Reviewed 10 October 2026. Use the linked official exam guide for your exam version. These are condensed revision notes; the topic pages provide worked distinctions and more recall practice. Google’s 2026 guides use newer Gemini Enterprise Agent Platform names while some APIs and documentation still use Vertex AI.
Memory hook: Identity → boundary → data → evidence → obligations.
1. Configure access — 1.1–1.5
Cloud Identity/Workspace stores organizational users/groups; directory sync provisions identity attributes; SAML SSO delegates sign-in. Workforce Identity Federation serves people; Workload Identity Federation serves software. Protect Super Admin/emergency accounts, MFA/recovery and sessions. Offboarding must address group membership, delegated applications and active credentials.
Grant roles to groups/workloads at the narrowest practical hierarchy level. Allow policies grant; deny policies block supported permissions despite grants; principal access boundaries (PABs) constrain eligible resources for supported access checks. Organization policies constrain configurations. None of these should be confused with a firewall rule. Conditions can limit supported grants by context; Access Context Manager supplies context/access-level definitions.
Service accounts are both principals and manageable resources. A user allowed to attach or impersonate a powerful service account may gain its capabilities. roles/iam.serviceAccountUser and roles/iam.serviceAccountTokenCreator solve different delegation needs; actual data roles belong to the runtime principal. Prefer short-lived federation/impersonation over downloadable keys; restrict trust mappings, audiences and attributes. Privileged Access Manager supports time-bounded elevation; Policy Intelligence supports diagnosis and least-privilege review, subject to rare legitimate use.
2. Secure communications and boundaries — 2.1–2.3
| Control | What it protects / does not do |
|---|---|
| VPC/NGFW policy | Network flows; not application data authorization |
| Cloud Armor | Supported load-balanced application/edge traffic; not every arbitrary workload path |
| IAP / context-aware access | Supported user entry paths and contextual controls |
| Secure Web Proxy | Governed outbound web access; not address translation alone |
| VPC Service Controls | Supported managed-service data boundaries; complements IAM |
| Private Google Access / PSC / private services access | Different private API/service connectivity patterns; not interchangeable |
| HA VPN / Interconnect | Encrypted tunnels / private connectivity with explicit encryption design |
Shared VPC centralizes network ownership; peering does not automatically provide transit. Segment tiers and restrict ingress/egress/API exposure. Validate service-perimeter dry-run logs and required ingress/egress before enforcement. DNSSEC authenticates signed DNS data, not encryption; private DNS still needs authorized networks and correct forwarding. Certificate Authority Service issues private PKI certificates; Certificate Manager manages supported certificate deployment.
3. Protect data and AI — 3.1–3.3
Sensitive Data Protection identifies/classifies and de-identifies supported content. Masking, tokenization, pseudonymization and anonymization are different guarantees; removing names alone does not ensure anonymity. Use BigQuery row/column controls, Cloud Storage IAM/public access prevention and database privileges in the correct service layer. Instance metadata can expose configuration and workload tokens to code on a VM; never treat it as a general secret store.
Encryption at rest, TLS in transit and supported Confidential Computing in use address different states. Google-managed keys minimize key operations; CMEK adds customer lifecycle control; HSM uses hardware-backed operations; EKM integrates external key control. Separate key administrators from users, protect key availability and test restore dependencies. Rotation creates a new key version; it does not universally re-encrypt old data. Secret Manager stores secret values and versions; KMS performs key operations.
For AI, control dataset/model permissions, retrieval filters, notebook/runtime identities and tool scopes. Model Armor/content filters supplement external authorization. Protect against prompt injection, data exfiltration, model artifacts and unsafe actions; responsibility differs between self-managed infrastructure and managed platform offerings.
4. Secure operations — 4.1–4.2
Scan images/dependencies for CVEs, prioritize exploitable exposure, harden/patch and verify remediation. Provenance/attestations prove aspects of origin; Binary Authorization enforces configured deployment policy. Neither replaces vulnerability assessment or code review. Use policy/drift controls and SCC custom/posture modules for recurring misconfiguration.
Audit categories include Admin Activity, Data Access, System Event and Policy Denied. Admin Activity/System Event are always written; most Data Access requires explicit enablement, with BigQuery a notable default-enabled exception. Verify service support and permissions for private logs. Aggregate relevant logs with scoped sink-writer access, protected destinations/retention and separate evidence administrators. VPC Flow Logs are sampled metadata; Packet Mirroring copies packets; IDS detects supported network threats. SCC posture findings and SecOps investigations are complementary.
5. Compliance — 5.1
Map requirements to the complete workload: compute, stores, logs, backup, network, identities, operators and exports. Assured Workloads supports selected compliance controls; Access Transparency gives eligible provider-access visibility; Access Approval adds eligible approval workflows, with documented scope/exceptions. Residency is one part of sovereignty/compliance. Maintain evidence and customer responsibilities even when the provider holds a certification.
Traps to catch
- Private is not authorized; encrypted is not least-privileged; perimeter is not firewall.
- Disabling a key can break production and recovery. Rotating a password may not revoke every token.
- Detection without preserved telemetry and an owned response process does not complete security operations.
Last-pass self-check
1. An inherited grant still permits access after a project binding is removed. Why?
Removing one binding does not remove ancestor or other applicable grants; inspect effective policy and supported deny/boundary enforcement.
2. Which federation type serves an external CI job?
Workload Identity Federation; Workforce Identity Federation is for external workforce identities.
3. How does a service perimeter differ from a private endpoint?
The perimeter restricts supported data movement; the endpoint supplies a connectivity path. IAM remains necessary.
4. Can you assume all read access is in default audit logs?
No. Verify Data Access configuration and service behavior; most such logs require enablement, with exceptions such as BigQuery.
5. Why is key destruction a data-recovery decision?
Backups may still depend on that key; destroying it can make otherwise retained data irrecoverable.
Sources
- Official exam guide
- IAM policy types
- Service-account permissions
- Cloud Audit Logs
- VPC Service Controls
- Cloud KMS rotation
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · IAM, Service Accounts and Data Security
Memory hook: Grant the action to the actual caller at the narrowest scope.
Must remember
An IAM binding associates a principal with a role on a resource, optionally under conditions. Basic roles are broad; predefined roles are service-oriented; custom roles bundle supported permissions for specific needs. Inherited allow grants can broaden access; deny policies and organization constraints have distinct effects. Removing one narrow grant does not remove an inherited grant elsewhere.
A service account is both an identity used by workloads and a resource whose use can be controlled. Attaching/acting as a service account and creating short-lived impersonated credentials require different permissions. Grant API permissions to the runtime identity, not merely to the human who deployed it.
Prefer attached workload identity, service-account impersonation or Workload Identity Federation over downloaded long-lived keys where supported. External federation exchanges trusted external identity for controlled Google access. Protect audience, attribute mappings/conditions and role bindings; a permissive trust mapping can expose many unintended callers.
Use Secret Manager for secrets and Cloud KMS for encryption-key control. Default encryption does not mean everyone should read the data. Customer-managed keys introduce key IAM, location, rotation, availability and destruction considerations. Separation between key administrators and data users reduces excessive privilege.
VPC Service Controls creates supported service perimeters to reduce data exfiltration; it complements IAM rather than replacing it. Identity-Aware Proxy controls supported application/tunnel access. Audit logs identify activity under their service-specific categories/settings; enable required data-access visibility deliberately and protect the sink destination.
For permission denied, establish the real principal, resource project, required permission, inherited/conditional/deny policies and any perimeter/org-policy restriction. Granting Owner to “make it work” conceals the diagnosis and creates risk.
Review details
Service Account User (roles/iam.serviceAccountUser) includes acting as the service account for supported resource attachment. Service Account Token Creator (roles/iam.serviceAccountTokenCreator) supports generating impersonated credentials and supported signing operations. Granting attachment rights is not the same as giving the human direct access to every resource the account can read, but launching code as that account can be a privilege-escalation path.
Application Default Credentials searches supported credential locations; it is not an IAM role. Workforce federation serves external people, workload federation software. To diagnose a denied call, distinguish authentication failure, missing permission, inherited deny/boundary, organization policy and VPC Service Controls. Principal access boundaries constrain eligible resources for supported access; they do not grant permissions.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Application accesses a bucket | Grant the workload identity the necessary bucket role. |
| CI outside Google Cloud | Federated short-lived credentials with narrowly defined trust. |
| Reduce exfiltration through supported managed APIs | VPC Service Controls plus IAM and data controls. |
Traps
- Service-account use permission is not identical to the service account’s resource permissions.
- A VPC Service Controls perimeter does not replace IAM.
02 · VPCs, Subnets and Private Access
Memory hook: VPC is global; subnet is regional; permission is separate.
Must remember
A Google Cloud VPC network is global; its subnets are regional and can serve zones in that region. Custom-mode networks give deliberate address allocation. Plan nonoverlapping primary/secondary ranges for VMs, Pods and services. Supported subnet expansion increases address space; do not assume arbitrary shrinking is available.
Routes decide where packets go; firewall rules/policies decide whether eligible traffic is allowed. Stateful firewall behavior permits matching return traffic, but the route must still exist. Priority, direction, source/destination and target selection matter. Network tags and service-account targets select workloads under their respective rule models; labels used for inventory are not automatically firewall selectors.
Shared VPC centrally manages a network in a host project while service projects deploy authorized resources into it. VPC Network Peering connects networks privately under its route-exchange rules and is not transitive by default. It does not merge IAM policy or all DNS behavior.
Private Google Access lets eligible private-address workloads reach supported Google APIs under correct routing/DNS. Private Service Connect exposes supported services through private endpoints or related service-connectivity patterns. Private services access allocates peering-based connectivity for supported managed services; these similarly named mechanisms are not interchangeable.
Cloud NAT provides configured outbound address translation for eligible private resources without accepting arbitrary unsolicited inbound connections. It needs the relevant routing and regional configuration; it is not an HTTP proxy or a packet-forwarding VM you administer. Reserve static addresses only where stable identity/allowlisting requires them.
Diagnose source identity/address, subnet/range, route, firewall, DNS and destination listener separately. Private networking reduces exposure but does not grant API IAM permissions or database access.
Review details
A new VPC has implied deny ingress and allow egress rules at the lowest effective priority; explicit rules/policies can change the outcome. Lower numeric priority means higher priority within the applicable rule model, but hierarchical/network/VPC policy evaluation must be considered as a whole. The pre-created default network's explicit rules are not the behavior of every custom VPC.
Cloud NAT is regional and uses Cloud Router configuration without routing packets through a Cloud Router VM. NAT port exhaustion can break outbound connections even when the default route exists. Private Google Access also needs appropriate DNS/routes; merely removing a public IP is not a complete private-access design.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Central network across several projects | Shared VPC with controlled service-project attachment. |
| Private workloads need outbound Internet | Appropriate Cloud NAT and routes. |
| Consume supported service at a private endpoint | Private Service Connect. |
Traps
- VPC peering is not automatically transitive.
- A network label is not the same as a firewall network tag.
03 · Load Balancing, Hybrid Connectivity and DNS
Memory hook: Choose protocol, reach and failover scope.
Must remember
Choose load balancing by protocol, external/internal reach, proxy/passthrough behavior and regional/global availability. Application load balancers route HTTP/S; network load balancers serve supported transport-level needs. Backend services, health checks and firewall permissions must agree; a healthy VM does not imply a health-check path is allowed.
Global versus regional resources affect failover and traffic locality. Premium and Standard Network Service Tiers use different network paths and support different product combinations. Check the actual load-balancer type rather than assuming every configuration is global or supports every tier.
Cloud CDN caches eligible content at the edge; cache keys, TTLs and origin protection determine behavior. Cloud Armor applies supported edge/backend security policies. Neither removes the need for secure application authorization or correct cache separation between users.
HA VPN supplies encrypted hybrid tunnels; Cloud Interconnect provides private connectivity with dedicated/partner options. Encryption requirements must be addressed explicitly. Cloud Router manages dynamic BGP route exchange for supported connectivity; it is not itself the data-plane router carrying every packet. Plan redundancy on both provider and on-premises sides.
Cloud DNS public zones publish public records; private zones serve authorized networks. Forwarding and peering zones support hybrid and cross-network resolution patterns. Names resolving correctly does not establish packet reachability. Use split-horizon designs deliberately and avoid forwarding loops.
Reserve static internal/external IPs where a stable endpoint is required. Review health-check sources, firewall rules, backend serving ports, certificates, routing and DNS TTL during migrations. Switching a DNS record does not immediately expire every existing cache or connection.
Review details
For DNS, A/AAAA return IPv4/IPv6 addresses, CNAME aliases a name, MX chooses mail exchangers, TXT carries text data, and NS delegates authority. Public zone creation must be paired with registrar/parent delegation; private zones require authorized networks. DNSSEC authenticates signed answers but does not encrypt queries. TTL controls cache freshness, not a guarantee that every active client connection immediately changes.
For a load-balancer failure, test frontend reachability → selected URL map/backend service → backend health → health-check/data-plane firewall allowance → serving port/application. A proxy load balancer and a passthrough load balancer expose different source-connection behavior; select the precise product before designing source-IP controls.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Private on-premises connectivity | Interconnect with explicit resilience and encryption design. |
| Encrypted hybrid tunnel | HA VPN with redundant BGP/tunnel topology. |
| HTTP host/path routing | Suitable Application Load Balancer configuration. |
Traps
- Cloud Router exchanges routes; it is not the packet-forwarding appliance.
- Private connectivity does not automatically mean encrypted connectivity.
04 · Governance, Sharing and AI-Ready Data
Memory hook: Catalog describes; policy controls; lineage explains.
Must remember
An enterprise data platform needs ownership, discoverability, classification, lineage and quality rules, not just a storage bucket. Dataplex Universal Catalog helps organize metadata and governance across supported assets. Metadata access does not automatically grant data access. Assign accountable stewards and measure quality dimensions such as completeness, freshness, validity and uniqueness.
Separate development, test and production identities and datasets. Apply least privilege at organization/project/dataset/table scope as appropriate. Sensitive Data Protection discovers/classifies and can de-identify supported content; masking is not equivalent to irreversible anonymization. Keep residency constraints, retention, deletion and access evidence together.
BigQuery sharing, associated with the Analytics Hub name, distributes governed shared datasets without ordinary full-copy workflows. Publisher and subscriber permissions, refresh behavior and commercialization rules remain separate design decisions. An exported file may escape later centralized revocation, so sharing mechanisms affect control.
Prepare AI features with point-in-time correctness: a model must not learn information unavailable at prediction time. Fit preprocessing on training data and apply it consistently. Data leakage can produce impressive offline scores and poor production results. BigQuery ML enables supported model workflows using SQL; embeddings encode similarity for retrieval, not guaranteed factual truth.
For retrieval-augmented generation, preserve document provenance and permissions through chunking, embedding, indexing and retrieval. A vector search result must still be authorized for the requesting user. Evaluate retrieval quality and final answer quality separately; stale indexes, missing context and prompt injection require explicit defenses.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Discover and trace enterprise data | Catalog, owners, classification and lineage. |
| SQL-oriented supported ML | BigQuery ML. |
| Share governed analytics datasets | BigQuery sharing with publisher/subscriber access design. |
Traps
- A catalog entry is not a grant to read the underlying data.
- Removing names alone does not prove a dataset is anonymous.
05 · AI Platforms, Agents and Responsible Architecture
Memory hook: Ground the answer; constrain the action; measure both.
Must remember
Google's current Gemini Enterprise Agent Platform evolves Vertex AI capabilities into an integrated model/agent platform. Older course and API terminology may still say Vertex AI. Model Garden offers model choices; managed APIs, customization and custom training address different levels of control and effort. Choose a prebuilt API when its capability fits rather than training unnecessarily.
Model choice depends on quality, modality, latency, context, cost, data handling and deployment constraints. RAG retrieves external knowledge at request time; tuning changes model behavior/weights through supported training. Grounding can improve factual relevance but does not guarantee correctness or enforce authorization by itself.
Agent systems add planning, tools, memory and actions. Keep tool authority narrow, authenticate workload identities, validate inputs/outputs and gate high-impact operations. Treat retrieved documents and tool results as untrusted content. Model Armor and Sensitive Data Protection can contribute filtering and sensitive-data controls; application policy and evaluation remain necessary.
ML pipelines orchestrate repeatable data preparation, training, evaluation and deployment. Track datasets, features, experiments and artifacts to reproduce results. Separate training from evaluation data to avoid leakage; monitor production drift and quality. GPUs/TPUs and AI Hypercomputer infrastructure fit different training/serving requirements; expensive hardware alone does not solve bad data or inefficient inference.
Managed search/conversation, vision, document, image, video and audio APIs reduce implementation work for suitable tasks. Gemini Enterprise and NotebookLM-related capabilities support enterprise knowledge workflows under their actual access/governance model. Check supported data locations, quotas, retention and integration rather than assuming all products share one policy.
Evaluate task success, groundedness, safety, latency and cost on representative and adversarial cases. Human review belongs where incorrect output/action has high consequences. Version prompts, retrieval configuration, models and tools as production changes.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Answers need current private knowledge | Permission-aware RAG with evaluation and source grounding. |
| Need a known vision/document capability | Assess a managed API before custom training. |
| Agent can update business records | Scoped tools, authorization, validation and auditable approval boundaries. |
Traps
- RAG does not automatically prevent unauthorized document disclosure.
- An AI-generated infrastructure proposal still needs human/automated verification.
06 · Secure Build, Release and Platform Automation
Memory hook: Build once; attest it; promote the same artifact.
Must remember
Cloud Build executes builds/tests; Artifact Registry stores versioned artifacts; Cloud Deploy manages delivery to supported targets with releases, rollouts, approvals and promotion. Skaffold/Kustomize help render and deploy Kubernetes workloads. GitOps controllers reconcile declared state from version control; they still need trustworthy commits, restricted credentials and a recovery process.
Build once and promote an immutable digest through environments. Scanning identifies known vulnerabilities; provenance records origin and build process; signatures/attestations provide evidence; Binary Authorization can enforce configured deployment policy. SLSA describes supply-chain assurance levels. A clean vulnerability scan alone does not establish trusted provenance or absence of malicious logic.
Use short-lived workload federation for external automation where supported. Separate build, deploy and runtime identities; give each only needed permissions. Secret Manager stores secrets, Parameter Manager serves configuration use cases, and KMS manages cryptographic keys. Runtime secret injection avoids embedding credentials in images; build-time secrets can leak through layers, caches and logs.
Choose rolling, blue/green or canary release from capacity, reversibility and exposure needs. Define success metrics before shifting traffic, including latency/errors and business behavior. ML releases also need model/data quality and drift checks. Feature flags decouple code deployment from activation but create configuration/cleanup work. Database changes require backward-compatible migration if rollback to old code must work.
Bootstrap projects with reviewed Terraform/Infrastructure Manager or blueprints, remote state protection and policy checks. Config Connector manages supported resources through Kubernetes configuration; Helm packages Kubernetes resources. Separate production and temporary environments, enforce expiry/cleanup, and control fleet upgrades. Cloud Workstations offers managed developer environments; AI coding assistants still require review, tests and secret-handling discipline.
Review details
A useful release sequence is source review → repeatable build → unit/integration/security tests → digest and provenance → staging verification → approval where needed → progressive rollout → observed success or rollback. Configure trigger permissions and environment-specific identities as carefully as runtime IAM. Cloud Build logs and audit/deployment records establish which actor promoted which artifact.
Certificate Manager handles supported certificate-management needs, distinct from Secret Manager values and KMS key operations. Parameter Manager holds configuration. A GitOps controller continually reconciles desired state; manually patching production without changing its declared source can be reverted by the controller.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Reproducible promotion | Immutable artifact digest plus provenance. |
| Enforce trusted artifacts at deployment | Binary Authorization policy and attestations. |
| External CI without long-lived keys | Workload Identity Federation with scoped impersonation. |
Traps
- Cloud Build and Cloud Deploy have different responsibilities.
- Rolling back code cannot automatically undo an incompatible database change.
07 · Telemetry, Incident Diagnosis and FinOps
Memory hook: Metrics point; logs explain; traces connect; profiles locate cost.
Must remember
Collect platform and application telemetry with the Ops Agent, OpenTelemetry and supported integrations. Managed Service for Prometheus handles Prometheus-style metrics; Cloud Monitoring supports dashboards, alerts and SLO observation. Synthetic checks exercise a user journey externally. A server reporting healthy does not prove login and checkout work.
Use structured logs with severity, service, deployment version and trace correlation. Logs Explorer queries events; routing sinks send selected entries to destinations such as BigQuery, Pub/Sub or Cloud Storage. Exclusions/sampling reduce cost but can remove evidence. Protect audit/security logs and redact sensitive fields before export. Multi-project logging and metrics scopes need explicit IAM and ownership.
Distributed traces connect spans across services. Follow the critical path: downstream timeouts, repeated retries, lock contention or network hops may dominate a request. Profiles identify CPU/memory hot spots; high average CPU does not reveal which code path wastes it. Correlate a regression with a deployment before assuming infrastructure is undersized.
Alert on actionable user impact and rapid error-budget consumption. Route incidents to an owner with a runbook; avoid paging on every harmless transient. Stabilize by rollback, traffic drain or capacity increase as evidence supports, then investigate root causes. AI-assisted analysis is a hypothesis source, not authority to change production without verification.
FinOps joins engineering, finance and product decisions. Attribute costs by project/labels, remove idle capacity, rightsize requests, tune logs and data transfer, and select commitments for stable demand. Spot capacity suits interruption-tolerant work. Dynamic Workload Scheduler and reservations address specific scheduling/capacity needs. Compare cost per useful transaction/job, not only the cheapest VM hour.
Review details
Use the four golden signals—latency, traffic, errors and saturation—plus service-specific indicators. High-cardinality metric labels such as unbounded user IDs can increase cost and make analysis harder. Synthetic checks test an external path; they complement, rather than replace, real-user telemetry.
If observability is missing, trace the telemetry path itself: agent/exporter → credentials/network → ingestion → filter/exclusion → sink/destination → query/permissions. A logs-based metric does not automatically become a useful alert. FinOps recommendations are evidence to investigate; rare peaks and failure headroom may not be visible in a short observation window.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Requests slow across many services | Correlated distributed traces. |
| High CPU inside one process | A profiler plus application context. |
| Growing observability bill | Review retention, volume, cardinality, exclusions and sampling without losing required evidence. |
Traps
- An alert without an owner/runbook often creates noise.
- A recommendation is not evidence that a workload can tolerate its proposed reduction.
08 · Enterprise Identity and Privilege Boundaries
Memory hook: Workforce is people; workload is software; neither needs permanent keys.
Must remember
Cloud Identity/Workspace manages organizational users/groups. Directory synchronization brings supported directory identity data into cloud identity; federation connects authentication to a trusted external identity provider. Workforce Identity Federation serves external workforce identities; Workload Identity Federation serves software workloads. The similar names conceal different principals and use cases.
Protect super-administrator and break-glass access with tightly controlled recovery, phishing-resistant authentication where supported, monitoring and rehearsed procedures. Separate normal work from privileged sessions. Account creation, role changes and offboarding must propagate to groups, applications and active credentials. An SSO login proves identity, not entitlement to every project.
Use service-account impersonation or federation for short-lived credentials instead of exporting keys. Limit who can impersonate, attach or administer a powerful service account: those permissions can become a privilege-escalation path. Audit the actual principal and delegated chain. Rotate/revoke unavoidable keys and discover unused credentials.
IAM allow grants are inherited; applicable deny policies can block permissions despite an allow. IAM Conditions refine supported grants with attributes such as time/resource context. Organization policies constrain resource configuration rather than granting access. Custom constraints address supported requirements; a constraint is effective only for the resource/action to which it applies.
Privileged Access Manager supports controlled temporary elevation with configured approvals and auditability. Policy Intelligence tools help investigate and reduce excessive access; recommendations need validation against rare legitimate operations. Access Context Manager defines access levels/service-perimeter policy inputs; context signals complement identity rather than replacing it.
Review details
Principal access boundary policies determine resource eligibility for supported permissions; they do not grant access. Read effective access as the required allow together with applicable deny/boundary enforcement and separate service/org constraints. A condition on one role binding does not constrain a different inherited unconditional grant.
SAML federation exchanges identity assertions for sign-in; OAuth delegates authorized access; two-step verification adds authentication factors. These do not provision accounts or assign every application permission by themselves. Service-account key discovery, disablement and deletion must address dependent workloads and audit evidence; rotating a human password does not revoke an unrelated service-account key.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| External contractors use their existing IdP | Workforce federation, appropriate authorization and lifecycle controls. |
| CI job needs Google API credentials | Workload federation and scoped short-lived access. |
| Temporary production elevation | Privileged Access Manager with limited duration and approval policy. |
Traps
- Service-account impersonation permission can be as sensitive as the account itself.
- Organization policy does not grant API permissions.
09 · Service Perimeters, Key Control and Data Protection
Memory hook: IAM answers who; perimeter limits where data may cross.
Must remember
VPC Service Controls establishes boundaries around supported managed services to reduce data exfiltration risk. It complements IAM and VPC firewalls; it is not a general packet firewall. Model ingress/egress rules, access levels and supported services carefully, using dry-run evidence before enforcement to avoid breaking legitimate workflows.
Private Google Access, restricted Google API access and Private Service Connect serve different connectivity needs. Private connectivity does not automatically authorize data access. Cloud NAT supplies outbound address translation without unsolicited inbound connections. Shared VPC centralizes network ownership; peering connects supported VPC paths but does not create transitive connectivity automatically.
Use Cloud Armor for supported edge application protection, Cloud NGFW for supported network enforcement, IAP for identity-aware application/tunnel access, and Secure Web Proxy for governed outbound web access. Certificate Authority Service issues private certificates; Certificate Manager manages supported deployment of certificates. DNS policy and API endpoint restriction are also part of the security path.
Default encryption protects stored data; CMEK gives customer control over supported key use/lifecycle. Cloud HSM provides hardware-backed key operations and Cloud EKM integrates external key management. Revoking a key can stop applications and recovery, so availability and separation of duties matter. Confidential Computing protects supported processing environments; TLS addresses transit. Key rotation does not automatically re-encrypt every historical object with a new version.
Sensitive Data Protection classifies and de-identifies supported data. Secret Manager protects application secrets; KMS protects cryptographic key operations. For AI, restrict training/retrieval datasets, protect prompts/responses, evaluate malicious inputs and enforce authorization on tool actions. Model Armor and other filters are layers, not proof that an agent is safe to execute arbitrary instructions.
Review details
Metadata on a compute instance is not a safe general-purpose secret store. Code running on an instance may be able to obtain the attached identity's tokens; least-privileged attachment, metadata access protection and avoiding injected secrets reduce impact. Cloud Storage lifecycle affects retention/deletion; irreversible locks must be understood before enforcement.
Pseudonymization replaces identifiers and may allow re-identification; tokenization can preserve joinability through controlled mappings; masking changes displayed data; anonymization aims to prevent re-identification. Choose transformation and key/mapping access from the privacy requirement rather than calling every redacted dataset anonymous.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Reduce exfiltration from supported managed services | VPC Service Controls plus IAM. |
| Keep supported APIs reachable privately | Choose the appropriate Private Google Access/PSC endpoint model. |
| Customer-controlled cryptographic lifecycle | CMEK with deliberately selected software, HSM or external backing. |
Traps
- A service perimeter is not a substitute for IAM.
- Destroying a key may make retained backups permanently unreadable.
10 · Detection, Incident Evidence and Compliance
Memory hook: Posture finds exposure; telemetry finds activity; response limits harm.
Must remember
Security Command Center centralizes supported posture, vulnerability and threat findings. Security Health Analytics identifies misconfiguration; detectors and custom modules address specific risks. Cloud IDS inspects supported mirrored network traffic. VPC Flow Logs describe sampled flow metadata; they are not a full packet capture. Traffic mirroring has scope, volume and privacy consequences.
Cloud Audit Logs distinguish administrative activity and supported data-access activity. Check which logs are available/enabled, especially data access, and aggregate them to a protected destination with suitable retention. Separate the ability to administer workloads from the ability to erase evidence. Correlate identity, resource, timestamp and deployment context before declaring a finding a confirmed incident.
Harden GKE/Cloud Run workloads, restrict images, scan dependencies and enforce trusted deployment policies. Patch operating systems and dependencies according to exposure and exploitability. A vulnerability finding requires validation, prioritization, remediation and confirmation; a dashboard alone does not close the risk.
Contain incidents with proportionate controls: revoke compromised credentials, isolate workloads, preserve evidence and communicate through the response process. Record actions and timestamps. Changing resources before preserving volatile evidence can hinder investigation, while delaying containment can increase harm; follow the approved playbook and incident authority.
Assured Workloads provides supported compliance-oriented controls. Access Transparency provides visibility into eligible provider access; Access Approval adds approval workflows for eligible access. They are different controls with scope and exceptions. Residency, sovereignty, contractual commitments and audit evidence must be evaluated against the actual workload; a certified provider does not automatically certify the customer’s application.
Review details
Audit recall: Admin Activity records administration, Data Access records supported data reads/writes and related access, System Event records provider-driven resource changes, and Policy Denied records supported denials. Admin Activity/System Event are always written; most Data Access needs enablement, with BigQuery a notable default-enabled exception. Private data-access logs also need appropriate reader permissions.
An aggregated sink can route matching descendant-resource logs to a central destination, provided the sink writer is authorized. Protect sink configuration and destination retention independently from workload ownership. Confirm missing evidence was actually collected before drawing conclusions from an empty query.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Misconfigured cloud resources | SCC posture findings with ownership and remediation. |
| Investigate access to sensitive records | Relevant data-access audit logs and protected evidence. |
| Visibility versus approval of provider access | Access Transparency versus Access Approval. |
Traps
- Flow logs are not complete packet contents.
- Cloud provider compliance does not transfer all customer obligations.