Skip to main content

google-cloud · associate-cloud-engineer

GCP Associate Cloud Engineer

Study notes for the Google Cloud Associate Cloud Engineer certification, organized the way GCP concepts stack on each other - each section only depends on what came before it.

The exam

Format50-60 multiple choice / multiple select, no negative marking
Length2 hours (no breaks - plan bathroom time)
Fee$125 USD (renewal exam: $75, 1 hour, 20 questions)
Validity3 years
ResultPass/fail only, no score breakdown
GuideOfficial exam guide

The exam blueprint has four sections; every page here carries a chip tying it back to one of them.

§1 setting up the environment20%
§2 planning & implementing30%
§3 ensuring successful operation30%
§4 access & security20%
GotchaThe dominant question pattern

Most questions are mini-scenarios where several answers work but only one meets every stated constraint without over-engineering. Read twice, eliminate first.

How to use this section

  • First pass: read sections 10 → 60 in order; the ordering is the mental map.
  • Last-day revision: skim only the colored cards (gotchas, numbers, decisions) plus everything under Revision.

Official exam guide

Rendered from the official Google exam guide. An Associate Cloud Engineer deploys and secures applications, services, and infrastructure, monitors the operations of multiple projects, and maintains enterprise solutions to meet target performance metrics. They perform common platform-based tasks, supported by AI tooling, to maintain and scale deployed solutions on Google Cloud.

Section 1: Setting up a cloud solution environment (~20%)

1.1 Setting up cloud projects and accounts

  • Creating a resource hierarchy
  • Applying organizational policies to the resource hierarchy
  • Granting members Identity and Access Management (IAM) roles within a project
  • Managing users and groups in Cloud Identity (manually and automated)
  • Enabling APIs within projects
  • Provisioning and setting up products in Google Cloud Observability
  • Assessing quotas and requesting increases
  • Setting up standalone organizations
  • Setting up cloud networking
  • Verifying product availability across geographical locations (e.g., regions, zones)
  • Configuring Cloud Asset Inventory and using Gemini Cloud Assist to analyze resources
  • Configuring Workforce Identity Federation

1.2 Managing billing configuration

  • Creating one or more billing accounts
  • Linking projects to a billing account
  • Establishing billing budgets and alerts
  • Setting up billing exports

Section 2: Planning and implementing a cloud solution (~30%)

2.1 Planning and implementing compute resources

  • Selecting appropriate compute choices for a given workload (e.g., Compute Engine, Google Kubernetes Engine [GKE], Cloud Run, Cloud Run functions, Agent Runtime on Gemini Enterprise Agent Platform [formerly Vertex AI Agent Engine])
  • Launching a compute instance (e.g., availability policy, SSH keys)
  • Choosing the appropriate storage for Compute Engine (e.g., zonal Persistent Disk, regional Persistent Disk, Google Cloud Hyperdisk)
  • Creating an autoscaled managed instance group by using an instance template
  • Configuring OS Login
  • Configuring VM Manager
  • Using Spot VM instances and custom machine types
  • Installing and configuring the command-line interface (CLI) for Kubernetes (kubectl)
  • Deploying a GKE cluster with different configurations (e.g., GKE Autopilot, regional clusters, private clusters)
  • Deploying a containerized application to GKE
  • Deploying an application to serverless compute platforms, including for the processing of Google Cloud events (e.g., Pub/Sub events, Cloud Storage object change notification events, Eventarc)
  • Identifying whether to use GPUs or TPUs

2.2 Planning and implementing storage and data solutions

  • Choosing and deploying data products (e.g., Cloud SQL, BigQuery, Firestore, Spanner, Bigtable, AlloyDB, Dataflow, Pub/Sub, Google Cloud Managed Service for Apache Kafka, Memorystore)
  • Choosing and deploying storage products (e.g., Cloud Storage, Filestore, Google Cloud NetApp Volumes, Google Cloud Managed Lustre) and Cloud Storage options (e.g., Standard, Nearline, Coldline, Archive)
  • Loading data (e.g., command-line upload, load data from Cloud Storage, Storage Transfer Service)
  • Maintaining multi-region redundancy across data solutions

2.3 Planning and implementing networking resources

  • Creating a VPC with subnets (e.g., custom mode VPC, Shared VPC, VPC Network Peering)
  • Creating and applying VPC firewall rules and Cloud Next Generation Firewall (Cloud NGFW) policies with ingress and egress rules and attributes (e.g., action, source, destination, targets, protocols, ports)
  • Using Tags (e.g., secure Tags) and service accounts in Cloud NGFW policy rules
  • Establishing network connectivity (e.g., Cloud VPN, VPC Network Peering, Cloud Interconnect)
  • Choosing and deploying load balancers
  • Differentiating Network Service Tiers

2.4 Planning and implementing resources using tooling

  • Infrastructure as Code tooling (e.g., Fabric FAST, Config Connector, Terraform, Helm)
  • AI-assisted planning and implementation (e.g., Gemini CLI, Google Antigravity, Gemini Cloud Assist, Application Design Center)

Section 3: Ensuring the successful operation of a cloud solution (~30%)

3.1 Managing compute resources

  • Remotely connecting to a Compute Engine instance
  • Viewing current running Compute Engine instances
  • Working with snapshots and images (e.g., create, view, and delete images or snapshots; schedule a snapshot)
  • Viewing current running GKE cluster inventory (e.g., nodes, Pods, Services)
  • Configuring GKE to access Artifact Registry
  • Working with GKE node pools (e.g., add, edit, or remove a node pool; autoscaling node pool)
  • Working with Kubernetes resources (e.g., Pods, Services, StatefulSets)
  • Managing horizontal and vertical Pod autoscaling configurations
  • Managing GKE Autopilot Pod resource requests
  • Deploying new versions of a Cloud Run application
  • Adjusting application traffic splitting parameters (e.g., Cloud Run, Cloud Run functions, GKE)
  • Configuring autoscaling for a Cloud Run application
  • Attaching GPUs and TPUs
  • Deploying an agent to Agent Runtime on Gemini Enterprise Agent Platform (formerly Vertex AI Agent Engine)
  • Managing notebooks in Gemini Enterprise Agent Platform Workbench (formerly Vertex AI Workbench) and BigQuery
  • Managing developer environments (e.g., Cloud Workstations)

3.2 Managing storage and data solutions

  • Managing and securing objects in Cloud Storage buckets
  • Setting object lifecycle management policies for Cloud Storage buckets
  • Executing queries to retrieve data from data instances (e.g., Cloud SQL, BigQuery, Bigtable, Spanner, Firestore, AlloyDB)
  • Estimating costs of data storage resources
  • Backing up and restoring database instances (e.g., Cloud SQL, Firestore, Spanner, AlloyDB, Bigtable)
  • Reviewing job status (e.g., Dataflow, BigQuery)
  • Using Database Center to manage the Google Cloud database fleet
  • Configuring customer-managed encryption keys (CMEK)

3.3 Managing networking resources

  • Resizing a subnet's IPv4 address range
  • Reserving static external or internal IP addresses
  • Adding custom static routes in a VPC
  • Using Cloud DNS and Cloud NAT
  • Managing VPC firewall rules and Cloud NGFW policies

3.4 Monitoring and logging

  • Creating Cloud Monitoring alerts based on resource metrics
  • Creating and ingesting Cloud Monitoring custom metrics (e.g., from applications or logs)
  • Configuring audit logs (e.g., VPC Flow Logs, audit logs, firewall logs)
  • Exporting logs to external systems (e.g., on-premises, BigQuery)
  • Configuring log buckets, log analytics, and log routers
  • Viewing and filtering logs in Cloud Logging
  • Viewing specific log message details in Cloud Logging
  • Using cloud diagnostic tools (e.g., Cloud Trace, Cloud Profiler, Query Insights, index advisor) to investigate an application issue
  • Viewing the Personalized Service Health dashboard
  • Configuring and deploying Ops Agent
  • Deploying Google Cloud Managed Service for Prometheus
  • Using Gemini Cloud Assist for Cloud Monitoring
  • Using Active Assist to optimize resource utilization
  • Using Cloud Hub to monitor active events and application health data

Section 4: Configuring access and security (~20%)

4.1 Managing IAM

  • Viewing and creating IAM policies
  • Attaching roles and policy inheritance in the Organization hierarchy
  • Managing the various role types and defining custom IAM roles

4.2 Managing service accounts

  • Creating service accounts, including Google-managed service accounts
  • Using service accounts in IAM policies with minimum permissions
  • Assigning service accounts to resources
  • Managing IAM permissions of a service account
  • Managing service account impersonation
  • Creating and managing short-lived service account credentials
  • Using a Google Cloud service account with a GKE application
  • Provisioning Workload Identity Federation