About the Exam

This professional-level Google Cloud certification is for cloud security engineers who design and implement secure workloads and infrastructure on Google Cloud. The exam covers configuring access, securing communications and boundary protection, ensuring data protection, managing operations, and supporting compliance requirements. Passing demonstrates that you can design, develop, and manage secure solutions using Google Cloud security technologies.

Exam Topics

  • Configuring access25%
  • Securing communications and establishing boundary protection22%
  • Ensuring data protection23%
  • Managing operations19%
  • Supporting compliance requirements11%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated August 27, 2026 at 9:44 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Configuring access

Your organization has engaged a small, temporary partner team for 18 months. The temporary team will work with your DevOps team to develop your organization’s application hosted on Google Cloud. You must grant the temporary partner team access to your application’s Google Cloud resources and ensure partner employees lose that access if they are removed from their employer’s organization. What should you do?

Explanation

Workforce Identity Federation lets external workforce users—including partners and contractors—authenticate through their existing identity provider and receive IAM-authorized access to Google Cloud resources. A workforce identity pool federated with the partner’s IdP keeps identity lifecycle control with that employer, so users removed from the IdP can no longer authenticate for access. Workforce Identity Federation

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Configuring access

Your security team wants to lower the risk that user-managed keys are mishandled or compromised. To do this, you must stop developers from creating user-managed service account keys for projects in their organization. How should this be enforced?

Explanation

Enforce the Organization Policy constraint that disables service account key creation (iam.managed.disableServiceAccountKeyCreation, or the legacy iam.disableServiceAccountKeyCreation). The policy blocks creation of new external, user-managed service account keys in the projects where it applies, reducing the risk from unmanaged long-lived credentials.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Managing operations

Your organization uses Vertex AI Workbench Instances. You must ensure that newly deployed Instances are automatically kept current and that users cannot inadvertently change operating-system settings. What should you do?

Explanation

Enforcing the Vertex AI Workbench organization policies for automatic scheduled upgrades and disabled root access requires newly created instances to have an automatic upgrade schedule and prevents them from enabling root access. This keeps the environment updated while preventing users from altering operating-system settings with root privileges.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Supporting compliance requirements

You work for a multinational organization with systems deployed across multiple cloud providers, including Google Cloud. Your organization operates an extensive on-premises security information and event management (SIEM) system. New security-compliance regulations require relevant Google Cloud logs to be seamlessly integrated with the existing SIEM, providing a unified view of security events.

You need to implement a solution that exports Google Cloud logs to the on-premises SIEM using a push-based, near-real-time approach. You must prioritize fault tolerance, security, and autoscaling capabilities. In particular, you must ensure that logs are resent if a log delivery fails. What should you do?

Explanation

An organization-level aggregated Cloud Logging sink can route relevant logs across the organization to a Pub/Sub topic in near real time. Pub/Sub supports redelivery when a subscriber does not acknowledge a message, while a Dataflow streaming pipeline provides managed, autoscaling processing to deliver the records to the SIEM. A secondary replay mechanism preserves recovery from failed deliveries.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Securing communications and establishing boundary protection

Your organization is moving to Google Cloud. You need to ensure that only trusted container images are deployed to Google Kubernetes Engine (GKE) clusters in a project. Containers must be deployed from a centrally managed Container Registry and be signed by a trusted authority.

What should you do?

Choose two
Explanation

The trusted image organization policy constraint restricts deployments to approved container image registries. A Binary Authorization policy that requires attestations enforces that an image was signed and approved by the configured trusted authority before GKE permits deployment.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home