Reviewed 10 October 2026. Use the linked official exam guide for your exam version. These are condensed revision notes; the topic pages provide worked distinctions and more recall practice. Google’s 2026 guides use newer Gemini Enterprise Agent Platform names while some APIs and documentation still use Vertex AI.
Memory hook: Business value → trusted data → suitable AI → modern applications → secure operations.
Version: this guide follows the Cloud Digital Leader scope launched 12 August 2026, including agentic AI and current security/data products.
1. Transformation — 1.1–1.2
Cloud’s business case is agility, elastic capacity, global reach and access to managed capabilities. Compare the business outcome with migration cost, skills, integration, governance and risk. Scalability handles growth; elasticity adjusts capacity as demand changes. A fast deployment that fails compliance is not successful transformation.
IaaS offers infrastructure with customer OS control; PaaS operates more of the application platform; SaaS supplies a finished application. Customer responsibility for identities, settings and data remains. Hybrid combines cloud and on-premises/private systems; multicloud uses multiple cloud providers. Open standards aid interoperability; open-source licensing does not mean zero operating cost.
Regions are geographical, zones isolate failures within a region, and edges place selected services close to users. Latency is delay; bandwidth is carrying capacity; DNS resolves names to records. A global network does not waive residency requirements.
2. Data transformation — 2.1–2.3
- A database supports application reads/writes; a warehouse supports analytics; a lake stores varied raw/curated data. Governance supplies owners, access, quality, cataloguing, lineage and lifecycle.
- Structured tables, semi-structured JSON and unstructured media have different preparation needs. First-party data comes from your relationships, second-party from a partner, third-party from external providers; all need appropriate rights.
- Cloud SQL: familiar relational engines. AlloyDB: demanding PostgreSQL-compatible workloads. Spanner: scalable consistent relational transactions. Firestore: documents. Bigtable: high-throughput key/range access. BigQuery: analytical SQL. Cloud Storage: objects.
- Data lifecycle: create/collect → process → store → analyze → act. Pub/Sub carries events; Dataflow processes batch/streams; Managed Service for Apache Spark fits Spark workloads; Looker supplies governed business metrics and dashboards.
- Storage classes trade access economics: Standard for frequent access, Nearline/Coldline/Archive for progressively colder data; retrieval/minimum-duration costs matter. Autoclass automates supported transitions.
3. AI value and choices — 3.1–3.2
AI is the umbrella, ML learns patterns, generative AI produces content, and agents combine models with tools/actions. Prediction is not the same task as generating a paragraph. A standard API for translation, vision or speech can be faster to adopt than custom training.
Gemini supplies foundation-model capabilities; Gemini Enterprise Agent Platform supports model/agent development and operations. AutoML reduces model-building work; BigQuery ML brings supported ML to SQL users; Agent Studio supports agent development. AI Hypercomputer combines accelerators, software and infrastructure. Choose by quality, cost, latency, privacy, skills and differentiation.
Training changes learned parameters, prompting changes instructions, retrieval supplies current evidence. Check accuracy, completeness, consistency, validity, uniqueness and timeliness of data. Evaluate unseen cases and subgroup performance; use human oversight for consequential decisions. Explainability helps understanding, not proof that a decision is fair or correct.
4. Modernization and APIs — 4.1–4.3
Discover dependencies first. Retire removes; retain keeps; rehost moves with limited change; replatform improves selected components; refactor redesigns; reimagine revisits the business workflow. Compute Engine gives VMs, GKE orchestrates containers, Cloud Run runs managed containers/functions. Autoscaling adds/removes capacity; load balancing distributes traffic. Microservices can improve independent delivery while adding operational complexity.
Apigee helps expose, govern, analyze and monetize APIs. AlloyDB Omni, BigQuery Omni and GKE Enterprise address specific hybrid/multicloud needs; they do not mean every Google service runs identically everywhere.
5. Trust and security — 5.1–5.2
Confidentiality limits disclosure; integrity protects correctness; availability keeps service usable. Authentication identifies, authorization permits, auditing records. Apply least privilege, separation of duties, MFA and identity/context-based zero trust.
TLS protects transit, default encryption/CMEK protect stored data, and Confidential Computing protects supported processing. IAM controls actions, IAP gates supported identity-aware access, Cloud Armor protects supported applications, Sensitive Data Protection discovers/de-identifies data. SCC prioritizes posture/threat findings; SecOps correlates telemetry and response; Google Threat Intelligence draws on Google visibility, Mandiant and VirusTotal. Model Armor adds AI filtering, not unlimited tool authorization.
6. Costs and reliability — 6.1–6.2
CapEx buys assets; OpEx pays operating consumption. TCO includes people, migration, licensing, support and transfer. Projects/labels allocate cost; budget alerts warn; quotas limit particular consumption measures. Rightsize, remove idle capacity, use Spot only for interruption-tolerant work, and consider commitments for predictable demand.
High availability tolerates failures; backups preserve history; DR restores the wider service. Metrics/logs/traces/profiles complement each other. Remember the golden signals: latency, traffic, errors, saturation. SLI = measurement, SLO = target, SLA = contractual commitment. DevOps improves delivery collaboration; SRE engineers reliability and reduces toil.
Traps to catch
- Serverless still has configuration, security, cost and limits.
- Provider compliance is not automatic application compliance; replication is not historical recovery.
- Fluent AI answers and attractive dashboards can both be wrong if the underlying evidence is poor.
Last-pass self-check
1. Which cloud model leaves the most OS responsibility with the customer?
IaaS, such as a VM. PaaS and SaaS progressively move more platform operation to the provider.
2. What should happen before selecting a migration product?
Inventory dependencies and define business, downtime, data, licensing and operational constraints.
3. Why is the lowest storage rate not necessarily cheapest?
Retrieval, requests, transfer and early-deletion/minimum-duration charges contribute to total cost.
4. Which three controls answer who, what may they do and what happened?
Authentication, authorization and auditing.
5. Why choose an existing AI API before custom training?
It may satisfy the business capability with less data, engineering time and operating effort; still evaluate task quality and privacy.
Sources
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · Cloud Transformation and Business Value
Memory hook: Buy an outcome, not a rack.
Must remember
Cloud provides configurable IT resources through managed service interfaces. Its business value can include faster experimentation, elastic capacity and access to global services. Benefits are not automatic: skills, integration, governance, migration cost and organizational resistance can slow transformation. Measure outcomes such as time to launch or customer experience, not only server count.
IaaS leaves more OS/application responsibility to the customer; PaaS manages more platform operations; SaaS provides a finished application. Shared responsibility changes with the model, but customers still manage appropriate identities, data use and configuration.
A public cloud is provider-operated; private cloud serves a dedicated organization; hybrid connects on-premises/private and public environments; multicloud uses more than one cloud. Open source makes source code available under a license; an open standard supports interoperability. Neither guarantees zero migration cost or identical service behavior.
Regions are geographic areas, zones separate failure domains within a region, and edge locations bring selected services closer to users. DNS resolves names; IP addresses identify network endpoints. Latency measures delay; bandwidth measures carrying capacity. Global reach does not override data-residency obligations.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Need full OS customization | IaaS/VMs. |
| Need an already-built business application | SaaS. |
| Connect existing data center and public cloud | Hybrid architecture. |
Traps
- Cloud can reduce waste but does not guarantee a lower bill.
- Multicloud and hybrid describe different dimensions.
02 · Data, Analytics and Better Decisions
Memory hook: Database runs the transaction; warehouse explains the pattern.
Must remember
Structured data follows a defined schema, semi-structured data carries flexible structure such as JSON, and unstructured data includes images/audio. First-party data comes from an organization’s own relationships; second-party data is another party’s directly shared data; third-party data is obtained through external aggregation/providers. Permission and quality matter regardless of source.
Cloud SQL manages familiar relational engines; AlloyDB targets PostgreSQL-compatible workloads; Spanner addresses globally scalable relational transactions; Firestore stores application documents; Bigtable serves large low-latency wide-column/key-based workloads. BigQuery supports analytical queries. Cloud Storage stores objects and can support a data lake; a lake is not automatically a governed warehouse.
Cloud Storage Standard suits frequent access; Nearline, Coldline and Archive trade cheaper storage for minimum-duration/retrieval considerations. Autoclass can manage supported transitions automatically. Select total cost and access needs rather than the cheapest storage line item.
Data pipelines collect, process, store, analyze and activate information. Pub/Sub decouples event delivery; Dataflow transforms batch/stream data; managed Spark supports Spark processing. Looker makes governed metrics and dashboards available to decision makers. Catalogs, lineage, ownership, retention and quality controls prevent an accessible lake becoming an untrusted data dump.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Operational relational application | Cloud SQL/AlloyDB according to engine and scale needs. |
| Large-scale SQL analytics | BigQuery. |
| Low-latency stream transformation | Pub/Sub with an appropriate Dataflow pipeline. |
Traps
- Object storage is not a relational database.
- A dashboard is only as trustworthy as its definitions and input data.
03 · AI, Models and Agents
Memory hook: Predict a pattern; generate content; constrain an action.
Must remember
AI is the broad field of machine-based intelligent behavior. ML learns patterns from examples; generative AI produces new content; an agent can select tools/actions toward a goal. Analytics describes and investigates data; business intelligence presents decision-oriented metrics. These capabilities overlap but solve different problems.
Use an existing API when a standard task such as translation, image analysis or speech recognition fits. A foundation model such as Gemini supports broader language/multimodal tasks. Gemini Enterprise Agent Platform brings model and agent development capabilities together; Agent Studio and supported AutoML workflows reduce different kinds of implementation work. BigQuery ML supports selected model workflows through SQL.
Training from scratch offers control at high cost and expertise requirements. Prompting adjusts instructions; retrieval supplies relevant context; tuning adapts supported model behavior with examples. Select the least complex approach that meets quality, privacy, latency and differentiation needs.
AI quality depends on accurate, complete, current, valid, unique and consistent data. Evaluate performance on representative unseen examples, including harmful or biased outcomes. Explainability helps people understand decisions; responsibility includes consent, security, fairness, human oversight and accountability. AI Hypercomputer combines compute such as GPUs/TPUs with software and consumption options, but hardware alone cannot fix poor data or evaluation.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Standard language translation | A pre-trained Translation API. |
| Answer from private current documents | Authorized retrieval plus a suitable generative model. |
| Analyst wants supported ML using SQL | BigQuery ML. |
Traps
- Fluent output can be incorrect.
- An autonomous agent should not inherit unlimited user or administrator privileges.
04 · Modern Applications, Migration and APIs
Memory hook: Move what you have; modernize what creates value.
Must remember
Discover dependencies and business constraints before selecting a migration. Retain keeps a workload where it is; retire removes it; rehost moves it with limited change; replatform improves selected components; refactor changes application design. A large rewrite is not automatically the best first step under a tight deadline.
Compute Engine provides VMs and OS control. Containers package application dependencies; GKE manages Kubernetes orchestration. Cloud Run services execute request-driven containers, and Cloud Run functions supports function-oriented workloads. Serverless shifts infrastructure operation to the provider; code, data and scaling limits still need design.
Autoscaling changes capacity; load balancing distributes traffic. Microservices separate capabilities into independently operated components, which can improve delivery flexibility but add network, observability and consistency complexity. Spot VMs suit interruption-tolerant jobs, not an unprotected single critical server.
APIs expose defined capabilities to other software. Apigee helps govern, secure, analyze and monetize API programs. Hybrid/multicloud offerings such as GKE Enterprise, AlloyDB Omni or BigQuery Omni address particular deployment/data needs; confirm product support rather than assuming every managed service runs everywhere.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Minimal change to a legacy OS-dependent app | Rehost on an appropriate VM. |
| Stateless web container with low administration | Cloud Run. |
| Govern partner/public APIs | Apigee API management. |
Traps
- Containers do not automatically make an application a microservice architecture.
- Serverless does not mean no cost or no limits.
05 · Trust, Security and Responsible Control
Memory hook: Authenticate identity; authorize action; audit evidence.
Must remember
Confidentiality limits disclosure, integrity protects correctness, and availability keeps services usable. Authentication establishes identity; authorization decides allowed actions; auditing records evidence. Least privilege grants only necessary access. Zero trust continually evaluates identity/context rather than trusting a network location alone.
Encryption at rest protects stored data, TLS protects transit, and supported confidential-computing environments protect aspects of processing. IAM manages permissions; IAP provides identity-aware access; Cloud Armor protects supported edge workloads; Sensitive Data Protection discovers/de-identifies supported sensitive data. A VPN encrypts a network path, while Interconnect provides dedicated connectivity options with separate encryption design.
Security Command Center helps prioritize cloud posture and threat findings. Google Security Operations supports detection/investigation from telemetry; threat intelligence adds information about adversaries and indicators. Model Armor addresses supported AI input/output threats, but application authorization and validation remain necessary.
Common risks include phishing, ransomware, misconfiguration, credential theft, DDoS and unsafe AI tool use. Provider certifications, transparency and audit reports support assessment; customers still decide lawful use, residency, access and retention. Compliance and security overlap but neither is a complete substitute for the other.
Review details
Distinguish posture (current exposures and weak settings), threat intelligence (adversary/indicator context), and response (containment and recovery actions). Google Threat Intelligence combines Google visibility with Mandiant frontline expertise and VirusTotal intelligence. A finding or IOC match is evidence to assess in context, not automatic proof of a confirmed incident.
Digital sovereignty considers control, applicable obligations and operational dependence as well as where data is stored. Certificate Manager supports certificate management; encryption does not authorize a user. Google's secure-by-design infrastructure and external audit evidence reduce customer assessment work but do not transfer ownership of customer configuration or lawful data use.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Restrict what a workload can access | Least-privilege IAM. |
| Discover exposed sensitive records | Sensitive Data Protection and appropriate remediation. |
| Investigate cross-system threat activity | Security operations tooling with relevant telemetry. |
Traps
- Encryption cannot compensate for an authorized account being overprivileged.
- A compliant provider does not automatically make an application compliant.
06 · Costs, Reliability and Cloud Operations
Memory hook: Budget warns; quota limits; SLO measures the experience.
Must remember
CapEx purchases long-lived assets; OpEx pays ongoing operating expenses. Cloud often shifts spending toward consumption, but total cost includes staffing, migration, support, data transfer and idle resources. Financial governance assigns ownership, cost allocation, forecasting and review rather than treating the bill as only finance’s problem.
The organization/folder/project hierarchy helps group resources and apply inherited policy. Billing accounts fund linked projects. Budgets warn at thresholds; quotas limit particular resource/API quantities. Neither is a universal automatic hard spending cap. Rightsizing, idle-resource removal, suitable Spot use and commitments for predictable demand address different sources of waste.
High availability uses redundancy to tolerate failures; backups preserve recoverable history; disaster recovery restores service after larger failures. Replication may copy accidental deletion, so it does not replace backup. Recovery needs tested access, dependencies and procedures.
Cloud Monitoring tracks metrics, Logging records events, Trace connects request paths, Profiler identifies runtime hot spots, and Error Reporting groups application errors. Watch latency, traffic, errors and saturation. An SLI is a measurement, an SLO is its target, and an SLA is a contractual commitment. DevOps improves delivery/operation collaboration; SRE applies engineering to reliability and operational toil.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Warn about projected overspend | Budget notifications with an accountable response process. |
| Recover accidental deletion | Verified backups/version history within retention. |
| Measure user-facing reliability | Meaningful SLIs and SLOs. |
Traps
- Replicas can faithfully replicate mistakes.
- More availability can cost more; choose the target the business needs.