Google Cloud Professional Cloud Security Engineer
Validates ability to design and implement secure workloads and infrastructure on Google Cloud. Covers configuring access through Cloud Identity, service accounts, authentication, authorization controls, and resource hierarchy; securing communications and establishing boundary protection with perimeter security, boundary segmentation, and private connectivity; ensuring data protection through sensitive data handling, encryption management, and AI workload security; managing operations with security automation, logging, monitoring, and detection; and supporting compliance requirements with regulatory standards. 50-60 multiple-choice and multiple-select questions in 2 hours. Recommended 3+ years industry experience; 2-year validity.
Sample questions
A free preview of 15 source-grounded questions from this exam — answers and explanations included.
- Q1Configuring accesseasy
A platform team is being asked to grant a support group access to a project only when its members connect from the corporate network, and otherwise deny it, without creating separate projects. The team is evaluating native IAM features. Which feature meets this requirement?
- A.Access Context Manager service perimeters, which wrap the project so data cannot leave the network boundary
- B.Organization policy constraints applied at the folder to restrict which regions the project may deploy into
- C.IAM Conditions on the role binding, granting the role only when the request comes from the corporate networkCorrect answer
- D.
Sources
Questions are grounded in 150 references from official and authoritative materials.