certslothcertsloth
PCDBE/Topic 02

Google Cloud / Professional

Connectivity, identities and protection

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Reachability, identity, privileges: three gates.

Must remember

  • Private connectivity removes a public path but does not grant database permission. Plan VPC routing, DNS, private services access or Private Service Connect according to the chosen database.
  • Cloud SQL/AlloyDB connectors and auth proxies simplify supported authenticated TLS connections. They do not magically create a missing private network route or remove engine-level authorization.
  • IAM controls cloud resource operations and supported IAM database authentication; database users/roles control SQL privileges. Separate administration, application access and migration identities.
  • Pool connections to avoid exhausting database limits during application autoscaling. Set bounded pool sizes, connection lifetimes, timeouts and retry behavior; multiply per-instance pools by maximum instance count.
  • Use TLS in transit and appropriate managed/CMEK encryption at rest. Plan key permissions, rotation and availability before restricting keys; secret rotation must coordinate clients and database credentials.
  • Audit sensitive access and changes at the relevant cloud and engine layers. Log enough to investigate without exposing query parameters or credentials unnecessarily.

Choose under exam pressure

Requirement Choice and reason
Many short-lived application instances Bounded connection pooling and a database connection budget.
Application can reach the host but SELECT fails Inspect database authentication and object privileges.

Traps

  • Cloud IAM administrator access does not imply every SQL data privilege.
  • An auth proxy is not a general-purpose VPN.

Active recall

1. Why calculate total pool size?

Hundreds of application instances can each open a pool and overwhelm the database.

2. What protects data in transit?

TLS with proper identity/certificate validation.

3. How diagnose a private connection timeout?

Check DNS, routing, firewall/service connectivity and target availability before SQL grants.

4. Why use separate migration credentials?

Migration often needs elevated temporary privileges that applications should not keep.

5. What happens if a required CMEK becomes unusable?

The dependent database operations or data access can fail.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.