Unit Roadmap509 words

Unit 5 roadmap — Trust and Security with Google Cloud

Cloud Digital Leader › Unit 5

Unit 5 roadmap — Trust and Security with Google Cloud

Unit 5 at a glance

~17%
3
14
82
70
9

Every objective below is quoted from Google's Cloud Digital Leader exam guide, retrieved 2026-09-22. Under each topic is that topic's own summary of what the exam actually tests, taken from its lecture.

Topic 1 — Trust and security in the cloud

CDL-U5.T1 · 4 objectives · lecture deck of 12 slides

  1. Describe today’s top cybersecurity threats and business implications.
  2. Differentiate between cloud security and traditional on-premises security.
  3. Describe the importance of control, compliance, confidentiality, integrity, and availability in a cloud security model.
  4. Define key security terms and concepts.

What this topic actually tests. Old risk or new? misconfiguration, access, visibility, dynamic workloads and compliance are the cloud's own. More secure or secured differently? Google says neither more nor less. Which word? name the question — see, change, be there, decide, obey. Which term? zero trust places trust; least privilege sizes it; defense in depth layers it.

Topic 2 — Google’s trusted infrastructure

CDL-U5.T2 · 6 objectives · lecture deck of 15 slides

  1. Describe the benefits of Google designing and building its own data centers, using purpose-built servers, networking, and custom security hardware / software.
  2. Describe the role of encryption in securing an organization’s data and the ways that it can protect data exposed to risks in different states.
  3. Differentiate between authentication, authorization, and auditing.
  4. Describe the benefits of using two-step verification (2SV) and IAM.
  5. Describe how an organization can protect against network attacks using Google products, including distributed denial-of-service (DDoS) using Google Cloud Armor.
  6. Define Security Operations (SecOps) in the cloud and describe its business benefits.

What this topic actually tests. Which state? at rest and in transit are default; in use needs Confidential Computing. Whose key? default encryption is Google's key; CMEK is yours. Which check? authentication proves, authorization permits, auditing records. Which second step? security keys resist phishing; codes do not. Where does Cloud Armor act? at the load balancer, before the backends.

Topic 3 — Google Cloud’s trust principles and compliance

CDL-U5.T3 · 4 objectives · lecture deck of 12 slides

  1. Discuss how Google Cloud's trust principles are a commitment to our shared responsibility for protecting and managing an organization’s data in the cloud.
  2. Describe how sharing transparency reports and undergoing independent third-party audits support customer trust in ​​Google.
  3. Describe ​​why data sovereignty and data residency may be requirements and how Google Cloud offers organizations the ability to control where their data is stored.
  4. Describe how Google Cloud compliance resource center and Compliance Reports Manager support industry and regional compliance needs.

What this topic actually tests. Whose task is it? each commitment has a customer counterpart. Who is vouching? Google publishes the Transparency Report; a third party audits. Where, or who? residency is location; sovereignty is access and keys. Is it, or can I have it? the offerings page says what Google meets; Compliance Reports Manager hands over the proof — and your own certification is still yours.

Ready to study Cloud Digital Leader (GCP-CDL)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free