certslothcertsloth
ADP/Topic 05

Google Cloud / Associate

Governance, lifecycle and recovery

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Permission, retention, recovery, keys.

Must remember

  • IAM permissions are bundled into roles. Prefer narrowly scoped predefined roles over broad basic roles; separate permission to run BigQuery jobs from permission to read particular datasets.
  • Uniform bucket-level access centralizes Cloud Storage authorization through IAM rather than object ACLs. Public access prevention blocks accidental public exposure; signed sharing needs a deliberate expiry and audience.
  • Analytics Hub, also described as BigQuery sharing, distributes governed data listings without requiring each subscriber to maintain unmanaged exports. Verify the permissions and region of shared datasets.
  • Choose storage class by access pattern and minimum storage duration, not headline storage price alone. Lifecycle rules can transition or delete objects; table and partition expiration remove aged analytical data.
  • Replication improves availability; independent backups and point-in-time recovery address corruption or deletion. Define RPO and RTO, choose regional/dual-region/multi-region placement appropriately, and test recovery.
  • Google-managed keys are the default for many services; CMEK gives control through Cloud KMS; customer-supplied keys require the customer to supply key material for supported operations. At-rest encryption does not replace TLS, authorization or privacy controls.

Choose under exam pressure

Requirement Choice and reason
Need control over key rotation and disablement CMEK with a documented recovery and access plan.
Recover yesterday’s valid database state Backups/PITR, not merely a replica of today’s corrupted state.

Traps

  • Deleting a key can make retained data unusable.
  • An archive class can charge retrieval and early-deletion fees.

Active recall

1. Why separate job and data permissions?

A user may need to execute queries without receiving access to every dataset.

2. What is RPO?

The acceptable amount of data loss measured in time.

3. What does a lifecycle delete rule do?

Removes matching data according to the configured rule; it is not a backup.

4. Does encryption grant access?

No; IAM and service authorization still determine who can use data.

5. How prove a recovery plan?

Restore and validate it within the required RPO and RTO.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.