
Explore Google Cloud certifications in a bundle, covering core services, storage, big data, machine learning, and networking, with labs and case studies to boost your cloud skills and opportunities.
Save time by consolidating basic Google Cloud concepts into one foundation course, covering commonalities across certifications and paths from cloud architect to machine learning engineer for mastery.
Explore Google Cloud platform certifications, from cloud engineer to machine learning engineer, detailing how each role provisions, designs, develops, secures, and operates cloud solutions across the software delivery lifecycle.
Course Structure
Learn how to obtain a completion certificate on Udemy by ensuring all checkboxes are checked and your progress is complete, then view or download the certificate and receive the email.
Explore Google Cloud Platform’s infrastructure as a service and platform as a service, covering compute engine, storage, databases, and global regions, zones, edge locations, free tier, and billing basics.
Explore Google Cloud Platform compute services, including Compute Engine, Kubernetes Engine, Cloud Run, App Engine, and Cloud Functions, plus API Gateway and Apigee for API management.
Learn how cloud identity and access management defines who can do what on which resources, with users, groups, roles, and service accounts, plus quotas and organization policy across the organization.
Learn how to create a free Google Cloud Platform account, claim $300 credit, set up the billing account, and monitor remaining credit as you explore paid services.
Explore the Google Cloud Platform console, navigate the dashboard, manage security and billing, and launch services from compute, App Engine, Cloud Functions, storage, and monitoring tools.
Explore Google Cloud's database and storage services, including Cloud SQL, Cloud Spanner, Cloud Bigtable for time-series workloads, Firestore, Cloud Storage, Memorystore, File Store, persistent disk, and AlloyDB for scalable data.
Explore Google Cloud Platform operations, including cloud logging and monitoring, dashboards and alerts, and tools like debugger, profiler, trace, and error reporting for app latency and reliability.
Explore google cloud platform network services, including vpc and subnet design across zones, firewall rules, routes, vpc peering, shared vpc, interconnect options, cloud vpn, and load balancers.
Get a high-level overview of cloud security, covering IAM permissions, data encryption at rest and in transit, confidential computing, Cloud KMS, Secrets Manager, web security scanner, and Cloud Armor.
Learn how to download, install, and initialize the Google Cloud SDK CLI, log in, and set a default project and compute zone (US West 1A), with gsutil and BigQuery utilities.
Explore Google Cloud Platform tools for managing applications, including Cloud Build for CI/CD, Cloud Scheduler for cron jobs, Cloud Task for workflows, Container Registry, Deployment Manager, and Identity Platform.
Gain a 10000-foot view of Google Cloud Platform by exploring core services across computing, networking, data and storage, and infrastructure management. Includes free-trial setup, regions and zones, and hands-on labs.
Explore Google Cloud compute services, including Compute Engine virtual machines, Container Engine for containers, App Engine as a platform, and Cloud Functions for event-driven workloads.
Explore Compute Engine in the Google Cloud Console, creating VM instances, managing disks, images, instance templates, and groups, while learning about networking, health checks, and marketplace options.
Create and configure a Google Cloud compute engine virtual machine from scratch or templates. Choose machine type, disks, networking, firewall, and security settings; learn startup scripts and encryption options.
Explore how to manage a compute engine instance: view status and networking, configure disks and SSH, monitor with logs, and adjust permissions on a running VM.
Explore the components and subsystems of Compute Engine, including console UI, disks and snapshots, container-optimized OS, IAM keys, labels, networks, and autoscaling with instance templates.
Understand Compute Engine storage options, including local SSD, zonal and regional persistent disks, cloud storage, and file storage. Learn to attach, resize, snapshot, and create boot and custom images.
Learn about container-optimized OS in Google Cloud, a chromium OS for container workloads with pre installed docker runtime, kernel locked down, automatic updates, and a locked-down default security posture.
Explore how labels identify Compute Engine resources and how tags enable firewall rules in Google Cloud VPC. Apply network tags to subnet firewalls and manage external and internal IP addresses.
Learn to use startup scripts in Google Cloud Compute Engine to install software, deploy applications, and run binaries at startup via inline, metadata, or cloud storage options.
Create and manage Google Cloud instance templates to define machine type, image, startup scripts, and metadata, then leverage managed instance groups for autoscaled, highly available VMs behind a load balancer.
Set quotas and limits to control cloud bills in public cloud environments by monitoring usage and restricting consumption, with easy access to view and adjust via the cloud console.
Explore Google Cloud spot instances, the preemptible VM, and learn how bidding, preemption signals, and 30-second shutdown scripts reduce costs by up to 90% while preserving data in persistent storage.
Explore sole tenancy in Google Cloud, reserving dedicated node hardware with node groups and node templates, configuring CPU, RAM, local SSDs, GPUs, auto scaling, and maintenance for secure, high-performance workloads.
Explore shielded VM with secure boot, Titan TPM, and integrity monitoring, and enable confidential computing on AMD EPYC processors to protect data in use in Google Cloud.
Explore Compute Engine as scalable virtual machines and contrast it with App Engine, GKE, and Cloud Function, highlighting infrastructure control, no-ops, and serverless options.
Explore Compute Engine machine types on Google Cloud Platform, comparing predefined standard, high memory, and shared core options with custom machine types, memory and vCPUs rules, and GPU restrictions.
Learn to configure Google Cloud Compute Engine, choosing general purpose or memory-optimized instances, from images and memory to disks, networking, and security options, including auto restart and delete protection.
Explore App Engine basics: deploy code or containers without provisioning infrastructure, enjoy auto scaling, traffic splitting, and a fully managed, open platform with standard and flexible environments.
Explore App Engine's hierarchy: applications, services, and versions, with traffic splitting and auto, manual, or basic scaling. Learn how instances run, set minimums, and view pricing and errors.
Learn how App Engine traffic splitting routes percentages to new app versions, gradually migrating traffic from v1 to v2 using IP-based, cookie-based, or random splits, and finalizing a complete switch.
Google App Engine standard environment, a predefined sandbox runtime with App Engine API support, secure isolation, and scalable instance classes with automatic, manual, or basic scaling.
Explore the App Engine deployment file app.yaml, covering standard and flexible environments, and configure service name, runtime, scaling, and resources like memory and disk size.
Learn to enable App Engine security scanner, configure firewall rules to allow or deny traffic, set up logging and debugging, and inspect source code for secure app deployment.
Explore App Engine pricing across standard and flexible environments, including instance class differences, resources billed (compute, memory, disk), cloud data store calls, search API, network traffic, and storage.
Learn how to prevent Google Cloud charges by disabling App Engine in settings, especially during the free trial, and manage default services by deleting extras so nothing runs.
Deploy your application on Google Cloud Platform using App Engine, offering standard and flexible environments, including docker containers, automatic scaling, and traffic splitting.
Discover how Google Cloud Kubernetes Engine manages containerized workloads with a master–worker architecture, API server, scheduler, and deployments, services, and ingress for scalable pod management.
Learn to practice Kubernetes locally with Minikube, create deployments and scale pods using kubectl, and compare with Google Cloud Platform's cloud features for certification readiness.
Learn to create a standard Kubernetes cluster on Google Cloud, compare autopilot vs standard, configure zones or regions, manage node pools with autoscaling, and understand blue-green upgrades.
Launch an autopilot cluster with default networking and container-managed workloads. Deploy nginx, expose it as a service, scale replicas, and rely on the cluster to manage pods, services, and autoscaling.
Explore Kubernetes pods, containers, and replica sets, with container-level resource requests and limits, and understand pod lifecycles and deployments. Also learn init containers and static pods that orchestrate pre-start tasks.
Learn how Kubernetes labels and selectors use key-value pairs to identify and select objects, apply node selectors, and perform equality-based and set-based filtering with kubectl.
Explore how Kubernetes uses namespaces to isolate objects within a cluster, apply resource quotas, and manage objects through YAML, deployments, jobs, and services.
Explore how Kubernetes manages the application lifecycle from design to production, highlighting pod priority and preemption, and deployment strategies such as rolling updates, canary, blue-green, and autoscaling.
Learn how to perform rolling updates in Kubernetes Engine, update deployment images, monitor rollout history, and rollback to a specific revision.
Understand ingress and ingress controller concepts for routing http and https from outside the cluster to internal services via routing rules and a load balancer, with nginx controller in GKE.
Explore Kubernetes networking, including container-to-container, pod-to-pod, and pod-to-service communication, plus external access, and learn how master and worker nodes, API server, and Flannel enable cross-node connectivity.
the kube scheduler filters feasible nodes for a pod by resource and port requirements, scores candidates with priorities like least requested and selector spread, and binds the best node.
Kubernetes engine monitors each node's health and replaces unresponsive nodes after about 10 minutes of health checks; enable node repair in standard engine settings to drain and recreate nodes.
Delete the cluster to remove all workloads and nodes, preventing ongoing charges for running nodes in your Google Cloud project.
Explore Kubernetes hybrid environments with Anthos, linking on-prem data centers to Google Cloud Platform, using service mesh, policy repository, and configuration management to manage clusters from a single console.
Kubernetes is an open-source container orchestration engine that runs on premises or public cloud, with Google Kubernetes Engine in Google Cloud Platform for cluster creation, deployments, services, and storage.
Explore cloud function basics, a serverless, event-driven compute service where you pay only for execution and can build APIs and microservices from event triggers.
Learn cloud run basics, see how it runs stateless containers in a fully managed, serverless environment, with auto scaling and per-request billing.
Discover how cloud run services operate as fully managed resources across regions or clusters, exposing unique endpoints and enabling domain mapping for your applications, with configurable service definitions and authorization.
Discover how Cloud Run revisions are immutable bundles containing environment variables, memory limits, and concurrency, and how deploying a new revision redirects traffic to the updated container.
Cloud Run spins up container instances based on concurrency; set a concurrency value (80 here) to trigger new instances, potentially up to 1000, with initial latency and cost considerations.
Explore Cloud Run fully managed features, including scale down to zero, up to 1000 containers, no provisioning, and pricing details like 2 million free requests per month.
Explore Cloud Run for Anthos, deploying containers as a service on clusters, choosing machine types, managing cluster capacity, and configuring custom domains with manual SSL.
Explore Cloud Run as a fully managed serverless platform for deploying containers, with configurable memory, timeout, region availability, and service accounts, plus access control for unauthorized invocations.
Explore software-defined load balancing in Google Cloud Platform, with global routing, health checks, and auto scaling directing traffic via intelligent routing to nearby healthy backend services.
Configure a load balancer in the cloud console by selecting network services, setting backend and frontend options, and attaching it to VMs or cloud storage, with future deep dives.
Explore how content aware load balancing routes video, images, and pages to dedicated backend services through front-end rules, with a default backend and load distribution algorithms that balance traffic.
Explore the load distribution algorithm for Google Cloud backends, configuring load distribution, balancing modes, capacity, and session affinity to distribute traffic across backend services.
Explore the various load balancers in Google Cloud Platform, including global external, regional external, and internal options, and learn how to choose the right type for single or multi-region deployments.
Configure a Google Cloud http load balancer by creating instance templates and groups, linking back-end services with Cloud DNS, and distributing traffic across Asia, Europe, and US West.
Explore global external load balancing with ssl proxy and dcp load balancers, leveraging intelligent routing and ssl offloading at the global layer 4 transport level to reduce backend load.
Learn how regional internal load balancers route traffic within a single region’s VPC, reducing latency. See how regional backend services and forwarding rules optimize internal traffic.
Demonstrate an optional http load balancer by creating regional instance templates and auto-scaling groups, configuring backend services and health checks, and routing traffic to the nearest region.
Demonstrates cleaning up a Google Cloud load balancer by deleting the load balancer, its instance template, the instance group, and all instances, then reviewing utilization.
Please download attached file and go through LAB Exercise.
Lab Exercise is not tracked systematically and optional. Make sure you mark this lecture complete for your course completion certificate gets generated.
Learn to configure Google Cloud load balancers, including global and regional options, SSL/TCP proxies, and UDP balancing, with backend routing, health checks, and security policies.
Explore Google Cloud data and storage services, including Cloud SQL, Cloud Spanner, Bigtable, BigQuery, Dataflow, and DataProc, with AI and natural language API.
Explore Cloud SQL, a fully managed Google Cloud database service for MySQL, PostgreSQL, and SQL Server, enabling OLTP workloads with high availability, backups, replication, and read replicas.
Explore Cloud SQL for PostgreSQL on Google Cloud Platform, a fully managed service with encryption at rest, SSL, multi-zone replication, and on-demand backups, import/export, and cloning.
Explore cloud sql performance parameters including cpu type, memory, network throughput, and storage type and size. Change machine types and storage configurations to affect throughput and IOPS.
Learn to manage Cloud SQL backups with automatic and on-demand options, set backup windows, initiate restores, and explore point-in-time restore and logging for reliability.
Explain how high availability in Cloud SQL uses synchronous replication between a master and a standby replica, enabling automatic failover across zones.
Discover how Cloud SQL read replicas offload read traffic to multiple replicas across zones, enabling read capacity despite vertical scaling limits, with the option to promote a replica to master.
Understand Cloud SQL pricing by selecting machine types and generations, with charges based on configuration and regional data egress. Delete unused instances to avoid ongoing costs.
Manage Google Cloud SQL as a scalable, hosted service by creating or migrating instances, configuring region, machine type, and storage; optimize performance and enable regional high-availability with seamless failover.
Explore alloydb, a PostgreSQL-like database from Google Cloud, offering horizontal scalability and fast oltp and olap workloads with a separate compute node and Colossus file system storage.
Discover how Cloud Spanner delivers a globally scalable, highly available relational database with strong consistency, multi-region replication, horizontal scaling, and interleaved tables for OLTP workloads.
Learn how to provision a Cloud Spanner instance, configure regional or multi-regional deployment with processing units and replicas, create databases and tables, and explore basic query performance and maintenance tasks.
Learn how Cloud Spanner performance scales with node count, regional versus multi-regional deployments, and how key distribution and hotspot avoidance drive query throughput and storage efficiency.
Explore Cloud Spanner’s interleaved tables by nesting albums and songs inside a single table, with up to seven levels of nesting and indexing on albums and related songs.
Explore Cloud Spanner identity and access management by mapping instance, database, and data permissions, including create, read, write, and session operations, and configuring instance settings.
Explore how Cloud Spanner delivers horizontally scalable, globally available data storage with regional configurations, data co-location, and pricing based on storage and nodes.
Learn google cloud storage basics with buckets and objects, scalable regional and multi-regional object storage for images, videos, and backups, featuring 11 nines durability and flexible access controls.
Create and configure cloud storage buckets, apply fine-grained or uniform access control, enable versioning and retention policies, and manage encryption and data protection in Google Cloud Storage.
Explore google cloud storage classes: standard, nearline, coldline, and archive, and learn to choose by access frequency, cost, and durability, while using lifecycle policies and auto class to optimize storage.
Explore cloud storage security concepts such as IAM policies, access control lists, signed urls and signed policy documents, and uniform bucket level access for project, bucket, and object permissions.
Learn how signed URLs grant time-limited access and permissions for objects, and how policy documents, conditions, and uniform public access prevent exposure while enforcing secure uploads and downloads.
Learn to configure object change notifications for a cloud storage bucket using cloud function triggers or pops up, covering event types such as finalized, metadata update, delete, and archive.
Explore how Google Cloud Storage uses default server-side encryption, optional customer-managed or client-side encryption with KMS or CSK, bucket locks for retention, and logging and monitoring for observability.
Explore Cloud Firestore in Datastore mode, featuring a strongly consistent storage layer, collection and document data model, and real-time updates for mobile and web clients.
Explore Cloud Firestore schema design by comparing relational models to Cloud Firestore collections and documents, mapping tables to collections, rows to documents, and fields to properties.
Explore cloud firestore pricing by comparing two mechanisms—document-based costs per 100,000 documents and storage costs per gigabyte per month—revealing that both databases share the same pricing structure.
Explore Cloud Firestore IAM concepts, permissions, and rules governing database operations such as insert, update, delete, get, export, and import, with roles like data store owner, app, reader, and writer.
Explore Cloud Firestore and Datastore as document storage on Google Cloud Platform, enabling Mongo-like storage with documents, queries, and index creation for efficient data retrieval.
Learn the fundamentals of Cloud Bigtable schema design, including single-index tables, row-level atomicity, and storing an entity in a single row with related data in adjacent rows.
Explore Cloud Bigtable performance factors by adjusting table nodes and disk types (SSD vs HDD), and how replication and load balancing affect throughput and query performance.
Understand how a Cloud Bigtable application profile defines how an instance handles incoming requests. Explore single-cluster routing vs multi-cluster routing and how single-row transactions and failover work.
Understand Cloud Bigtable quotas and limits, distinguishing soft limits from hard limits. Apply recommended sizes for column families, qualifiers, and cell values, and respect per-table and per-cluster constraints.
Explore how cloud Bigtable pricing varies with configuration, including node count, region, storage, and networking costs for development clusters.
Explore cloud iam for bigtable, outlining instance and cluster permissions, data-related admin permissions, and customizable access rules, including bigtable administrator, readers, and writers.
Explore big data solutions on google cloud platform, including cloud spanner, bigtable, datastore, cloud storage, cloud query, data flow, data lab, data catalogue, data fusion, data prep, and composer.
Explore BigQuery, Google's fully managed analytics data warehouse. Create datasets and tables, load data, and run fast per query analytics with automatic partitioning and no hardware provisioning.
Discover best practices for BigQuery query performance, data sources, and cost control, optimize bytes read, pass, and output, use partitioning, previews, storage strategy, and explore public datasets.
Learn how Cloud BigQuery uses IAM to control access with dataset roles (reader, writer, owner) and project-level permissions, enabling you to create, delete, and run jobs without managing hardware.
Explore Cloud BigQuery pricing with slot-based capacity, flat-rate options, and pre-run query estimation, and learn to use the bq command line to create datasets, tables, and run SQL.
Explore how Google Cloud BigQuery powers data warehousing and analytics by ingesting data from diverse sources, creating datasets, databases, and tables, and optimizing queries to control storage and query costs.
Launch and manage Hadoop and Spark clusters on Google Cloud Platform with Dataproc, using automatic cluster management, flexible machine types, persistent disks, and integrated storage for cost-efficient data processing.
Learn to enable the component gateway, adjust image and spark versions, and select optional components—Anaconda, Jupyter, Druid, Presto, and Zookeeper—to customize cloud dataproc clusters; these features install only when chosen.
Explore Cloud Dataproc storage options, including cloud storage buckets for backups, persistent disks for network storage, and local ssds, with implications that data cannot be recovered if the node fails.
Learn how to submit Google Cloud Dataproc jobs on a West 1 cluster using a jar and main class, run Spark and Presto jobs, and understand Dataproc versus Dataflow jobs.
Learn to design DAG-based Cloud Dataproc workflows that manage job dependencies, automate cluster lifecycles, and deploy template-driven pipelines using gcloud and parameterization.
Explore quotas and limits for Google Cloud Dataproc, including per-minute quotas: 400 total operation requests, 200 cluster operations, and 7,500 get job requests per minute, with free trial constraints.
Learn cloud dataproc pricing and how it scales with compute engine configurations, with pricing and CPI margins, plus using gcloud to manage dataproc domains: clusters, operation, workflow template, and jobs.
Delete the Cloud Dataproc cluster in Google Cloud Platform to save your 300 dollars, freeing all computing resources and completing the cleanup reminder before moving to the next service.
Learn how to launch and configure a Google Cloud Dataproc cluster with master and worker nodes, manage networks and staging on Cloud Storage, and design workflows for batch jobs.
Discover Cloud Dataflow, a managed Apache Beam service on Google Cloud for streaming and batch pipelines, enabling auto scaling and unified programming across fraud detection, analytics, and personalized user experience.
Compare cloud dataflow and cloud dataproc, showing dataflow's unified batch and streaming pipelines and dataproc's Hadoop and Spark clusters for existing ecosystems and notebooks.
Explore Google Cloud Dataflow quotas and limits, including per-minute requests, 1000 worker cap, project and organization concurrency, and templates for Pub/Sub, BigQuery, and Cloud Spanner to text files.
Assign job execution and control service accounts for Cloud Dataflow, granting access to cloud resources like Cloud Storage, Cloud Spanner, and Pub/Sub, and define roles for operators, developers, and administrators.
Explore cloud dataflow pricing, including per-second billing for batch and streaming jobs. Learn how memory, storage, and data processed costs depend on actual resource usage.
Explore how Google Cloud Dataflow enables building and running pipelines for batch and streaming data, from templates and Pub/Sub sources to datasets and Cloud Console jobs.
Discover how cloud pub/sub enables real-time streaming by connecting publishers, topics, and subscribers. It provides at-least-once delivery, exactly-once processing, and a managed open architecture with data plane and control plane.
Learn real-time messaging with cloud Pub/Sub by creating topics and subscriptions, publishing and pulling messages, and configuring acknowledgments, retention, and snapshots.
Explore data with Google Cloud Data Lab and Data Studio, connect to BigQuery, run notebooks in a VM, and use Python and machine learning for visualization and analysis.
Learn how Google Cloud Platform uses VPC networks, subnets, routing tables, firewall rules, and DNS to isolate resources, connect data centers, and manage networking services such as a load balancer.
Explore how VPC, subnets, and firewall rules secure isolated networks, and connect on premise data centers to cloud via interconnect and VPN, using DNS, load balancing, and caching.
Google Cloud VPC is a global, software-defined private network that spans regions and zones, enabling private resource communication, subnetting, firewall rules, routes, peering, and flow logs.
Explore the three vpc types on google cloud: default auto mode with prebuilt subnets and firewall rules, and custom vpc with user-defined subnets and ip ranges.
Manage projects as containers for cloud resources and use the default VPC, with up to five networks per project; for more networks, create another project and account for egress charges.
Understand Google Cloud VPC subnetworks, assign internal IP addresses to resources, and enforce firewall rules across production, development, and testing networks in regions and zones.
Allocate external IP addresses for Google Cloud VPC to enable VM access from outside the network, noting that unattached IPs incur charges.
Learn how cloud VPC firewall rules control ingress and egress traffic using IP ranges, protocols, ports, target tags, and priorities to allow or deny connections.
Learn how to set up a shared VPC with a host project and guest projects, manage network and security roles, and enforce permissions across an organization.
Explore vpc peering to connect networks inside or across projects, enabling vm-to-vm communication via pre-programmed routes while enforcing exclusive ip ranges and quotas for up to 25 direct peer networks.
Review Google Cloud VPC quotas and limits, including extendable quotas and a hard cap of 1000 instances per network. Learn about subnet limits, per-network constraints, and shared VPC attachment rules.
Understand cloud VPC flow logs that capture network traffic for monitoring, forensics, and real-time security analysis, and export logs to supported destinations.
Set up a bastion host to securely access internal servers, removing external IP exposure and connecting through an internal IP or DNS name during maintenance.
Learn how to use a bastion host to access a private vm by removing external ip, connecting via internal ip, and configuring virtual networking, interconnect, vpn, dns, and cloud seeding.
Enable host isolation by using a mapping gateway with IP forwarding to access an internal instance across networks, while applying firewall rules to restrict traffic and maintain security.
Learn vpc pricing basics: no charge to create a network, but traffic egress incurs costs; compare standard versus premium tier and their latency implications for regional traffic.
Explore cloud vpn and hybrid connectivity to securely extend your data center to Google Cloud, compare cloud interconnect and peering, and optimize egress costs.
Learn how cloud router enables dynamic routing between your data center and Google Cloud by exchanging routing information via BGP, replacing manual static routes.
Master cloud interconnect options to link your on-premises data center with Google Cloud Platform, including dedicated interconnect and partner interconnect, to access Google services and G Suite from on premises.
Learn how Cloud CDN uses Google's global fiber network and 80 PoP locations to deliver web content with low latency, SSL, and cache-driven efficiency.
Learn how Google Cloud DNS delivers scalable, high-availability domain name resolution via a global network, with programmable management of zones and record sets, low latency, and clear pricing.
Configure DNS to register a domain, set name servers, and map the domain to a load balancer and cloud storage bucket, illustrating DNS propagation.
Learn how Stackdriver applications provide multi-cloud monitoring, logging, and error reporting across GCP and AWS, with health checks, dashboards, log search, and latency tracing.
Learn to manage stackdriver applications by centralizing log entries from many sources, exporting to sinks, and choosing batch or near real-time delivery via Pub/Sub and cloud storage.
Learn Stackdriver Logging, a scalable multi-cloud log management service for storing, analyzing, searching, alerting, and exporting logs to Cloud Storage, Pub/Sub, or BigQuery.
Identify and monitor real-time application errors with Stackdriver error reporting, configure alerts, and analyze stack traces from the dashboard and mobile application.
Analyze end-to-end latency with Stackdriver trace to detect bottlenecks and performance issues. Collect near real-time latency data from App Engine and load balancer using the Google Cloud SDK.
Enable production debugging with Stackdriver Debug to inspect live code, add log points, and monitor logs and performance without redeploying.
Explore cloud identity and access management on the Google Cloud platform, from primitive access rules to fine-grained service accounts, and brush up on advanced concepts essential for security engineers.
Explore Cloud IAM basics, including identity and access management, primitive and fine-grained roles, organization policies, and audit trails that govern access across resources from organization to project.
Discover how Cloud IAM roles bundle permissions into primitive, predefined, and custom types, attach roles to users to grant access, and mix roles with permissions for fine-grained control.
Learn how Google Cloud IAM policies define resource-level access by binding roles to members, with IAM conditions enabling temporary access based on location and agent types.
Learn how service accounts enable secure app-to-app authentication in Google Cloud, enforce least privilege, and manage keys—Google managed vs user managed—and how to rotate and impersonate safely.
Explore why service account key rotation reduces leakage risk, compare push and pull models, and learn to use iam apis to create, upload, and manage short-lived credentials and impersonation.
Enable temporary access with short lived credentials and service account impersonation. They allow access without sharing keys to Google Cloud resources, using id tokens and JWTs.
Enforce organization-wide restrictions on service accounts and key creation, audit using IAM, delete unused keys, and apply least privilege with short-lived permissions to reduce impersonation risk.
Explore how cloud identity acts as a central identity platform for corporate, customer, and service identities, enabling centralized management and unified access across Google Workspace, Google Cloud, and third-party apps.
Learn how one-way gcds sync transfers on-prem ldap identities, including users, groups, and attributes, into cloud identity, with setup, testing, and best practices.
Understand how Google Cloud audit logs capture admin activity, data access, and system events. Learn how to enable, view, and export logs to BigQuery or Cloud Storage.
Learn how Cloud KMS enables encryption key management for Google Cloud services, including default encryption, customer supplied keys, and automated rotation, with IAM integration and Cloud Audit Logging.
Use the cloud security scanner to automatically scan App Engine and web apps for vulnerabilities. It detects flaws like flash injection, mixed content, and insecure JavaScript libraries.
Explore the Google Cloud source code repository on Google Cloud Platform to host unlimited private repositories, push and clone code, deploy apps, and debug with code search and GitHub integration.
Discover how the Google cloud container registry securely stores docker images, enables private hosting, automatic build and deploy, and image scanning for apps deployed on app engine.
Explore cloud build configuration files to define steps, docker builds, and deployment to cloud run, including environment variables, entry points, artifacts, secrets, and optional parameters.
Connect a repository, create a cloud build trigger, and deploy automated continuous integration pipelines that build docker containers and deploy to cloud run as changes push to branches or tags.
Explore a simple cloud build demo that builds a container from a Dockerfile, pushes to container registry, and runs on Cloud Run, with troubleshooting and region setup.
Demonstrate setting up a cloud build pipeline that uses a source code repository to trigger builds, create a container, push to the container registry, and deploy to Cloud Run.
Configure cloud build cd demo by creating a repository trigger, building a docker image, pushing to the container registry, and deploying to Cloud Run.
Explore cloud tasks in Google Cloud: leverage App Engine to distribute work via task queues, enabling synchronous, scalable, fully managed task execution with guaranteed delivery and a dashboard and CLI.
Create and manage cron-style tasks in Google Cloud using Cloud Scheduler, a fully managed service with Unix cron format, supporting App Engine and HTTP endpoints, time zones, and detailed logging.
Use deployment manager to automate cloud resource provisioning on Google Cloud Platform with infrastructure-as-code templates, configuration files, and VM instances.
Explore Google Cloud API management, featuring Apigee and Cloud Endpoints. Learn how to expose internal department APIs to external applications with discovery, contracts, security, monetization, and analytics.
Explore Apigee API management by creating proxy APIs, deploying to test and production, and applying shared flows and policies for spike arrest, quota, validation, and caching.
Explore Google Cloud developer tools and Eclipse integration, install the Google Cloud plugin via Eclipse Marketplace, and configure App Engine components to run and deploy apps locally with gcloud.
Configure IntelliJ with the Google App Engine plugin, set up the App Engine and Cloud SDKs, and create a new project using the guest book and opinion skeleton archetypes.
Explore the associate cloud engineer certification syllabus, from setting up the cloud environment to practicing services via labs, demos, and questions to build confidence.
Explore the associate cloud engineer syllabus and exam structure, a two-hour exam with 50 questions, covering cloud setup, deployment, IAM and security, billing, and compute resources like App Engine.
Develop exam-focused strategies for Google Cloud certifications by provisioning and managing cloud resources, monitoring production apps, and practicing sample questions to pass the exam.
Review the cloud certification syllabus and recap covered topics: setup cloud environment, plan and configure, deploy and implement, and ensure operation with secure access.
Set up a cloud solution environment by creating a project and account, managing users and APIs, provisioning strike driver workspaces, and configuring billing, budgets, alerts, and the command line interface.
Set up the Google Cloud environment by creating and managing projects, linking billing and accounts, enabling APIs and services, and configuring quotas within an organization hierarchy.
Configure budgets and alerts for billing accounts with thresholds at 50%, 90%, and 100%, then create service accounts with IAM roles to enforce quotas via console, CLI, and API libraries.
Explore planning and configuring a cloud solution on Google Cloud Platform by examining compute resources, data storage options, and network resources, using pricing calculator insights for budgeting and security.
Plan and estimate costs for GCP products using the pricing calculator, exploring discounts and sustained-use options for compute engine instances.
2.2 Planning and configuring compute resources. Considerations include:
Selecting appropriate compute choices for a given workload (e.g., Compute Engine, Kubernetes Engine, App Engine).
Using preemptible VMs and custom machine types as appropriate.
Explore the Google Cloud pricing calculator to estimate costs for Compute Engine, preemptible instances, storage, Cloud SQL, including discounts, free tiers, and sustained use.
Learn to estimate costs with the Google Cloud pricing calculator, exploring Compute Engine configurations, Cloud SQL, sustained use discounts, free tiers, and options like preemptible instances.
Learn to plan and configure cloud solutions using the pricing calculator, compute, storage, and network resources, while comparing services like Cloud SQL and Hadoop and exploring security and access controls.
4.1 Managing Compute Engine resources. Tasks include:
Managing a single VM instance (e.g., start, stop, edit configuration, or delete an instance).
SSH/RDP to the instance.
Attaching a GPU to a new instance and installing CUDA libraries.
Viewing current running VM Inventory (instance IDs, details).
Working with snapshots (e.g., create a snapshot from a VM, view snapshots, delete a snapshot).
Working with Images (e.g., create an image from a VM or a snapshot, view images, delete an image).
Working with Instance Groups (e.g., set auto scaling parameters, assign instance template, create an instance template, remove instance group).
Working with management interfaces (e.g., Cloud Console, Cloud Shell, GCloud SDK).
4.2 Managing Kubernetes Engine resources. Tasks include:
Viewing current running cluster inventory (nodes, pods, services).
Browsing the container image repository and viewing container image details.
Working with nodes (e.g., add, edit, or remove a node).
Working with pods (e.g., add, edit, or remove pods).
Working with services (e.g., add, edit, or remove a service).
Working with management interfaces (e.g., Cloud Console, Cloud Shell, Cloud SDK).
4.3 Managing App Engine resources. Tasks include:
Adjusting application traffic splitting parameters.
Setting scaling parameters for autoscaling instances.
Working with management interfaces (e.g., Cloud Console, Cloud Shell, Cloud SDK).
4.4 Managing data solutions. Tasks include:
Executing queries to retrieve data from data instances (e.g., Cloud SQL, BigQuery, Cloud Spanner, Cloud Datastore, Cloud Bigtable, Cloud Dataproc).
Estimating costs of a BigQuery query.
Backing up and restoring data instances (e.g., Cloud SQL, Cloud Datastore, Cloud Dataproc).
Reviewing job status in Cloud Dataproc or BigQuery
Moving objects between Cloud Storage buckets.
Converting Cloud Storage buckets between storage classes.
Setting object lifecycle management policies for Cloud Storage buckets.
Working with management interfaces (e.g., Cloud Console, Cloud Shell, Cloud SDK).
4.5 Managing networking resources. Tasks include:
Adding a subnet to an existing VPC.
Expanding a CIDR block subnet to have more IP addresses.
Reserving static external or internal IP addresses.
Working with management interfaces (e.g., Cloud Console, Cloud Shell, Cloud SDK).
4.6 Monitoring and logging. Tasks include:
Creating Stackdriver alerts based on resource metrics.
Creating Stackdriver custom metrics.
Configuring log sinks to export logs to external systems (e.g., on premises or BigQuery).
Viewing and filtering logs in Stackdriver.
Viewing specific log message details in Stackdriver.
Using cloud diagnostics to research an application issue (e.g., viewing Cloud Trace data, using Cloud Debug to view an application point-in-time).
Viewing Google Cloud Platform status.
Working with management interfaces (e.g., Cloud Console, Cloud Shell, Cloud SDK).
5. Configuring access and security
5.1 Managing Identity and Access Management (IAM). Tasks include:
Viewing account IAM assignments.
Assigning IAM roles to accounts or Google Groups.
Defining custom IAM roles.
5.2 Managing service accounts. Tasks include:
Managing service accounts with limited scopes.
Assigning a service account to VM instances.
Granting access to a service account in another project.
5.3 Viewing audit logs for project and managed services.
5.1 Managing Identity and Access Management (IAM). Tasks include:
Viewing account IAM assignments.
Assigning IAM roles to accounts or Google Groups.
Defining custom IAM roles.
5.2 Managing service accounts. Tasks include:
Managing service accounts with limited scopes.
Assigning a service account to VM instances.
Granting access to a service account in another project.
View and manage audit logs for a project and its managed services, including admin activity, system events, and data access logs, with Stackdriver logging, per-service defaults, and BigQuery exports.
Master the professional cloud developer certification by learning how to deploy and develop applications, leverage cloud integrations and ready-made services, and manage services across cloud platforms for Google cloud certification.
Discover the professional cloud developer certification details, including the exam blueprint and registration fee, and master designing, deploying, integrating, and monitoring scalable cloud apps on Google Cloud Platform.
Develop exam strategy by mastering Google Cloud Platform services and deploying apps on App Engine and Compute Engine. Utilize Cloud Build, Cloud Run, and pricing insight for integration and performance.
Explore a local community app case study, its global expansion challenges, and how to design scalable, compliant cloud solutions on Google Cloud Platform with API management and analytics.
Explore the professional cloud developer syllabus and its mapping to certifications, then learn to design scalable cloud data applications and build, test, deploy, and integrate apps on Google Cloud Platform.
Explore how to design highly scalable, available, and reliable cloud-native apps, covering API design, secure deployments, data storage options, and multi-zone orchestration in cloud and datacenter contexts.
1.1 Designing performant applications and APIs. Considerations include:
Infrastructure as a Service vs. Container as a Service vs. Platform as a Service (e.g., autoscaling implications)
Portability vs. platform-specific design
Evaluating different services and technologies
Operating system versions and base runtimes of services
Geographic distribution of Google Cloud services
Microservices
Defining a key structure for high write applications using Cloud Storage, Cloud Bigtable, Cloud Spanner, or Cloud SQL
Session management
Deploying and securing an API with cloud endpoints
Loosely coupled applications using asynchronous Cloud Pub/Sub events
Health checks
Google-recommended practices and documentation
Compare infrastructure as a service, container as a service, and platform as a service, illustrating how cloud providers manage hardware, runtimes, and auto scaling to deploy and scale applications.
Explore portability and platform-specific design across development, test, and production environments, and learn how containers and configuration strategies reduce dependencies while guiding service choices.
Explore how Google Cloud Platform uses regions and zones and a private fiber network to deploy apps near customers, reduce latency, and compare premium versus standard networks and egress costs.
Learn to design microservices with an API proxy, using cloud endpoint to secure backend resources, enable logging, analytics, and monetization.
Design performant microservice APIs by filtering response attributes and using GraphQL to reduce payload, minimizing API management load and improving network efficiency.
Designing performant apps with database keys such as primary keys and index keys, using Cloud Spanner and Cloud Bigtable concepts on Google Cloud Platform.
Design session persistence by maintaining a user's login state across sessions with persistent storage. Use data store, Bigtable, Cloud Datastore, or memory cache to balance persistence and performance.
Explore how loosely coupled apps leverage Cloud Pub/Sub as a managed messaging gateway. It scales automatically, handling publishers and subscribers and routing messages to compute and analytics services like BigQuery.
Configure health checks on the load balancer to verify backend instances' health, using port 80 tcp probes every 30 seconds and an unhealthy threshold to stop routing to unhealthy instances.
Learn Google’s best practices for enterprise app design, covering project setup, identity and access management, networking, VPC, and firewall rules, plus logs and audit trails.
1.2 Designing secure applications. Considerations include:
Applicable regulatory requirements and legislation
Security mechanisms that protect services and resources
Storing and rotating secrets
IAM roles for users/groups/service accounts
HTTPs certificates
Google-recommended practices and documentation
Already Covered as Part of Foundation.
1.3 Managing application data. Tasks include:
Defining database schemas for Google-managed databases (e.g., Cloud Datastore, Cloud Spanner, Cloud Bigtable, BigQuery)
Choosing data storage options based on use case considerations, such as:
Cloud Storage signed URLs for user-uploaded content
Using Cloud Storage to run a static website
Structured vs. unstructured data
ACID transactions vs. analytics processing
Data volume
Frequency of data access in Cloud Storage
Working with data ingestion systems (e.g., Cloud Pub/Sub, Storage Transfer Service)
Following Google-recommended practices and documentation
1.4 Re-architecting applications from local services to Google Cloud Platform. Tasks include:
Using managed services
Using the strangler pattern for migration
Google-recommended practices and documentation
Set up your development environment with Google Cloud libraries, then build and test applications using a continuous integration pipeline, performance testing, agile coding, and monitoring and logging.
2.1 Setting up your development environment. Considerations include:
Emulating GCP services for local application development
Creating GCP projects
Configure budgets and alerts for your billing account to monitor costs and thresholds. Manage service accounts and permissions with identity and access management to control access to resources.
2.2 Building a continuous integration pipeline. Considerations include:
Creating a Cloud Source Repository and committing code to it
Creating container images from code
Developing unit tests for all code written
Developing an integration pipeline using services (e.g., Cloud Build, Container Registry) to deploy the application to the target environment (e.g., development, test, staging)
Reviewing test results of continuous integration pipeline
2.3 Testing. Considerations include:
Performance testing
Integration testing
Load testing
2.4 Writing code. Considerations include:
Algorithm design
Modern application patterns
Efficiency
Agile methodology
Deploy applications across compute engine, app engine, and cloud functions, and provision data and networking resources with Deployment Manager while managing service accounts, reinforced by demos and theory.
3.1 Implementing appropriate deployment strategies based on the target compute environment (Compute Engine, Google Kubernetes Engine, App Engine). Strategies include:
Blue/green deployments
Traffic-splitting deployments
Rolling deployments
Canary deployments
3.2 Deploying applications and services on Compute Engine. Tasks include:
Launching a compute instance using GCP Console and Cloud SDK (gcloud) (e.g., assign disks, availability policy, SSH keys)
Moving a persistent disk to different VM
Creating an autoscaled managed instance group using an instance template
Generating/uploading a custom SSH key for instances
Configuring a VM for Stackdriver monitoring and logging
Creating an instance with a startup script that installs software
Creating custom metadata tags
Creating a load balancer for Compute Engine instances
3.3 Deploying applications and services on Google Kubernetes Engine. Tasks include:
Deploying a GKE cluster
Deploying a containerized application to GKE
Configuring GKE application monitoring and logging
Creating a load balancer for GKE instances
Building a container image using Cloud Build
3.4 Deploying an application to App Engine. Considerations include:
Scaling configuration
Versions
Traffic splitting
Blue/green deployment
3.7 Deploying and implementing networking resources. Tasks include:
Creating an auto mode VPC with subnets
Creating ingress and egress firewall rules for a VPC (e.g., IP subnets, Tags, Service accounts)
Setting up a domain using Cloud DNS
3.9 Managing Service accounts. Tasks include:
Creating a service account with a minimum number of scopes required
Downloading and using a service account private key file
Explore integrating Google Cloud Platform services for data and storage, including persistent storage, databases, and file storage, and connect apps to compute services and cloud APIs.
4.1 Integrating an application with Data and Storage services. Tasks include:
Enabling BigQuery and setting permissions on a dataset
Writing an SQL query to retrieve data from relational databases
Analyzing data using BigQuery
Fetching data from various databases
Enabling Cloud SQL and configuring an instance
Connecting to a Cloud SQL instance
Enabling Cloud Spanner and configuring an instance
Creating an application that uses Cloud Spanner
Configuring a Cloud Pub/Sub push subscription to call an endpoint
Connecting to and running a CloudSQL query
Storing and retrieving objects from Google Storage
Publishing and consuming from Data Ingestion sources
Reading and updating an entity in a Cloud Datastore transaction from an application
Using the CLI tools
Provisioning and configuring networks
Learn to integrate a Node.js application with Google Cloud SQL MySQL using a proxy, environment variables, and App Engine deployment, including creating a database and querying visits.
4.2 Integrating an application with Compute services. Tasks include:
Implementing service discovery in Google Kubernetes Engine, App Engine, and Compute Engine
Writing an application that publishes/consumes from Cloud Pub/Sub
Reading instance metadata to obtain application configuration
Authenticating users by using Oauth2 Web Flow and Identity Aware Proxy
Using the CLI tools
Configuring Compute services network settings (e.g., subnet, firewall ingress/egress, public/private IPs)
Learn how service discovery enables scalable microservices on cloud platforms, using API gateway, DNS proxy, and Spring Cloud patterns to register, locate, and route to multiple service instances.
Learn how to read and set instance metadata in Google Compute Engine to configure applications, including standard and custom metadata, via console and API, for identifying and categorizing instances.
4.3 Integrating Google Cloud APIs with applications. Tasks include:
Enabling a GCP API
Using pre-trained Google ML APIs
Making API calls with a Cloud Client Library, the REST API, or the APIs Explorer, taking into consideration:
batching requests
restricting return data
paginating results
caching results
Using service accounts to make Google API calls
Using APIs to read/write to data services (BigQuery, Cloud Spanner)
Using the Cloud SDK to perform basic tasks
5.1 Installing the logging and monitoring agent
5.2 Managing VMs. Tasks include:
Debugging a custom VM image using the serial port
Analyzing a failed Compute Engine VM startup
Sending logs from a VM to Stackdriver
5.3 Viewing application performance metrics using Stackdriver. Tasks include:
Creating a monitoring dashboard
Viewing syslogs from a VM
Writing custom metrics and creating metrics from logs
Graphing metrics
Using Stackdriver Debugger
Streaming logs from the GCP Console
Reviewing stack traces for error analysis
Setting up log sinks
Viewing logs in the GCP Console
Profiling performance of request-response
Profiling services
Reviewing application performance using Stackdriver Trace and Stackdriver Logging
Monitoring and profiling a running application
5.4 Diagnosing and resolving application performance issues. Tasks include:
Setting up time checks and other basic alerts
Setting up logging and tracing
Setting up resources monitoring
Troubleshooting network issues
Debugging/tracing cloud apps
Troubleshooting issues with the image/OS
Using documentation, forums and Google support
Explore the foundation of cloud solution architecture for Google Cloud Platform, covering requirements, design, security and compliance, and optimizing hybrid cloud operations with data mart and multicore games case studies.
Learn the professional cloud architect syllabus and exam structure for Google Cloud, including planning and designing cloud solutions, security and compliance, resource management, and case-study driven questions.
Prepare for the Google Cloud certifications by mastering exam questions, core services, and case studies. Apply design and architecture thinking to compute, database, networking, big data, and machine learning services.
Prepare before the exam by working through case studies, developing solutions, and practicing solution architecture, since case studies will make up about 40 percent of questions.
Learn a case-study driven approach to cover the Google Cloud syllabus. Apply syllabus principles to real scenarios and architect and refine solutions with Google's guidelines for the architect exam.
Explore the TerramEarth case study of mining and farming equipment to design a scalable data pipeline that reduces unplanned downtime by enabling real-time and batch analytics on connected vehicle data.
Design cloud solution architecture by defining business and technical requirements, outlining network, storage, and compute resource ids, and creating a migration plan while envisioning future solutions.
1.1 Designing a solution infrastructure that meets business requirements. Considerations include:
business use cases and product strategy
cost optimization
supporting the application design
integration
movement of data
tradeoffs
build, buy or modify
success measurements (e.g., Key Performance Indicators (KPI), Return on Investment (ROI), metrics)
Compliance and observability
Provisioning one or more Stackdriver accounts.
1.2 Designing a solution infrastructure that meets technical requirements. Considerations include:
high availability and failover design
elasticity of cloud resources
scalability to meet growth requirements
1.3 Designing network, storage, and compute resources. Considerations include:
integration with on premises/multi-cloud environments
Cloud native networking (VPC, peering, firewalls, container networking)
identification of data processing pipeline
matching data characteristics to storage systems
data flow diagrams
storage system structure (e.g., Object, File, RDBMS, NoSQL, NewSQL)
mapping compute needs to platform products
1.4 Creating a migration plan (i.e., documents and architectural diagrams). Considerations include:
integrating solution with existing systems
migrating systems and data to support the solution
licensing mapping
network and management planning
testing and proof-of-concept
1.5 Envisioning future solution improvements. Considerations include:
cloud and technology improvements
business needs evolution
evangelism and advocacy
2.1 Configuring network topologies. Considerations include:
extending to on-premise (hybrid networking)
extending to a multi-cloud environment which may include GCP to GCP communication
security
data protection
2.2 Configuring individual storage systems. Considerations include:
data storage allocation
data processing/compute provisioning
security and access management
network configuration for data transfer and latency
data retention and data lifecycle management
data growth management
3.1 Designing for security. Considerations include:
Identity and Access Management (IAM)
Resource hierarchy (organizations, folders, projects)
data security (key management, encryption)
penetration testing
Separation of Duties (SoD)
security controls
Managing customer-supplied encryption keys with Cloud KMS
3.2 Designing for legal compliance. Considerations include:
legislation (e.g., Health Insurance Portability and Accountability Act (HIPAA), Children’s Online Privacy Protection Act (COPPA), etc.)
audits (including logs)
certification (e.g., Information Technology Infrastructure Library (ITIL) framework)
Analyze and optimize technical and business processes using the public cloud platform’s ready-made features, including continuous deployment, troubleshooting, post-mortem analysis, service catalog, provisioning, and disaster recovery.
Analyze and define business processes for cloud adoption, communicate benefits to stakeholders, and align change management, skills readiness, and on-demand provisioning across multi-region resources to optimize costs.
Develop resilience in production by designing for failure, using multiple pub/sub topics and documented recovery procedures, and testing disaster recovery for regional outages.
5.1 Advising development/operation team(s) to ensure successful deployment of the solution. Considerations include:
application development
API best practices
testing frameworks (load/unit/integration)
data and system migration tooling
5.2 Interacting with Google Cloud using GCP SDK (gcloud, gsutil and bq). Considerations include:
local installation
Google Cloud Shell
Enhance reliability by implementing monitoring, logging, profiling, and alerting with deployment and release management for a hybrid cloud environment, and document audit-ready controls for the operations team.
Mountkirk Games case study shows deploying a cloud-based multiplayer backend on Google Cloud Platform for streaming analytics and reporting. It emphasizes auto-scaling, low-latency load balancing, and managed databases for insights.
Analyze the as-is architecture of Mountkirk Games, mapping the game backend, load balancer, and data flow into a MySQL database, then design a to-be architecture.
Design and plan a scalable, cost-optimized cloud solution architecture that meets business and technical requirements, enabling self-managed resources, external system integration, analytics, and KPI-driven metrics.
design a cloud-based game backend with 98% uptime and low latency by deploying resources near users, choosing virtual machines, NoSQL databases, and analytics pipelines using BigQuery or Spark.
Design resilient and scalable game backends on Google Cloud by selecting appropriate compute engine machines, auto-scaling, and load balancing. Implement security, disaster recovery, and monitoring to ensure reliable performance.
Analyze and optimize technical and business processes by migrating to Google Cloud Platform, leveraging real-time data from mobile devices, cloud analytics, and scalable architecture to improve performance and resiliency.
Learn to manage implementation for monaco came application development on Google Cloud Platform by applying best practices, testing frameworks, data and system integration, and Compute Engine migration tools.
Explore migrating Dress4Win to the cloud and mapping on-prem components to GCP services. Plan a disaster recovery site, assess architecture options, and adopt automation for scalable production.
Analyze EHR healthcare use cases to map platform and infrastructure components, including Kubernetes clusters, MySQL, Redis, MongoDB, and API/file interfaces, with a focus on disaster recovery, CI/CD, and regulatory compliance.
Map on-premise VMs and databases to Google Cloud using Compute Engine, Kubernetes Engine, and Cloud SQL or Firestore; enable scalable, observable, multi-region deployment with Anthos and CI/CD.
Explore migrating an existing asset to Google Cloud, enabling AI-driven race predictions, real-time telemetry, and global streaming with CDN, video intelligence, and Vertex AI.
Learn how to implement cloud DevOps practices on Google Cloud, building CI/CD pipelines, and mastering observability, logging, and troubleshooting best practices across cloud services and APIs.
Bootstraps a Google Cloud organization for DevOps, designs the resource hierarchy and infrastructure as code, and builds cloud-native or hybrid CI/CD architecture while managing dev, stage, production environments and permissions.
Design the organizational resource hierarchy with folders and projects, covering departments and billing. Review networking, vpc peering, identity and access management, permissions, and service accounts and keys for exam recap.
Explore resource management in Google Cloud, shaping policy by defining organization policies across organization, folders, and projects to enforce constraints, access controls, and trusted images for secure governance.
Learn how VPC peering connects two networks for VM-to-VM communication, including cross-project setups, quotas, nontransitive behavior, exclusive IP ranges, and its contrast with shared VPC.
Google Cloud IAM provides fine-grained access to Google Cloud resources across organizations, folders, and projects, with an audit trail and roles for identities such as accounts, groups, and service accounts.
Explore how iam policies provide access control for google cloud resources through policy objects and bindings, assigning roles to members and supporting parent to child inheritance and conditions.
Explore how service accounts authenticate service-to-service communication in Google Cloud, preserving least privilege by separating identities from passwords, with Google managed and user managed options and key rotation.
Discover how to use short lived service account credentials and impersonation to run gcloud commands and generate ID and JWT tokens with OAuth 2.0 and OpenID Connect, while auditing.
Explore Google Cloud networking basics, including global VPC networks, subnets, regions and zones, firewall rules, and peering options, with insights on load balancing and autoscaling.
Examine load balancers and their security perimeters, from global external http/https and tcp proxy to regional and internal options. Learn how anycast IP, failover, and cloud armor protect backend services.
Explore Google Cloud database and storage services while mastering data security practices, including encryption at rest and in transit, redaction, and DLP for protecting sensitive data.
Explore infrastructure as code in Google Cloud, including Cloud Foundation Toolkit, Config Connector, Terraform, Helm, and Deployment Manager, and learn best practices for provisioning, config management, and immutable architecture.
Design a CI/CD architecture stack in Google Cloud for hybrid multi-cloud environments, covering CI/CD concepts and tools like Cloud Build, Cloud Deploy, GitHub, Artifact Registry, and basic security.
Define the number and purpose of environments, ensuring dev, test, production isolation across projects and networks. Use Kubernetes Engine and Terraform with ci/cd tools like Git, Cloud Build, Spinnaker.
Learn how Google Cloud Source Repositories, a fully managed git service, provides unlimited private repositories, seamless integration with GitHub, fast code search, and quick deploy and debug.
Store and deploy Docker images in Google Cloud container registry with private secure storage, native Docker support, automatic builds, and vulnerability scanning for fast, highly available access.
Use Google Cloud Deployment Manager to automate infrastructure as code by defining resources in a configuration file and launching deployments from templates to provision compute resources, networks, and storage.
Master cloud build as a ci/cd tool on Google Cloud, turning code from Cloud Source or GitHub into Docker containers or Java archives via triggered build steps.
Connect a repository to cloud build, set triggers on branches or tags, and build with a dockerfile or yaml to deploy. Pricing: 20 minutes free, then 0.3 cents per minute.
Detail cloud build configuration with steps, environment variables, secrets, and artifacts in cloudbuild.yaml or cloudbuild.json, then build, push, and deploy Docker images to Cloud Run.
Show end-to-end cloud devops with Cloud Build, pushing code from a source repository, building a container, pushing to the container registry, and deploying to Cloud Run via a ci/cd pipeline.
Configure a cloud build workflow that builds a docker image, pushes it to the container registry, and launches a cloud run instance for a node.js hello world app.
Explore cloud task, a fully managed, scalable service for synchronous task execution on App Engine, offering Http targets, rate controls, retry policies, de-duplication, guaranteed delivery, and the command line interface.
Explore Google Cloud Scheduler, a fully managed cron-like service that delivers to App Engine, Cloud Pub/Sub, or HTTP endpoints, with configurable retry policies, Stackdriver logging, and Unix cron format.
Design and manage a CI/CD pipeline with artifact registry, deploy to hybrid and multi-cloud environments using Anthos and GKE, and explore deployment strategies, approvals, and binary authorization.
Implement ci/cd pipelines with auditing and tracking of dependent deployments. Emphasize deployment and rollback strategies using artifact registry, cloud build, cloud code, cloud deploy, and audit logs.
Explore deployment strategies—blue-green, recreate, canary with traffic splitting, AB testing, and rolling updates—driven by resource constraints, business goals, and safe rollbacks in Kubernetes.
Learn three approaches to securing a cloud ci cd deployment pipeline: vulnerability analysis with artifact registry, artifact scanning reports, binary authorization, and environment-specific iam policies.
This lecture explains securing infrastructure and applications by identifying common vulnerabilities, from injections to outdated libraries, and using web security scanner for design-time checks and cloud armor for production protection.
Learn to use Google's web security scanner, a security command center tool that detects web vulnerabilities on App Engine, Kubernetes Engine, and Compute Engine, with managed and custom scans.
Cloud armor protects production web apps by enforcing edge security policies at the POP, allowing or denying traffic by IP range or region, and blocking layer 3–7 threats.
Explore applying site reliability engineering practices to services, grounded in Google's SRE theory and the site reliability workbook, with practical guides for operating and implementing SRE across cloud environments.
Learn how site reliability engineering balances change, velocity, and service reliability, focusing on SLAs, error budgets, toil, automation, and incident management, with ITIL and Six Sigma context in DevOps.
Discover how DevOps and SRE merge to break silos, standardize tooling, and govern incidents with blameless post-mortems, SLOs, and error budgets for reliable, fast software delivery.
Learn how to define service level indicators (SLIs), set SLOs and error budgets, and balance releases with reliability signals like latency, availability, and durability across complex services.
Set up alerting policies that trigger on aggregated failures within fixed or moving windows, using error budgets and SLAs to avoid flooding, and translate alerts into incidents for timely response.
Define toil as manual, repetitive, value-free work that scales with a service, and explore automating provisioning, cleanup, and repetitive tasks to reduce toil and improve engineering efficiency.
Explore the service lifecycle from onboarding to retirement. Plan capacity with quotas and limits, enable autoscaling across GKE, Cloud Run, and Cloud Function, and use feedback to improve.
Explore healthy communications and blameless culture in operations, prevent burnout via toil reduction and automation, and manage incidents with post-mortems, root-cause analysis, traffic draining, and prioritized actions.
Implement service monitoring strategies by mastering cloud logging and monitoring tools, configuring the logging agent, and collecting structured and unstructured logs from Compute Engine, GKE, and serverless platforms.
Explore cloud logging in Google Cloud: configure, view, and analyze logs; export via sinks to Cloud Storage, BigQuery, or Pub/Sub; monitor with dashboards and alerts.
Explore firewall rule logs and VPC flow logs to audit access and monitor traffic between VMs and subnets. Learn how pocket monitoring mirrors traffic for forensic analysis.
Master cloud monitoring with alerts, uptime checks, and custom metrics that ingest logs and expose insights across hybrid deployments. Use incident reporting, autoscaling, and real-time error tracking with Stackdriver.
Explore logging and monitoring agents, including the ops agent, collectd, and fluentbit, and learn how to configure receivers, pipelines, and multi-line java logs for Google Cloud Platform services.
Explore Log Explorer, create dashboards and metrics, route logs to cloud storage or Pub/Sub, and analyze with BigQuery for alerts and monitoring.
Explore cloud monitoring in the console, setting dashboards, alerts, and incidents for VM and app metrics. Define services and SLOs, and monitor CPU utilization.
Explore managing metrics with cloud monitoring, dashboards and alerts, Terraform-defined alerting policies, and cloud managed Prometheus, plus enabling data access logs, VPC flow logs, and logging and monitoring access control.
Learn to filter and redact sensitive data in logs, use cloud data loss prevention to scan log buckets, and manage permissions to protect audit and VPC flow logs across projects.
Optimize service performance and cost optimization by using Cloud Operation Suite tools—monitoring, logging, trace, and profiler—while applying resource strategies like preemptible VMs and discounts.
Explore how Stackdriver debug lets you investigate production code with detailed performance insights, collaborate across teams, and enable in-production debugging by installing the debug agent and adding log points.
Use Stackdriver trace for distributed tracing and end-to-end latency analysis across App Engine, Kubernetes, and HTTP load balancer, with automatic latency detection and performance insights.
Discover how Stackdriver error reporting monitors real-time application errors, aggregates and filters them, explores stack traces, and sends alerts across languages and platforms such as NodeJS and App Engine.
Discover cost optimization strategies using preemptible spot instances with discounts, committed use discounts, and sustained use discounts, plus premium versus standard network tiers to balance latency and efficiency.
Examine exam recaps across sections to understand the questions and scope of the Google Cloud certification, covering cloud developer, cloud engineer, DevOps foundations, and cloud architecture.
Distinguish IAC, CI, and CD tools; compare Terraform, Deployment Manager, Ansible, and Cloud Deploy; explore deployment strategies (blue-green, canary, rolling updates), Kubernetes workflows, security, and immutable architecture.
Explore Google Cloud DevOps principles through global and golden signals, SLOs and SLAs, blameless post-mortems. Learn incident command roles, lifecycle steps, root cause analysis, and practical monitoring and tracing tools.
Explore Google Cloud foundation concepts, including least privilege, organization policy, service accounts, and VPC security, with practical guidance on firewall rules, shared VPC, and private access.
1.1 Selecting the appropriate storage technologies. Considerations include:
Mapping storage systems to business requirements
Data modeling
Tradeoffs involving latency, throughput, transactions
Distributed systems
Schema design
1.2 Designing data pipelines. Considerations include:
Data publishing and visualization (e.g., BigQuery)
Batch and streaming data (e.g., Cloud Dataflow, Cloud Dataproc, Apache Beam, Apache Spark and Hadoop ecosystem, Cloud Pub/Sub, Apache Kafka)
Online (interactive) vs. batch predictions
Job automation and orchestration (e.g., Cloud Composer)
1.3 Designing a data processing solution. Considerations include:
Choice of infrastructure
System availability and fault tolerance
Use of distributed systems
Capacity planning
Hybrid cloud and edge computing
Architecture options (e.g., message brokers, message queues, middleware, service-oriented architecture, serverless functions)
At least once, in-order, and exactly once, etc., event processing
1.4 Migrating data warehousing and data processing. Considerations include:
Awareness of current state and how to migrate a design to a future state
Migrating from on-premises to cloud (Data Transfer Service, Transfer Appliance, Cloud Networking)
Validating a migration
2.1 Building and operationalizing storage systems. Considerations include:
effective use of managed services (Cloud Bigtable, Cloud Spanner, Cloud SQL, BigQuery, Cloud Storage, Cloud Datastore, Cloud Memorystore)
storage costs and performance
lifecycle management of data
2.2 Building and operationalizing pipelines. Considerations include:
data cleansing
batch and streaming
transformation
data acquisition and import
Integrating with new data sources
3.1 Leveraging pre-built ML models as a service. Considerations include:
ML APIs (e.g., Vision API, Speech API)
customizing ML APIs (e.g., AutoML Vision, Auto ML text)
conversational experiences (e.g., Dialogflow)
3.4 Measuring, monitoring, and troubleshooting machine learning models. Considerations include:
Machine Learning terminology (e.g., features, labels, models, regression, classification, recommendation, supervised and unsupervised learning, evaluation metrics)
Impact of dependencies of machine learning models
Common sources of error (e.g., assumptions about data)
4.1 Designing for security and compliance. Considerations include:
identity and access management (e.g., Cloud IAM)
data security (encryption, key management)
ensuring privacy (e.g., Data Loss Prevention API)
legal compliance (e.g., Health Insurance Portability and Accountability Act (HIPAA), Children's Online Privacy Protection Act (COPPA), FedRAMP, General Data Protection Regulation (GDPR))
4.2 Ensuring scalability and efficiency. Considerations include:
building and running test suites
pipeline monitoring (e.g., Stackdriver)
assessing, troubleshooting, and improving data representations and data processing infrastructure
resizing and autoscaling resources
4.3 Ensuring reliability and fidelity. Considerations include:
performing data preparation and quality control (e.g., Cloud Dataprep)
verification and monitoring
planning, executing, and stress testing data recovery (fault tolerance, rerunning failed jobs, performing retrospective re-analysis)
choosing between ACID, idempotent, eventually consistent requirements
4.4 Ensuring flexibility and portability. Considerations include:
mapping to current and future business requirements
designing for data and application portability (e.g., multi-cloud, data residency requirements)
Data staging, cataloging and discovery
Bootstrapping machine learning: explore supervised, unsupervised, and reinforced learning concepts, key algorithms like regression, classification, clustering, neural networks, and TensorFlow and PyTorch demonstrations through visualization.
Explore the three core machine learning types: supervised, unsupervised, and reinforced, plus semi-supervised and generative AI, with examples like regression, classification, clustering, and large language models.
Master supervised learning with features and labels to predict sales from monthly data, then compare unsupervised, semi-supervised, and reinforcement learning using practical examples.
Learn how regression predicts continuous outcomes with a linear model y = mx + c from inputs, and how classification assigns categories via logistic regression and probability thresholds.
Compute loss from training data and use the validation set to tune hyperparameters, discuss mean squared error in linear regression, and address overfitting, underfitting, and generalization.
Explore how accuracy differs from precision and recall, and learn to evaluate models with true/false positives and negatives, roc auc, and f1 for better model performance.
Explore hyperparameter tuning through iterative learning, adjusting weights and loss with gradient descent and a learning rate. Learn how batch size, epochs, regularization, and TensorBoard optimize training.
Explore TensorBoard's playground to experiment with hyperparameters like learning rate, regularization, batch size, and activation functions on different data sets, visualizing epochs and training progress.
Explore how L1 and L2 regularization affect weights in a classification model, showing L1 zeroing features and L2 reducing weights to simplify the model and improve convergence.
Learn how feature cross and one hot encoding create synthetic features that capture interactions between inputs. Use L1 regularization to prune unimportant features and encode categorical data for robust models.
Explore how neural networks use hidden layers, activation functions like ReLU, tanh, and sigmoid, and backpropagation to model input-output relationships for deep learning, including softmax for multi-class classification.
Embeddings use vector representations to capture similarity between users and items, guiding recommendations from watch history and movie features; neural networks with embedding layers boost accuracy.
Gain an overview of Keras within TensorFlow Lite, compare sequential and functional models, and trace the end-to-end machine learning workflow from data preparation to model deployment.
Explore building a simple TensorFlow Keras sequential model to predict y from x using a basic linear equation y=2x+1, train with data, tune learning rate, and visualize results with TensorBoard.
Learn how to save and load machine learning models for production serving, including saving full models or weights, loading them for consistent predictions, and using the functional API.
Explore the functional model in Keras, building graphs with input, multiple dense layers, parallel pipelines, and merges, contrasted with sequential models, and visualize with graphviz.
Explore convolutional neural networks for image classification, learning features with filters, pooling, and relu, then flattening for a dense classifier using softmax to distinguish cat and dog.
Learn how the knn classifier uses training data to predict labels with a lazy training approach, adjustable k and distance or uniform weighting, contrasted with k-means concepts.
Explore ensemble learning, including bagging and boosting with examples like random forest, AdaBoost, and XGBoost, and learn how binning converts continuous data into categorical features.
Explore Google Cloud Platform machine learning options: pre-trained models, AutoML, and custom models via Vertex AI. Deploy models and run predictions, using bqml, generative AI studio, and retail AI.
Explore Vertex AI in the console, navigate dashboard, model garden, workbench, and pipelines, and learn to train, deploy, and serve models with data, feature store, and labeling tasks.
Learn how to create and use vertex ai datasets for training, fine-tuning, and serving, selecting image, video, text, or tabular data from cloud storage or bigquery.
Discover how the Vertex AI feature store centralizes transformed features for ML, enabling reusable entities and tables, ingesting and transforming data, and sharing features across projects.
Learn how AutoML in Vertex AI automates data preparation, training, and evaluation for image, text, video, and tabular data. Deploy online or batch predictions via endpoints and monitor costs.
Explore the Google Cloud professional machine learning engineer certification syllabus across six sections, from architecting low code ml solutions to monitoring models in production, including data collaboration and ml pipelines.
Section 1: Architecting low-code AI solutions (13% of the exam)
1.1 Developing ML models by using BigQuery ML. Considerations include:
● Building the appropriate BigQuery ML model (e.g., linear and binary classi cation, regression, time-series, matrix factorization, boosted trees, autoencoders) based on the business problem
● Feature engineering or selection by using BigQuery ML
● Generating predictions by using BigQuery ML
1.2 Building AI solutions by using ML APIs or foundational models. Considerations include:
● Building applications by using ML APIs from Model Garden
● Building applications by using industry-speci c APIs (e.g., Document AI API, Retail API)
● Implementing retrieval augmented generation (RAG) applications by using Vertex AI Agent Builder
1.3 Training models by using AutoML. Considerations include:
● Preparing data for AutoML (e.g., feature selection, data labeling, Tabular Workfows on AutoML)
● Using available data (e.g., tabular, text, speech, images, videos) to train custom models
● Using AutoML for tabular data
● Creating forecasting models by using AutoML
● Configuring and debugging trained models
1.1 Developing ML models by using BigQuery ML. Considerations include:
● Building the appropriate BigQuery ML model (e.g., linear and binary classication, regression, time-series, matrix factorization, boosted trees, autoencoders) based on the business problem
● Feature engineering or selection by using BigQuery ML
● Generating predictions by using BigQuery ML
Learn how to create and configure BigQuery ML models, selecting between internally trained, externally trained, remote, and imported options with optional transform-based pre-processing.
Explore BigQuery ML prediction and inference with Ml.predict, forecasting using ARIMA+ models, anomaly detection, and recommendations via matrix factorization, plus model building and generating predictions.
Identify useful features and transform raw data into numeric representations for training. Understand online and offline transformations in BigQuery ML, and the permissions to create and use models.
Build apps with pre-trained ML APIs—vision, natural language, speech, and translation—to gain inference without training, including text detection, landmark and logo recognition, and sentiment analysis.
Explore retail AI and document AI methods in Google Cloud, including catalog-driven recommendations, clickstream-based personalization, and document processing with custom, general, and specialized processors.
Section 2: Collaborating within and across teams to manage data and models (~14% of the exam)
2.1 Exploring and preprocessing organization-wide data (e.g., Cloud Storage, BigQuery, Spanner, Cloud SQL, Apache Spark, Apache Hadoop). Considerations include:
● Organizing different types of data (e.g., tabular, text, speech, images, videos) for e cient training
● Managing datasets in Vertex AI
● Data preprocessing (e.g., Data ow, TensorFlow Extended [TFX], BigQuery)
● Creating and consolidating features in Vertex AI Feature Store
● Privacy implications of data usage and/or collection (e.g., handling sensitive data such as personally identifiable information [PII] and protected health information [PHI]) 2
● Ingesting different data sources (e.g., text documents) into Vertex AI for inference 2.2 Model prototyping using Jupyter notebooks. Considerations include: ● Choosing the appropriate Jupyter backend on Google Cloud (e.g., Vertex AI Workbench, Colab Enterprise, notebooks on Dataproc)
● Applying security best practices in Vertex AI Workbench ● Using Spark kernels ● Integrating code source repositories ● Developing models in Vertex AI Workbench by using common frameworks (e.g., TensorFlow, PyTorch, sklearn, Spark, JAX) ● Leveraging a variety of foundational and open-source models in Model Garden 2.3 Tracking and running ML experiments. Considerations include: ● Choosing the appropriate Google Cloud environment for development and experimentation (e.g., Vertex AI Experiments, Kubeow Pipelines, Vertex AI TensorBoard with TensorFlow and PyTorch) given the framework ● Evaluating generative AI solutions
Organize organization-wide data from BigQuery, Cloud Storage, and other sources for machine learning, and transform with data flow and TensorFlow extended, while orchestrating pipelines with Airflow, Cloud Composer, and Kubeflow.
Explore model prototyping with Jupyter notebooks, using Python data processing, and compare running environments like Vertex AI workbench, Dataproc, Colab, and local laptops for enterprise data security.
Apply security best practices for Vertex AI with encryption, access controls, and private networking under the shared responsibility model. Enforce data residency and Private Service Connect to prevent data exfiltration.
Learn to train models with structured and unstructured data, including images and CSV, ingest via BigQuery or Cloud Storage, and use distributed training with mirror strategies and accelerators.
Discover distributed training with CPUs and GPUs, using parameter servers or reduction servers to coordinate workers, enable allreduce, and optimize bandwidth with a single evaluator for TensorFlow.
3.1 Building models. Considerations include:
● Choosing ML framework and model architecture
● Modeling techniques given interpretability requirements
3.2 Training models. Considerations include:
● Organizing training data (e.g., tabular, text, speech, images, videos) on Google Cloud (e.g., Cloud Storage, BigQuery)
● Ingestion of various le types (e.g., CSV, JSON, images, Hadoop, databases) into training
● Training using di erent SDKs (e.g., Vertex AI custom training, Kubeow on Google Kubernetes Engine, AutoML, tabular work ows)
● Using distributed training to organize reliable pipelines
● Hyperparameter tuning
● Troubleshooting ML model training failures
● Fine-tuning foundational models (e.g., Vertex AI, Model Garden)
Explore online versus batch predictions for real-time and historical insights, deploy models via a model registry, and validate with A/B testing, traffic splits, and scalable infrastructure health checks.
5.1 Developing end-to-end ML pipelines. Considerations include:
● Data and model validation
● Ensuring consistent data pre-processing between training and serving
● Hosting third-party pipelines on Google Cloud (e.g., MLFlow)
● Identifying components, parameters, triggers, and compute needs (e.g., Cloud Build, Cloud Run) ● Orchestration framework (e.g., Kubeflow Pipelines, Vertex AI Pipelines, Cloud Composer)
● Hybrid or multicloud strategies
● System design with TFX components or Kubeflow DSL (e.g., Data ow) 4
5.2 Automating model retraining. Considerations include:
● Determining an appropriate retraining policy
● Continuous integration and continuous delivery (CI/CD) model deployment (e.g., Cloud Build, Jenkins) 5.3 Tracking and auditing metadata. Considerations include:
● Tracking and comparing model artifacts and versions (e.g., Vertex AI Experiments, Vertex ML Metadata)
● Hooking into model and dataset versioning
● Model and data lineage
Develop end-to-end ml pipeline by validating data quality, performing continuous data and model validation, and monitoring training versus serving skew to ensure reliable predictions.
Learn to automate model retraining by defining a retraining policy and orchestrating a continuous training pipeline with data validation, A/B testing, and canary deployments.
Identify risks in ML solutions and monitor security and responsible AI practices, while assessing readiness, biases, fairness, and explainability on Vertex AI, plus drift and performance monitoring.
Identify risks to ML solutions by applying responsible AI principles: fairness, accountability, interpretability, explainability, safety, and privacy, while addressing biases in data and deployment.
Explore model explainability on Vertex AI by revealing which features, such as color and shape, drive predictions, with examples like apple vs banana and feature attribution values.
Explore monitoring, testing, and troubleshooting ml solutions with continuous evaluation metrics, training and serving skew, and feature attribution drift, using Vertex AI to detect prediction drift and surface actionable insights.
Deep dive into Google Cloud Platform networking concepts for the professional cloud network engineer, covering DCP VPC configuration, network services, hybrid interconnectivity, and network security on foundational knowledge.
Design and implement disaster recovery and high availability for a GCP network by mapping business requirements to multi-region, multi-zone load balancing, health checks, and persistent state storage.
1.1 Designing the overall network architecture. Considerations include:
Failover and disaster recovery strategy
Options for high availability
DNS strategy (e.g., on-premises, Cloud DNS, GSLB)
Meeting business requirements
Choosing the appropriate load balancing options
Optimizing for latency (e.g., MTU size, caches, CDN)
Understanding how quotas are applied per project and per VPC
Hybrid connectivity (e.g., Google private access for hybrid connectivity)
Container networking
IAM and security
SaaS, PaaS, and IaaS services
Microsegmentation for security purposes (e.g., using metadata, tags)
Explore global and regional load balancers in Google Cloud, including SSL proxy and proxy load balancing, and learn how to route client requests to back-end instances based on traffic conditions.
Explore how a content delivery network caches static content at Google Cloud CDN edge locations to optimize latency and reduce backend load.
Understand the distinction between project quota and VPC quota, how quotas differ from hard limits, and how to request increases to avoid bill shock.
Explore hybrid connectivity options for Google Cloud, including Cloud VPN with scalable channels and Cloud Interconnect with direct peering or partner interconnect, to reduce egress fees across Google services.
Understand cloud service models—iaas, paas, and saas—alongside traditional data centers, with examples from Google Cloud Platform and App Engine, and how virtualization and managed runtimes differ.
1.3 Designing a hybrid network. Considerations include:
Using Interconnect (e.g., dedicated vs. partner)
Peering options (e.g., direct vs. carrier)
IPsec VPN
Cloud Router
Failover and disaster recovery strategy (e.g., building high availability with BGP using cloud router)
Shared vs. standalone VPC Interconnect access
Cross-organizational access
Bandwidth
Implement a Google Cloud VPC, focusing on VPC configurations, network firewall rules, and routes, including VPC peering, in hands-on demos.
2.1 Configuring VPCs. Considerations include:
Configuring GCP VPC resources (CIDR range, subnets, firewall rules, etc.)
Configuring VPC Peering
Creating a shared VPC and explaining how to share subnets with other projects
Configuring API access (Private, Public, NAT GW, Proxy)
Configuring VPC flow logs
Configure VPC peering between auto network and the customer network, establish the connection, and enable traffic between the two networks by opening firewall rules.
Configure shared vpc by linking a G Suite organization, assigning a network administrator, and sharing subnets with service projects to enable cross-project networking.
2.2 Configuring routing. Tasks include:
Configuring internal static/dynamic routing
Configuring routing policies using tags and priority
Configuring NAT (e.g., CloudNAT, instance-based NAT)
2.3 Configuring and maintaining Google Kubernetes Engine clusters. Considerations include:
VPC-native Clusters using Alias IPs
Clusters with Shared VPC
Private Clusters
Cluster Network policy
Adding authorized networks for Cluster Master Access
Configure and maintain Google Kubernetes Engine clusters by managing Shared VPC configurations, private clusters, and network policies, including alias IP, private Google access, and master authorized networks for controlled access.
2.4 Configuring and managing firewall rules. Considerations include:
Target network tags and service accounts
Priority
Network protocols
Ingress and egress rules
Firewall logs
3.1 Configuring load balancing. Considerations include:
Creating backend services
Firewall and security rules
HTTP(S) load balancer: including changing URL maps, backend groups, health checks, CDN, and SSL certs
TCP and SSL Proxy Load Balancers
Network load balancer
Internal load balancer
Session affinity
Capacity scaling
3.2 Configuring Cloud CDN. Considerations include:
Enabling and disabling Cloud CDN
Using cache keys
Cache invalidation
Signed URLs
3.3 Configuring and maintaining Cloud DNS. Considerations include:
Managing zones and records
Migrating to Cloud DNS
DNS Security (DNSSEC)
Global serving with Anycast
Cloud DNS
Internal DNS
Integrating on-premises DNS with GCP
3.4 Enabling other network services. Considerations include:
Health checks for your instance groups
Canary (A/B) releases
Distributing backend instances using regional managed instance groups
Enabling private API access
4.1 Configuring Interconnect. Considerations include:
Partner (e.g., Layer 2 vs. Layer 3 connectivity)
Virtualizing using Vlan attachments
Bulk storage uploads
4.2 Configuring a site-to-site IPsec VPN (e.g., route-based, policy-based, dynamic or static routing).
4.3 Configuring Cloud Router for reliability.
4.2 Configuring a site-to-site IPsec VPN (e.g., route-based, policy-based, dynamic or static routing).
5.1 Configuring Identity and Access Management (IAM). Tasks include:
Viewing account IAM assignments
Assigning IAM roles to accounts or Google Groups
Defining custom IAM roles
Using pre-defined IAM roles (e.g., network admin, network viewer, network user)
5.2 Configuring Cloud Armor policies. Considerations include:
IP-based access control
6.2 Managing and maintaining security. Considerations include:
Firewalls (e.g., cloud-based, private)
Diagnosing and resolving IAM issues (shared VPC, security/network admin)
6.3 Maintaining and troubleshooting connectivity issues. Considerations include:
Identifying traffic flow topology (e.g., load balancers, SSL offload, network endpoint groups)
Draining and redirecting traffic flows
Cross-connect handoff for Interconnect
Monitoring ingress and egress traffic using flow logs
Monitoring firewall logs
Managing and troubleshooting VPNs
Troubleshooting Cloud Router BGP peering issues
6.4 Monitoring, maintaining, and troubleshooting latency and traffic flow. Considerations include:
Network throughput and latency testing
Routing issues
Tracing traffic flow
Learn to optimize network resources by improving traffic flow, reducing costs, and boosting efficiency in Google Cloud.
7.1 Optimizing traffic flow. Considerations include:
Load balancer and CDN location
Global vs. Regional dynamic routing
Expanding subnet CIDR ranges in service
Accommodating workload increases (e.g., autoscaling vs. manual scaling)
7.2 Optimizing for cost and efficiency. Considerations include:
Cost optimization (Network Service Tiers, Cloud CDN, autoscaler (max instances))
Automation
VPN vs. Interconnect
Bandwidth utilization (e.g., kernel sys tuning parameters)
Greetings, Cloud Professionals!
We have 450,000+ Subscriptions & 323,000 Unique Students for Google Cloud Platform Certifications making us "No 1 Training for Google Cloud Platform on Udemy"
We have received feedback from numerous students indicating that our courses have been instrumental in helping them pass their certifications. Please continue to do so if this course help you to pass the certification.
Updates in April 2024:
Updated Services Video Content: Google has updated the video content for several of its Cloud Platform services, including Compute Engine, Kubernetes Engine, and Cloud Storage. The updated videos provide more comprehensive and up-to-date information on how to use these services.
Added DevOps Engineer and Cloud Security Engineer Certifications: Google has added two new certifications to its Cloud Platform certification program: the Google Cloud Certified - Professional DevOps Engineer and the Google Cloud Certified - Professional Cloud Security Engineer. These certifications demonstrate that professionals have the skills and knowledge necessary to design, implement, and manage DevOps and Cloud Security solutions on the Google Cloud Platform.
The majority of IT professionals around the world hold at least one certification. The Global Knowledge 2024 IT Skills and Salary Report found that 85% of IT professionals hold at least one certification and that 66% of these professionals intend to acquire a new certification this year.
Udemy's Lifetime Availability Guarantee - If you purchase ONCE, you will receive a lifetime update for Google Cloud Platform Certifications.
Why pay for certification training for GCP.? This course will help you to pay only once and plan for any certification on the Google Cloud Platform.
The course is structured into sections that cover all the concepts in one go, followed by a focused approach toward earning each certification incrementally.
This course will fully prepare you for the certifications listed below.
Cloud Digital Leader
Associate Cloud Engineer
Professional Cloud Architect
Professional Cloud Developer
Professional DevOps Engineer
Professional Security Engineer
Professional Machine Learning Engineer - Exam recap still pending
Professional Cloud Network Engineer - Syllabus changed and don't refer it for actual exam.
Note : Data Engineer is not part of this course.
We have not provided Question Sets for all certifications but updating Exam Recap for you to review your understanding.
This course is not for Lazy learners - This course provides in-depth knowledge of the Google Cloud Platform and requires students to maintain a high level of focus and attention throughout.
For Advanced Professionals joining this course only for certification -> It is recommended that you go through the foundation section at least once to gain a clear understanding of the certification sections.
Thank You for your time and stay connected!
Happy Learning !!
Google Cloud Gurus
Seattle, WA USA