Professional Cloud Security Engineer - Google Cloud Certified Logo
Google Logo

Professional Cloud Security Engineer - Google Cloud Certified Exam Questions

391

Total Questions

SEP
2025

Last Updated

1st

1st Try Guaranteed

Expert Verified

Experts Verified

Question 1 Single Choice

A customer’s company is divided into multiple business units, each with its own independent engineering team. Your team needs visibility into all projects created within the company and wants to categorize Google Cloud Platform (GCP) projects by business unit. Additionally, each business unit requires distinct IAM permissions.

What approach should you take to meet these requirements?

Question 2 Single Choice

You are part of your company's development team and have observed that your web application, hosted in staging on GKE, dynamically incorporates user data into web pages without validating the input first. This flaw could allow attackers to execute arbitrary commands and display malicious content in a user's browser in the production environment.

What should you do to prevent and resolve this vulnerability?

Question 3 Single Choice

You work for an organization in a regulated industry with stringent data protection requirements. The organization backs up their data in the cloud. To comply with data privacy regulations, this data can only be stored for a specific length of time and must be deleted after this period. You aim to automate compliance with this regulation while minimizing storage costs. What should you do?

Question 4 Single Choice

At NetCore Labs, you are setting up a new Service Account that needs the ability to list all Compute Engine VM instances within a Google Cloud project. You also want to follow Google's best practices for access control.

What is the appropriate approach?

Question 5 Single Choice

Your organization's record data is stored in Cloud Storage, and it must be retained for a minimum of seven years, with this policy being permanent. How should you proceed to ensure compliance with this requirement?

Question 6 Single Choice

You need to establish a Cloud Interconnect connection between your company’s on-premises data center and VPC host network. Your goal is to ensure that on-premises applications can only access Google APIs over the Cloud Interconnect and not through the public internet. You are required to use only APIs supported by VPC Service Controls to mitigate against exfiltration risk to non-supported APIs. How should you configure the network?

Question 7 Multiple Choice

Applications frequently need to use `secrets`—small bits of sensitive information—during either the build or run phases. An administrator handling these secrets on GCP aims to monitor `who performed what action, in which location, and at what time` within their GCP projects.

Which two logging streams would give the administrator the desired information? (Select two.)

Question 8 Single Choice

How can you ensure the trustworthiness and alignment with security requirements of operating system images used across projects during the migration of virtual machines (VMs) to Google Cloud?

Question 9 Single Choice

The security operations team at CyberNexa Corp wants to centralize log collection from all development projects for analysis in their SIEM system. These development projects are grouped under the NONPROD folder alongside test and pre-production environments. All of these projects are billed under the XYZ-BILLING account.

What is the most effective logging export approach to provide a unified log view in the SIEM?

Question 10 Single Choice

You are part of the security team at AlphaTrust Corp. Currently, your team operates a single GCP project that hosts both credit card payment systems and non-sensitive workloads such as web applications and data processing services. To meet compliance goals, you aim to reduce the PCI DSS audit scope as much as possible.

What action should you take?

Page: 1 / 40