GOOGLE · Professional Cloud Security Engineer

Google Professional Cloud Security Engineer Exam Practice Questions

361 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 361 questions in this pack

Question 1

A customer needs an alternative to storing their plain text secrets in their source-code management (SCM) system.

How should the customer achieve this using Google Cloud Platform?

  1. Use Cloud Source Repositories, and store secrets in Cloud SQL.
  2. Encrypt the secrets with a Customer-Managed Encryption Key (CMEK), and store them in Cloud Storage.
  3. Run the Cloud Data Loss Prevention API to scan the secrets, and store them in Cloud SQL.
  4. Deploy the SCM to a Compute Engine VM with local SSDs, and enable preemptible VMs.
Show answer and explanation

Correct answer: B. Encrypt the secrets with a Customer-Managed Encryption Key (CMEK), and store them in Cloud Storage.

Encryption Key (CMEK), and store them in Cloud Storage. The best practice for storing secrets outside of source code is to encrypt them with a Customer-Managed Encryption Key (CMEK) and store them in Cloud Storage. This approach keeps secrets out of the SCM system while providing encryption at rest and access control. Cloud Source Repositories doesn't solve the secret storage problem. The Data Loss Prevention API scans for secrets but doesn't manage their storage. Deploying SCM to a Compute Engine VM replicates the on-premises problem and doesn't address secure secret management.

Why the other options are wrong

  • A. Cloud Source Repositories is a version control system and doesn't provide secure secret storage; storing secrets in Cloud SQL alongside code doesn't solve the SCM problem.
  • C. The Data Loss Prevention API detects secrets but doesn't provide a secure storage solution.
  • D. Running SCM on Compute Engine with local SSDs doesn't provide encryption or centralized secret management and replicates the original problem.

Question 2

Your team wants to centrally manage GCP IAM permissions from their on-premises Active Directory Service. Your team wants to manage permissions by AD group membership.

What should your team do to meet these requirements?

  1. Set up Cloud Directory Sync to sync groups, and set IAM permissions on the groups.
  2. Set up SAML 2.0 Single Sign-On (SSO), and assign IAM permissions to the groups.
  3. Use the Cloud Identity and Access Management API to create groups and IAM permissions from Active Directory.
  4. Use the Admin SDK to create groups and assign IAM permissions from Active Directory.
Show answer and explanation

Correct answer: A. Set up Cloud Directory Sync to sync groups, and set IAM permissions on the groups.

IAM permissions on the groups. Cloud Directory Sync synchronizes Active Directory groups to Google Cloud Identity, allowing teams to manage GCP IAM permissions based on AD group membership. This provides centralized management of both identity and access control. SAML 2.0 SSO handles authentication but not group-based permission management in the way required. The Cloud Identity and Access Management API and Admin SDK require programmatic integration and don't provide the automatic synchronization that Cloud Directory Sync offers for group-based management.

Why the other options are wrong

  • B. SAML 2.0 SSO enables single sign-on but doesn't centrally manage group-based IAM permissions from Active Directory.
  • C. The IAM API requires manual integration and doesn't automatically sync AD groups for permission management.
  • D. The Admin SDK also requires manual integration and doesn't provide automatic synchronization of AD groups.

Question 3

A customer needs to launch a 3-tier internal web application on Google Cloud Platform (GCP). The customer's internal compliance requirements dictate that end-user access may only be allowed if the traffic seems to originate from a specific known good CIDR. The customer accepts the risk that their application will only have SYN flood DDoS protection. They want to use GCP's native SYN flood protection.

Which product should be used to meet these requirements?

  1. Cloud Armor
  2. VPC Firewall Rules
  3. Cloud Identity and Access Management
  4. Cloud CDN ✅Correct Answer: B, VPC Firewall Rules Google Cloud's infrastructure provides SYN flood protection natively for traffic reaching VM instances, with no additional product required. Because the customer accepts that SYN flood mitigation is the only DDoS defense, the remaining requirement is simply to allow end-user traffic only from one known good CIDR. VPC firewall rules do exactly that: an ingress allow rule scoped to the specific source range, applied to the tiers of the internal application, blocks everything else by default. This meets the compliance requirement while relying on GCP's built-in SYN flood protection.
Show answer and explanation

Answer and explanation for question 3

See all 10 free questions Get the full pack, US$39

361 practice questions for Google Cloud Professional Cloud Security Engineer, with full explanations.

Every question comes with the correct answer and a clear explanation. Mapped to the current Professional Cloud Security Engineer exam objectives.

  • 361 questions mapped to the Professional Cloud Security Engineer exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed attempt costs another US$200, plus the weeks it takes to get ready again. This pack is US$39, paid once, and refunded if you fail anyway.

Try 10 questions free before you buy.

Last updated September 2026 · 361 questions

What makes the Professional Cloud Security Engineer hard

The Professional Cloud Security Engineer is one of Google Cloud’s strongest specialist credentials and the go-to badge for anyone responsible for securing workloads on the platform. Security is the top concern for most organisations, which makes this one of the most valuable certifications to hold.

What decides it is securing Google Cloud end to end: identity and access management, organisation structure and policies, boundary protection with VPC Service Controls and Cloud Armor, data protection with Cloud KMS, threat detection and security automation with Security Command Center, and supporting compliance requirements across the environment. The exam rewards deep, scenario-based security design.

It is 50 to 60 questions in two hours. This pack has 361 practice questions mapped to the Professional Cloud Security Engineer exam objectives, so the question style is familiar before exam day.

About the exam

The Google Cloud Professional Cloud Security Engineer certification validates the ability to design and implement secure infrastructure on Google Cloud, including IAM, network security, data protection, and threat management. Google recommends three or more years of industry experience including one or more year on Google Cloud. It is valid for two years.

Exam sections

  • Configure access
  • Secure communications and establish boundary protection
  • Ensure data protection
  • Manage operations
  • Support compliance requirements

Google does not publish percentage weightings for these sections. 50 to 60 questions, 2 hours, multiple choice and multiple select, US$200 per attempt, available in English and Japanese, online proctored or test centre, valid 2 years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Google Professional Cloud Security Engineer pack?

361 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.