GCP Associate Cloud Engineer (ACE) — Complete Exam Deck
A complete, self-contained Associate Cloud Engineer study deck built to be used on its own, not just as a review companion, covering every exam-guide domain with the same depth and currency as the 8-part tutorial series.
Slides
GCP foundations, fully current
Opening slide framing this deck as a complete, standalone study tool for the current Associate Cloud Engineer exam.
The exam itself, and how this deck maps to it
2 hours, 50-60 questions, four domains at 20/30/30/20, delivered through Pearson VUE.
The project is the real unit of isolation
IAM, billing, quotas, and API enablement all attach at the project level, and GCP's regions/zones work differently from AWS's and Azure's.
Organization, folders, projects, and now: standalone orgs
The resource hierarchy plus the newer standalone-organization path that needs no Cloud Identity at all.
Org policies now ship with a dry-run mode
Dry-run mode lets a team observe a policy's real blast radius against live traffic before ever enforcing it.
Five more day-zero considerations
IAM roles at project creation, API enablement, quotas, observability provisioning, and the default VPC you shouldn't build on.
Three metadata mechanisms, one exam trap
Labels, network tags, and Resource Manager tags look similar but only one of them can gate a firewall rule or an IAM condition.
Cloud Identity: manual and SCIM-automated
Automated SCIM provisioning keeps GCP's identity directory in sync with an external IdP, including on offboarding.
Cloud Asset Inventory, Gemini Cloud Assist, and Workforce Identity Federation
Three mechanisms for knowing what exists, asking AI about it, and letting external humans sign in without a directory entry.
A budget alerts, it never caps
Billing accounts are separate objects from projects, and a budget's job ends at notification unless you build automation on top.
gcloud, Cloud Shell, and the ADC trap
Named configurations switch your whole working context at once, and two separate auth commands solve two separate problems.
Five infrastructure tools, five different jobs
gcloud, Terraform, Config Connector, Helm, and Fabric FAST each occupy a genuinely different layer, not interchangeable choices.
Gemini CLI sunset, Antigravity, and Application Design Center
The AI tooling landscape changed meaningfully in 2026, know which product does what before an exam question conflates them.
Principal, permission, role, and policy
Four precise terms describing how a permission ever reaches a resource, a permission is never granted directly, only through a role.
Predefined first, custom only for a documented gap
Policy inheritance is a strict union up the hierarchy, and a basic role's blast radius is bigger than most requesters realize.
Impersonation over keys, by default now
Short-lived, audit-friendly impersonation has replaced the long-lived JSON key as the default workload credential.
Keys are now blocked by default
For organizations created on or after May 3, 2024, service account key creation is disabled out of the box.
Workforce vs. Workload Identity Federation
One federates humans for console SSO, the other federates workloads for programmatic API calls, a frequent exam trap pair.
Hyperdisk is now the default, not Persistent Disk
Four Hyperdisk types decouple IOPS and throughput from disk size, and Persistent Disk no longer ships on the newest machine series.
OS Login and VM Manager: fleet control by IAM, not by hand
SSH access ties to IAM roles instead of scattered keys, and VM Manager turns fleet patching into a queryable operation.
Spot VMs, custom machine types, and managed instance groups
A 60-91% discount trades against a 30-second reclaim notice, a sound trade only when the workload's architecture already tolerates it.
GPUs, TPUs, and a snapshot schedule nobody had tested
Choose accelerators by framework fit and workload shape, and a backup that's never been restored is an unverified assumption.
Autopilot bills per Pod, Standard bills per node
The billing model difference is the whole decision, and Autopilot now mandates resource requests at every Pod.
Cloud Run: revisions, traffic splitting, and instant rollback
Every deploy creates a new revision with zero traffic until explicitly assigned, and old revisions never disappear on their own.
The Agent Runtime: the newest exam addition
A managed, serverless runtime specifically for AI agents, with session state and tool-calling Cloud Run doesn't provide natively.
Cloud Workstations and managed notebooks
Standardized, versioned developer environments, and two different notebook contexts that get conflated on the exam.
Choosing between GKE, Cloud Run, and the Agent Runtime
The first, decisive question is whether the workload is specifically an AI agent, everything else follows familiar serverless-vs-Kubernetes tradeoffs.
Cloud Storage plus three file-storage products
Object storage lifecycle and Autoclass, and a genuinely new three-way file-storage split for AI training workloads.
Choosing a managed database, still the same tree
Relational versus document versus wide-column versus analytical, the first fork that narrows the field before scale even matters.
The relational family and the NoSQL split
Cloud SQL, AlloyDB, and Spanner cover relational; Firestore and Bigtable split NoSQL by access pattern.
Two newer additions: Managed Kafka and Memorystore
Choose Kafka specifically for genuine API compatibility, choose Pub/Sub for everything else building new.
CMEK, a fleet-wide view, and a rotation that locked out a replica
Disabling a CMEK key version makes data permanently unreadable by design, and Database Center gives one aggregated view across the fleet.
Custom-mode VPCs, Shared VPC, and non-transitive peering
The default VPC still isn't for production, and peering connects exactly two networks, never a chain.
Cloud NGFW: Secure Tags replace network tags
The newer firewall policy model doesn't support plain network tags at all, only centrally-governed Secure Tags.
Load balancer choice and an asymmetric tier rule
Scope and layer decide the load balancer, and only one combination is locked to Premium Tier only.
Cloud VPN, Interconnect, DNS, and NAT
Bandwidth and lead time trade off between VPN and Interconnect, and NAT is strictly outbound-only by design.
Resizing subnets, static IPs, and static routes
A subnet that runs out of IP addresses silently caps autoscaling, with no error the application layer ever sees.
Cloud Monitoring and Cloud Logging, still the backbone
Alerting policies plus custom metrics, and a log router that decides where every entry actually lands.
Trace, Profiler, and Query Insights: a narrowing sequence
Each tool's output decides which tool comes next, not three independent, parallel checks.
Personalized Service Health, Active Assist, and Cloud Hub
Three 2026-era operations surfaces, each answering a different kind of question about your environment's health.
The traps that recur across every domain
Six patterns of mistake that show up as distractors across multiple exam domains, not just one chapter.
Quick-fire recall
A rapid-drill term list spanning every chapter, for a last pass the night before the exam.
Exam-day strategy
How to spend your time across a 50-60 question, 2-hour exam weighted 20/30/30/20 across four domains.
Readiness checklist, fully current
The minimum signals a GCP foundation is production-ready, now including the 2026-era additions this deck covered.