-day minimum storage duration.

5
New cards

Cloud Storage Coldline

Best for data accessed less than once a quarter; 90-day minimum storage duration.

6
New cards

Cloud Storage Archive

Best for long-term data kept for years; 365-day minimum storage duration; highest retrieval cost.

7
New cards

Compute Engine Custom Machine Type

Allows you to specify exact numbers of vCPUs and GB of RAM to optimize cost and performance.

8
New cards

Preemptible VMs

Short-lived, low-cost VMs that can be reclaimed by GCP at any time; max 24-hour runtime.

9
New cards

Spot VMs

The modern replacement for Preemptible VMs; same low cost but no 24-hour runtime limit.

10
New cards

Committed Use Discounts (CUD)

Significant discounts in exchange for committing to use a specific amount of resources for 1 or 3 years.

11
New cards

Sustained Use Discounts (SUD)

Automatic discounts applied to Compute Engine bills when resources are used for a large portion of the billing month.

12
New cards

Sole-Tenant Nodes

Physical hardware dedicated to a single customer; used for compliance, licensing, or security.

13
New cards

Cloud SQL

Managed relational database supporting MySQL, PostgreSQL, and SQL Server; limited to 64TB.

14
New cards

Cloud Spanner

Fully managed, horizontally scalable, relational database with strong consistency for global scale.

15
New cards

Firestore

Flexible, scalable NoSQL document database for mobile, web, and server development.

16
New cards

BigTable

High-performance, scalable NoSQL wide-column database for large analytical and operational workloads (HBase compatible).

17
New cards

BigQuery

Serverless, highly scalable data warehouse with a built-in SQL engine and machine learning.

18
New cards

MemoryStore

Fully managed in-memory data store service for Redis and Memcached.

19
New cards

Choosing Compute Engine

Use when you need full control over the OS or have legacy software that won't run in containers.

20
New cards

Choosing GKE

Use when you need to manage a complex microservices architecture using Kubernetes.

21
New cards

Choosing App Engine Standard

Use for web apps in specific languages where you want zero-server management and scaling to zero.

22
New cards

Choosing App Engine Flexible

Use for web apps in containers or unsupported languages that need more underlying infrastructure control.

23
New cards

Choosing Cloud Run

Use for stateless containers that scale to zero and are triggered by HTTP requests or events.

24
New cards

Choosing Cloud Functions

Use for small, single-purpose snippets of code triggered by cloud events (FaaS).

25
New cards

Standard Network Tier

Delivers traffic over the public internet; cheaper but higher latency.

26
New cards

Premium Network Tier

Delivers traffic over Google’s private high-speed global network; default and higher performance.

27
New cards

Public IP Address

An IP address reachable from the internet; assigned to a VM for external communication.

28
New cards

Static External IP

A reserved public IP address that remains assigned to a resource even if it is stopped.

29
New cards

Ephemeral IP

A temporary IP address that is released when a resource is deleted or stopped.

30
New cards

VPC (Virtual Private Cloud)

A global private network that provides connectivity for GCP resources.

31
New cards

Subnet Mask /24

Provides 256 total IP addresses (252 usable in GCP).

32
New cards

Reserved IP Addresses in Subnets

GCP reserves the first two (.0, .1) and last two addresses (.254, .255) plus the gateway (.1).

33
New cards

Regional Managed Instance Group (MIG)

Provides high availability by spreading VM instances across multiple zones in one region.

34
New cards

Autoscaling Policy

Rules that trigger a MIG to add or remove instances (e.g., CPU usage, Load Balancing capacity).

35
New cards

Health Check

A mechanism to determine if a VM or service is healthy; used by MIGs for auto-healing and Load Balancers.

36
New cards

Global Load Balancer

Routes traffic to the closest healthy instance across different regions (HTTP/S, SSL Proxy, TCP Proxy).

37
New cards

Regional Load Balancer

Routes traffic within a single region (Network Load Balancer, Internal HTTP/S).

38
New cards

Content Delivery Network (Cloud CDN)

Caches content at Google’s edge locations to reduce latency for end users.

39
New cards

Cloud Storage Multi-Regional

Storing data in at least two geographic locations for maximum availability.

40
New cards

Cloud Storage Dual-Regional

Storing data in two specific regions (e.g., us-east1 and us-west1) for high availability and low latency.

41
New cards

Transfer Appliance

A high-capacity physical hardware device used to migrate massive amounts of data (TB to PB) to GCP.

42
New cards

Storage Transfer Service

An online service to move data from other cloud providers or on-premises to Cloud Storage.

43
New cards

Database Migration Service (DMS)

Serverless tool to migrate databases (like MySQL/Postgres) to Cloud SQL with minimal downtime.

44
New cards

VPC Peering

Connecting two VPC networks so they can communicate using private IP addresses.

45
New cards

Shared VPC

Allows multiple projects to share a single VPC network managed in a host project.

46
New cards

Cloud VPN

Securely connects on-premises networks to GCP VPCs over the public internet using IPsec.

47
New cards

Cloud Interconnect (Dedicated)

Direct physical connection between on-premises and Google network; 10 Gbps or 100 Gbps.

48
New cards

Cloud Interconnect (Partner)

Physical connection to Google through a supported service provider.

49
New cards

Cloud Router

Enables dynamic routing (BGP) between VPCs and on-premises networks.

50
New cards

Firewall Rules: Priority

A number from 0-65535; lower numbers have higher priority (0 is highest).

51
New cards

Firewall Rules: Implied Egress Allow

A default rule that allows all outgoing traffic from VMs.

52
New cards

Firewall Rules: Implied Ingress Deny

A default rule that blocks all incoming traffic to VMs.

53
New cards

Internal Load Balancer

Distributes traffic to instances within a VPC; not accessible from the internet.

54
New cards

Cloud DNS

A scalable, reliable, and managed authoritative Domain Name System service.

55
New cards

Private Google Access

Allows VMs with only private IPs to access Google APIs and services.

56
New cards

Cloud NAT

Allows VMs without public IPs to access the internet for updates or downloads.

57
New cards

Deployment Manager

An infrastructure-as-code service that uses YAML or Python to automate resource creation.

58
New cards

Terraform

An industry-standard infrastructure-as-code tool often used with GCP for multi-cloud deployments.

59
New cards

App Engine Traffic Splitting

Mechanism to send a percentage of traffic to different versions of an application (A/B testing).

60
New cards

Instance Template

A resource used to define the configuration (machine type, image, disk) for instances in a MIG.

61
New cards

Managed Instance Group (MIG)

A collection of identical VM instances managed as a single entity.

62
New cards

Unmanaged Instance Group

A group of dissimilar VMs; does not support autoscaling or auto-healing.

63
New cards

Shielded VMs

Compute Engine instances hardened against rootkits and boot-level malware.

64
New cards

Confidential Computing

Encrypts data in use (while it is being processed in RAM).

65
New cards

Snapshot

A point-in-time backup of a persistent disk; used for disaster recovery or image creation.

66
New cards

Custom Image

A boot disk image created from a VM or snapshot used to deploy identical pre-configured instances.

67
New cards

Cloud IAM Role: Project Viewer

Permission to see resources but not change them or see data (e.g., cannot see contents of a bucket).

68
New cards

Cloud IAM Role: Project Editor

Permission to modify most resources but not manage access or billing.

69
New cards

Cloud IAM Role: Project Owner

Full control over resources, including access management and billing.

70
New cards

Storage Object Viewer

Allows reading objects and metadata in a bucket but not listing the bucket itself.

71
New cards

Storage Object Creator

Allows writing objects to a bucket but not viewing or deleting them.

72
New cards

Cloud Storage Lifecycle Management

Rules to automatically transition data to cheaper storage classes or delete old data.

73
New cards

BigQuery Slot

A unit of computational capacity used to execute SQL queries.

74
New cards

BigQuery Partitioning

Dividing a table based on a column (usually Date) to improve query performance and reduce cost.

75
New cards

BigQuery Clustering

Organizing data based on the values of specific columns to optimize range filters.

76
New cards

Dataflow

Fully managed service for stream and batch data processing (based on Apache Beam).

77
New cards

Dataproc

Managed Hadoop and Spark service used for running big data clusters.

78
New cards

Pub/Sub

Asynchronous messaging service that decouples senders from receivers.

79
New cards

Cloud Build

Serverless CI/CD platform that builds, tests, and deploys software.

80
New cards

Artifact Registry

Next-generation manager for container images and language packages (Docker, Maven, npm).

81
New cards

Cloud Source Repositories

Private Git repositories hosted on Google Cloud.

82
New cards

Operation Suite: Cloud Monitoring

Collects metrics, dashboards, and alerts for infrastructure and applications.

83
New cards

Operation Suite: Cloud Logging

Stores, searches, and analyzes log data from GCP services.

84
New cards

Operation Suite: Cloud Trace

Provides distributed tracing for finding performance bottlenecks in microservices.

85
New cards

Operation Suite: Error Reporting

Aggregates and displays errors from running cloud services.

86
New cards

Secret Manager

Securely stores API keys, passwords, and certificates.

87
New cards

Cloud Armor

Web Application Firewall (WAF) and DDoS protection for HTTP/S load balancers.

88
New cards

Identity-Aware Proxy (IAP)

Controls access to applications and VMs without using a VPN.

89
New cards

Cloud Endpoints

Tool to help develop, deploy, and manage APIs on Google Cloud.

90
New cards

Apigee

Enterprise-grade API management platform for complex API ecosystems.

91
New cards

Vertex AI

Unified platform for training and deploying machine learning models.

92
New cards

Vision API

Pre-trained ML model for analyzing image content (labels, faces, OCR).

93
New cards

Translation API

Pre-trained ML model for translating text between languages.

94
New cards

Pub/Sub Topic

A named resource to which messages are sent by publishers.

95
New cards

Pub/Sub Subscription

A named resource representing the stream of messages from a specific topic to be delivered to a subscriber.

96
New cards

Pull Subscription

Subscriber requests messages from the Pub/Sub server.

97
New cards

Push Subscription

Pub/Sub server sends messages to a specific URL (webhook).

98
New cards

VPC Network Peering Transitivity

Peering is NOT transitive; if A peers with B, and B peers with C, A cannot talk to C.

99
New cards

Cloud Storage Versioning

Keeps a history of object changes to protect against accidental deletion.

100
New cards

Cloud Storage Signed URL

A URL that provides temporary, time-limited access to a specific Cloud Storage resource.