The blueprint
A mock exam here has 50 questions in 2 hours, split across the domains in the same proportions as the official exam guide. FixOps scores practice against a target of 70%.
-
01
Setting up a cloud solution environment
-
02
Planning and implementing a cloud solution
-
03
Ensuring the successful operation of a cloud solution
-
04
Configuring access and security
Sample questions
Three of the 10 questions in the free diagnostic. Open one to see the answer and why.
In which order does the Google Cloud resource hierarchy go, from top to bottom?
- Billing account, organization, projects, folders
- Folders, organization, projects, resources
- Organization, folders, projects, resources
- Organization, projects, folders, resources
Answer: Organization, folders, projects, resources. The organization is the root node, folders group projects (and other folders), and projects hold the resources. Policies set higher up are inherited by everything below.
A team sets a budget of 1,000 dollars a month on a project. What happens when the spending reaches it?
- Alerts are sent; the resources keep running
- Every resource in the project is stopped
- New resources are refused until the next month
- The project is unlinked from the billing account
Answer: Alerts are sent; the resources keep running. A budget tracks spending against an amount and sends alerts at its thresholds. It does not cap usage; stopping spend needs automation built on the budget notifications.
A stateless HTTP API ships as a container, has idle periods and should cost nothing while idle. Which compute option fits best?
- A Compute Engine managed instance group
- A GKE Standard cluster
- A sole-tenant node
- Cloud Run
Answer: Cloud Run. Cloud Run runs containers without servers to manage, scales with requests and scales to zero when there is no traffic. The other options keep machines running.
Revision notes: Setting up a cloud solution environment
The notes for one domain, free to read here and in the app. FixOps Pro has them for all 4 domains.
The resource hierarchy and organization policies, projects, APIs and quotas, identities in Cloud Identity, the gcloud CLI, and billing accounts, budgets and exports.
Resource hierarchy
- The hierarchy is organization, folders, projects, resources; allow policies and organization policies set on a node are inherited by everything below it.
- The organization resource comes with a Google Workspace or Cloud Identity account for a verified domain.
- Folders group projects by department, team or environment, and can be nested.
- A project has a name (changeable), a project ID (unique and fixed once created) and a project number that Google assigns.
- A project that was shut down can be restored for 30 days; after that it is gone and its ID is never reused.
Organization policies
- An organization policy restricts how resources may be configured; IAM decides who may act. They answer different questions.
- Common constraints are gcp.resourceLocations, compute.vmExternalIpAccess, compute.requireOsLogin and iam.disableServiceAccountKeyCreation.
- Setting them needs the Organization Policy Administrator role, which Project Owner does not include.
- A policy set lower in the hierarchy can override or merge with the inherited one, which is how an exception for one project is made.
Projects, APIs and quotas
- Most APIs must be enabled per project first: gcloud services enable NAME.googleapis.com, with the Service Usage Admin role.
- Quotas cap what a project may use, many of them per region; an increase is requested on the Quotas and System Limits page.
- A region contains several zones, and not every product, machine type or accelerator is offered in every location.
- Cloud Asset Inventory searches resources and IAM policies across the organization, keeps their history and can publish changes to Pub/Sub.
- Gemini Cloud Assist helps design, troubleshoot and optimize from the console in natural language.
Identities
- Cloud Identity provides managed users and groups without Google Workspace; Google Cloud Directory Sync copies them one way from Active Directory or LDAP.
- Grant roles to groups rather than to individuals, so that access follows group membership.
- Workforce Identity Federation lets users of an external identity provider sign in without Cloud Identity accounts; Workload Identity Federation is the same idea for applications.
The gcloud CLI
- gcloud init authorizes the CLI and sets the default project; gcloud config set project changes it later.
- Named configurations (gcloud config configurations create and activate) hold an account, project, region and zone each, for quick switching.
- Cloud Shell is a browser terminal on a temporary VM with gcloud, kubectl and Terraform installed and a 5 GB home directory.
- A metrics scope lets one project show the Cloud Monitoring metrics of many projects.
Billing
- A project is linked to one Cloud Billing account; a billing account can pay for many projects.
- Billing Account User can link projects, Billing Account Administrator manages the account, and Billing Account Viewer sees costs.
- Changing a project's billing account needs Project Billing Manager on the project and Billing Account User on the new account.
- A budget sends alerts at its thresholds, on actual or forecasted spend; it does not stop anything.
- To stop spending automatically, send budget notifications to Pub/Sub and let a function disable billing on the project.
- Billing export to BigQuery allows SQL over costs: standard usage cost, detailed (resource-level) usage cost, and pricing data.
Easy to mix up
- Organization policies restrict what can be configured; IAM policies decide who can do it. A project owner cannot bypass a constraint.
- The project ID is fixed and globally unique; the project name is a label that can change; the project number is assigned by Google.
- A budget alerts and never caps: the resources keep running after the amount is reached.
- Billing Account User links projects to an account; Project Billing Manager changes the billing of a project. Moving a project needs both.
- Workforce Identity Federation is for people from an external identity provider; Workload Identity Federation is for applications.
- A quota is a limit on usage, not a permission and not a payment problem: more IAM roles or more credit do not raise it.