Associate Cloud Engineer Flashcards
You are seeing a series of malicious data packets from IPs in a certain region. What can you use to protect your apps the best?
Cloud Armor
True or False: Some products are served outside of google
True
Google Cloud is PCI-DSS compliant. What does this mean for a customer?
They still need to ensure their application is compliant.
Default Encryption
Data at rest- customer has no access to keys control of key rotation
Cloud KMS
Customer can manage keys generated and stored by Google integrated with other cloud services
Cloud HSM
Customer can manage keys generted by Google and stored in a google owned and operated HSM
Customer Supplied Encrypt keys
Keys owned by customer and provided on each API call to be used ephemerally to access data
Private Hosted HSM
Select customers may use keys their own HSM in a Colo. (GOOGLE does not have any control of the HSM.)
CLOUD EKM
customer encrypts data-at-rest using a key residing outside of Google Cloud. Provide Platform for KAJ.
My application has structured relational data. What storage option should I consider if my application requires horizontal scalability?
Cloud Spanner
My application has structured non-relational data. What storage option should I consider if I don’t require mobile SDKS?
Cloud Datastore
My application has heavy read/write requirements, and my workload is analytics. What storage option should I consider for low-latency updates?
Cloud Bigtable
Your application requries fine-grained control for users to download individual objects in a bucket. What option should you use to secure your storage objects?
Access Control List (ACLs)
Which of the following buckets follows naming best practices?
037763b8-2b55-us-east
Cloud Spanner
combines the benefits of relational database structure with non-relational horizontal scale
VPC Network Types
Auto,custom, default
Auto Mode
-default network, one subnet per region, regional IP allocation, fixed /20 subnetwrok per reigon, expanable up to /16
Custom Mode
No default subnets created, full control of IP ranges, regional IP allocation, expandable to IP ranges you specify
You need to give IT contractors access to your Google Cloud account. Which of these would you recommend?
Cloud Identity Account
Quotas
-prevent runaway consumption in case of an error, -prevent billing spikes or surprises, - forces sizing consideration and periodic review
Labels
Attached to resources; vm, disk, snapshot, image (inventory, filter resources, in scripts, help analyze costs, run bulk operations)
Storage requirement; very fast reads, typical use case like storing session data. Which database is appropriate?
Memorystore