Memory hook: Permission, retention, recovery, keys.
Must remember
- IAM permissions are bundled into roles. Prefer narrowly scoped predefined roles over broad basic roles; separate permission to run BigQuery jobs from permission to read particular datasets.
- Uniform bucket-level access centralizes Cloud Storage authorization through IAM rather than object ACLs. Public access prevention blocks accidental public exposure; signed sharing needs a deliberate expiry and audience.
- Analytics Hub, also described as BigQuery sharing, distributes governed data listings without requiring each subscriber to maintain unmanaged exports. Verify the permissions and region of shared datasets.
- Choose storage class by access pattern and minimum storage duration, not headline storage price alone. Lifecycle rules can transition or delete objects; table and partition expiration remove aged analytical data.
- Replication improves availability; independent backups and point-in-time recovery address corruption or deletion. Define RPO and RTO, choose regional/dual-region/multi-region placement appropriately, and test recovery.
- Google-managed keys are the default for many services; CMEK gives control through Cloud KMS; customer-supplied keys require the customer to supply key material for supported operations. At-rest encryption does not replace TLS, authorization or privacy controls.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Need control over key rotation and disablement | CMEK with a documented recovery and access plan. |
| Recover yesterday’s valid database state | Backups/PITR, not merely a replica of today’s corrupted state. |
Traps
- Deleting a key can make retained data unusable.
- An archive class can charge retrieval and early-deletion fees.
Active recall
1. Why separate job and data permissions?
A user may need to execute queries without receiving access to every dataset.
2. What is RPO?
The acceptable amount of data loss measured in time.
3. What does a lifecycle delete rule do?
Removes matching data according to the configured rule; it is not a backup.
4. Does encryption grant access?
No; IAM and service authorization still determine who can use data.
5. How prove a recovery plan?
Restore and validate it within the required RPO and RTO.