Free knowledge base

Professional Cloud Security Engineer — key terms, tricks & tips

Everything from the course in one searchable place: 250 entries. Use it to review before a practice test or look up a word you forgot.

250 results

Key term

Professional Cloud Security Engineer (PCSE)

Google Cloud certification for securing cloud deployments.

Getting Started: Exam Essentials

Key term

Exam Domains

Major content areas covered by the certification exam.

Getting Started: Exam Essentials

Key term

Scaled Scoring

Method where raw scores are converted to a standardized score.

Getting Started: Exam Essentials

Key term

Multiple-Choice Question

Question with one correct answer among several options.

Getting Started: Exam Essentials

Key term

Multiple-Select Question

Question with two or more correct answers from a list.

Getting Started: Exam Essentials

Key term

IAM

Identity and Access Management; controls who can do what.

Getting Started: Exam Essentials

Key term

VPC Service Controls

Creates security perimeters around sensitive data and services.

Getting Started: Exam Essentials

Key term

Cloud KMS

Cloud Key Management Service; manages cryptographic keys.

Getting Started: Exam Essentials

Memory trick

Understanding the Professional Cloud Security Engineer Exam

To remember the domains: 'A Network Data Operation Complies'. (Access, Network, Data, Operations, Compliance)

Getting Started: Exam Essentials

Exam tip

Understanding the Professional Cloud Security Engineer Exam

The exam is 2 hours long, with multiple-choice and multiple-select questions. There are no public passing scores; it uses scaled scoring. Memorize the five main exam domains.

Getting Started: Exam Essentials

Common mistake

Understanding the Professional Cloud Security Engineer Exam

Focusing too much on theoretical knowledge without understanding practical application.

Getting Started: Exam Essentials

Common mistake

Understanding the Professional Cloud Security Engineer Exam

Not reviewing the official exam guide for the most current domain breakdown and topics.

Getting Started: Exam Essentials

Common mistake

Understanding the Professional Cloud Security Engineer Exam

Underestimating the importance of hands-on experience with Google Cloud security services.

Getting Started: Exam Essentials

Key term

Official Documentation

Authoritative Google Cloud service guides and references.

Getting Started: Exam Essentials

Key term

Security Whitepapers

In-depth documents on specific security topics and compliance.

Getting Started: Exam Essentials

Key term

Google Cloud Blog

Source for Google Cloud news, announcements, and articles.

Getting Started: Exam Essentials

Key term

Community Forums

Platforms for peer support and shared knowledge on Google Cloud.

Getting Started: Exam Essentials

Key term

Qwiklabs

Hands-on labs for practicing Google Cloud skills.

Getting Started: Exam Essentials

Key term

Shared Responsibility Model

Defines security duties between cloud provider and customer.

Getting Started: Exam Essentials

Key term

Defense-in-Depth

Layered security approach to protect data and systems.

Getting Started: Exam Essentials

Memory trick

Navigating Google Cloud Documentation and Resources

Docs, Best Practices, Blog, Community, Training: 'Do Better By Being Consistent, Trustworthy!'

Getting Started: Exam Essentials

Exam tip

Navigating Google Cloud Documentation and Resources

The exam often presents scenarios requiring you to identify the correct Google Cloud service or feature for a security requirement. Knowing where to find the authoritative answer in documentation or best practices is key. Keywords like 'compliance', 'encryption at rest/in transit', 'IAM roles', and 'audit logging' should immediately point you to specific documentation sections.

Getting Started: Exam Essentials

Common mistake

Navigating Google Cloud Documentation and Resources

Relying solely on external blogs or outdated articles instead of official Google Cloud documentation for critical details.

Getting Started: Exam Essentials

Common mistake

Navigating Google Cloud Documentation and Resources

Ignoring security best practice guides, leading to suboptimal or insecure configurations.

Getting Started: Exam Essentials

Common mistake

Navigating Google Cloud Documentation and Resources

Not checking the Google Cloud Blog for recent announcements that might impact security features or exam topics.

Getting Started: Exam Essentials

Key term

Member

An identity (user, service account, group) that can be granted access.

Identity & Access Control Fundamentals

Key term

Role

A collection of permissions that can be granted to a member.

Identity & Access Control Fundamentals

Key term

Permission

A specific authorization to perform an action on a resource.

Identity & Access Control Fundamentals

Key term

Policy

A set of role bindings attached to a resource, defining access.

Identity & Access Control Fundamentals

Key term

Least Privilege

Security principle: grant only necessary permissions.

Identity & Access Control Fundamentals

Key term

Resource Hierarchy

Organizational structure (org, folder, project, resource) for policies.

Identity & Access Control Fundamentals

Key term

Primitive Roles

Broad, predefined roles: Owner, Editor, Viewer.

Identity & Access Control Fundamentals

Memory trick

Mastering IAM: Principles, Roles, and Policies

Remember 'MRP': Members get Roles via Policies. This helps you recall the core components of an IAM binding.

Identity & Access Control Fundamentals

Exam tip

Mastering IAM: Principles, Roles, and Policies

Memorize the three primitive roles (Owner, Editor, Viewer) and understand their broad implications. The exam often tests scenarios where these roles are inappropriately used. Also, know that IAM policies are evaluated hierarchically and are 'allow-by-default' if any policy grants permission.

Identity & Access Control Fundamentals

Common mistake

Mastering IAM: Principles, Roles, and Policies

Granting primitive roles (Owner, Editor) instead of more specific predefined roles, leading to over-privileging.

Identity & Access Control Fundamentals

Common mistake

Mastering IAM: Principles, Roles, and Policies

Not using Google Groups for managing user access, making administration complex and error-prone.

Identity & Access Control Fundamentals

Common mistake

Mastering IAM: Principles, Roles, and Policies

Forgetting that IAM policies are inherited down the resource hierarchy, potentially granting unintended access.

Identity & Access Control Fundamentals

Key term

Custom Role

User-defined IAM role with specific permissions.

Identity & Access Control Fundamentals

Key term

Service Account

Non-human identity for applications/services.

Identity & Access Control Fundamentals

Key term

API Key

Simple string for project authentication to public APIs.

Identity & Access Control Fundamentals

Key term

Google-managed Key

Cryptographic key managed and rotated by Google.

Identity & Access Control Fundamentals

Key term

User-managed Key

Cryptographic key created and managed by the user.

Identity & Access Control Fundamentals

Key term

Key Rotation

Regularly changing cryptographic keys to enhance security.

Identity & Access Control Fundamentals

Key term

ETag

Optimistic concurrency control for resource updates.

Identity & Access Control Fundamentals

Memory trick

Custom Roles, Service Accounts, and API Key Management

C-S-A: Custom roles for Control, Service accounts for Systems, API keys for Access. Remember the order of increasing security risk.

Identity & Access Control Fundamentals

Exam tip

Custom Roles, Service Accounts, and API Key Management

Memorize that custom roles are project-level or organization-level resources. Service accounts are identities for applications, not users. API keys are for project identification to specific APIs, not for granting IAM permissions to identities. Always restrict API keys and prefer Google-managed service account keys.

Identity & Access Control Fundamentals

Common mistake

Custom Roles, Service Accounts, and API Key Management

Using predefined roles when a custom role would provide more granular control, leading to over-permissioning.

Identity & Access Control Fundamentals

Common mistake

Custom Roles, Service Accounts, and API Key Management

Embedding service account private keys directly into application code or version control systems.

Identity & Access Control Fundamentals

Common mistake

Custom Roles, Service Accounts, and API Key Management

Creating API keys without any restrictions (e.g., IP address, HTTP referrer, or API limitations), making them vulnerable if exposed.

Identity & Access Control Fundamentals

Key term

Cloud Audit Logs

Logs recording admin activity, data access, and system events.

Identity & Access Control Fundamentals

Key term

IAM Policy Analyzer

Tool to understand effective permissions for users/resources.

Identity & Access Control Fundamentals

Key term

Google Cloud Directory Sync (GCDS)

Synchronizes on-prem directories with Google Cloud identities.

Identity & Access Control Fundamentals

Key term

Security Command Center (SCC)

Centralized platform for security management and risk analysis.

Identity & Access Control Fundamentals

Key term

VPC Flow Logs

Records network flow information for VM instances.

Identity & Access Control Fundamentals

Key term

Admin Activity logs

Logs API calls and configuration changes for resources.

Identity & Access Control Fundamentals

Key term

Data Access logs

Logs API calls that read or modify user-provided data.

Identity & Access Control Fundamentals

Memory trick

Auditing IAM and Google Cloud Directory Sync

Audit Logs: A.D.S. - Admin, Data, System. Remember 'Always Detect Suspicious' activity!

Identity & Access Control Fundamentals

Exam tip

Auditing IAM and Google Cloud Directory Sync

The exam often tests the different types of Cloud Audit Logs (Admin Activity, Data Access, System Event) and which ones are enabled by default. Remember that Data Access logs require explicit enablement and are crucial for auditing data access.

Identity & Access Control Fundamentals

Common mistake

Auditing IAM and Google Cloud Directory Sync

Forgetting to enable Data Access logs, leading to blind spots during security investigations.

Identity & Access Control Fundamentals

Common mistake

Auditing IAM and Google Cloud Directory Sync

Not regularly reviewing IAM policies, which can result in privilege creep over time.

Identity & Access Control Fundamentals

Common mistake

Auditing IAM and Google Cloud Directory Sync

Assuming GCDS synchronizes passwords; it only syncs user and group attributes, not credentials.

Identity & Access Control Fundamentals

Key term

Identity Platform

Google Cloud service for customer identity and access management (CIAM).

Identity & Access Control Fundamentals

Key term

Workforce Identity Federation

Allows enterprise employees to access GCP using their existing IdP.

Identity & Access Control Fundamentals

Key term

CIAM

Customer Identity and Access Management; for external application users.

Identity & Access Control Fundamentals

Key term

Identity Provider (IdP)

System that authenticates users and asserts their identity.

Identity & Access Control Fundamentals

Key term

SAML 2.0

Security Assertion Markup Language; XML-based standard for exchanging auth data.

Identity & Access Control Fundamentals

Key term

OpenID Connect (OIDC)

Authentication layer on top of OAuth 2.0; for verifying user identity.

Identity & Access Control Fundamentals

Key term

Assertion

Cryptographically signed statement of identity from an IdP.

Identity & Access Control Fundamentals

Memory trick

Identity Platform & Workforce Identity Federation

Imagine a 'PLATFORM' for your 'CUSTOMERS' to stand on, and 'WORKFORCE' 'FEDERATING' (joining forces) with Google Cloud.

Identity & Access Control Fundamentals

Exam tip

Identity Platform & Workforce Identity Federation

Memorize the distinction: Identity Platform is for *customers* using your *applications*. Workforce Identity Federation is for your *employees* accessing *Google Cloud* resources. Look for keywords like 'customer login', 'mobile app users' for Identity Platform, and 'enterprise employees', 'existing IdP', 'access GCP' for Workforce Identity Federation.

Identity & Access Control Fundamentals

Common mistake

Identity Platform & Workforce Identity Federation

Confusing Identity Platform (CIAM) with Workforce Identity Federation (enterprise access to GCP).

Identity & Access Control Fundamentals

Common mistake

Identity Platform & Workforce Identity Federation

Trying to use Workforce Identity Federation for customer authentication in a custom application.

Identity & Access Control Fundamentals

Common mistake

Identity Platform & Workforce Identity Federation

Believing Identity Platform replaces Google's core IAM for managing access to GCP resources.

Identity & Access Control Fundamentals

Key term

Service Perimeter

A boundary around Google Cloud resources that restricts API access.

Network Security Architecture

Key term

Access Level

Conditions (e.g., IP, user) allowing trusted external access to a perimeter.

Network Security Architecture

Key term

Firewall Rule

Controls traffic to and from VM instances in a VPC network.

Network Security Architecture

Key term

Ingress Rule

A firewall rule that controls incoming traffic to VM instances.

Network Security Architecture

Key term

Egress Rule

A firewall rule that controls outgoing traffic from VM instances.

Network Security Architecture

Key term

Network Tag

A label applied to VM instances to group them for firewall rules.

Network Security Architecture

Key term

Implicit Rules

Default firewall rules present in every VPC network (e.g., deny all ingress).

Network Security Architecture

Memory trick

VPC Service Controls and Firewall Rules Deep Dive

To remember VPC Service Controls: 'Perimeters Control Service Data Exfiltration'. Each word reminds you of a key aspect.

Network Security Architecture

Exam tip

VPC Service Controls and Firewall Rules Deep Dive

The exam frequently tests your understanding of VPC Service Controls' primary purpose: preventing data exfiltration. Know that it protects against unauthorized API calls and data movement to untrusted locations. For firewall rules, remember the implicit rules and how priority works.

Network Security Architecture

Common mistake

VPC Service Controls and Firewall Rules Deep Dive

Forgetting that VPC Service Controls primarily prevent data exfiltration, not all security threats.

Network Security Architecture

Common mistake

VPC Service Controls and Firewall Rules Deep Dive

Misunderstanding firewall rule priority, leading to unintended traffic flow or blocks.

Network Security Architecture

Common mistake

VPC Service Controls and Firewall Rules Deep Dive

Over-permissive firewall rules, exposing services unnecessarily to the internet or internal networks.

Network Security Architecture

Key term

Cloud Armor

DDoS protection and WAF service at Google's network edge.

Network Security Architecture

Key term

WAF

Web Application Firewall; filters HTTP traffic to protect web apps.

Network Security Architecture

Key term

DDoS Protection

Defends against distributed denial-of-service attacks.

Network Security Architecture

Key term

Cloud CDN

Content Delivery Network; caches content closer to users.

Network Security Architecture

Key term

Cloud DNS

High-performance, global DNS service for domain name resolution.

Network Security Architecture

Key term

DNSSEC

DNS Security Extensions; cryptographically signs DNS responses for authenticity.

Network Security Architecture

Key term

Private DNS Zone

DNS zone for internal name resolution within a VPC network.

Network Security Architecture

Key term

Adaptive Protection

Cloud Armor feature using ML to detect and mitigate novel attacks.

Network Security Architecture

Memory trick

Cloud Armor, CDN, and DNS for Network Protection

To remember the services: 'CAD' for 'Cloud Armor Defends' (DDoS/WAF), 'CDN Delivers' (Content), and 'DNS Directs' (Traffic).

Network Security Architecture

Exam tip

Cloud Armor, CDN, and DNS for Network Protection

The exam frequently tests your understanding of Cloud Armor's capabilities, especially its integration with Load Balancing and its WAF features for HTTP(S) traffic. Be ready to distinguish between Cloud Armor's DDoS protection and WAF functions.

Network Security Architecture

Common mistake

Cloud Armor, CDN, and DNS for Network Protection

Assuming Cloud CDN alone provides comprehensive WAF protection; it needs Cloud Armor for that.

Network Security Architecture

Common mistake

Cloud Armor, CDN, and DNS for Network Protection

Forgetting that Cloud Armor integrates with Load Balancers, not directly with individual VMs.

Network Security Architecture

Common mistake

Cloud Armor, CDN, and DNS for Network Protection

Not enabling DNSSEC on public Cloud DNS zones, leaving them vulnerable to spoofing.

Network Security Architecture

Key term

Global External Load Balancer

Distributes public internet traffic globally, offering DDoS protection and high availability.

Network Security Architecture

Key term

Cloud VPN

Establishes secure, encrypted IPsec tunnels over the public internet between networks.

Network Security Architecture

Key term

HA VPN

Highly available Cloud VPN with two interfaces and dynamic BGP routing for redundancy.

Network Security Architecture

Key term

Cloud Interconnect

Provides high-bandwidth, low-latency private connections between on-premises and Google Cloud.

Network Security Architecture

Key term

Dedicated Interconnect

Direct physical connection from your data center to a Google edge location.

Network Security Architecture

Key term

Partner Interconnect

Connects your on-premises network to Google Cloud via a service provider's network.

Network Security Architecture

Key term

VLAN Attachment

A logical connection over a Cloud Interconnect that carries private IP traffic.

Network Security Architecture

Memory trick

Load Balancing, VPN, and Interconnect Security

VPN is 'Via Public Net' for secure internet connections. Interconnect is 'In Private' for dedicated, direct links.

Network Security Architecture

Exam tip

Load Balancing, VPN, and Interconnect Security

The exam often tests your ability to choose the *most appropriate* connectivity solution based on specific requirements like bandwidth, latency, security, and cost. Memorize the key differentiators between Cloud VPN, Dedicated Interconnect, and Partner Interconnect.

Network Security Architecture

Common mistake

Load Balancing, VPN, and Interconnect Security

Confusing Cloud VPN with Cloud Interconnect: VPN uses the public internet with encryption; Interconnect uses a private, dedicated connection.

Network Security Architecture

Common mistake

Load Balancing, VPN, and Interconnect Security

Underestimating the security benefits of GELBs: They are not just for load balancing; they are a critical first line of defense.

Network Security Architecture

Common mistake

Load Balancing, VPN, and Interconnect Security

Choosing Classic VPN for production workloads: HA VPN provides the necessary redundancy and dynamic routing for critical applications.

Network Security Architecture

Key term

Network Intelligence Center

Centralized network monitoring and diagnostics.

Network Security Architecture

Key term

Private Google Access

VMs access Google services via internal IPs.

Network Security Architecture

Key term

Private Service Connect

Private consumption of services across VPCs.

Network Security Architecture

Key term

Service Producer

VPC publishing a service via Private Service Connect.

Network Security Architecture

Key term

Service Consumer

VPC accessing a service via Private Service Connect.

Network Security Architecture

Key term

Internal IP Address

An IP address not routable on the public internet.

Network Security Architecture

Memory trick

Network Intelligence, Security, & Private Access

PGA is for Google APIs, PSC is for all Services (and more Control!).

Network Security Architecture

Exam tip

Network Intelligence, Security, & Private Access

The exam often tests the distinction between Private Google Access and Private Service Connect. Remember: Private Google Access is simpler, subnet-level, for VMs to Google APIs. Private Service Connect is more granular, uses endpoints, and supports third-party/custom services and consumer-side firewall rules.

Network Security Architecture

Common mistake

Network Intelligence, Security, & Private Access

Confusing Private Google Access with Private Service Connect; remember their distinct use cases and configuration.

Network Security Architecture

Common mistake

Network Intelligence, Security, & Private Access

Forgetting to enable Private Google Access on the subnet when trying to access Google APIs from VMs without external IPs.

Network Security Architecture

Common mistake

Network Intelligence, Security, & Private Access

Not understanding that Private Service Connect can be used for both Google-managed and third-party/custom services.

Network Security Architecture

Key term

Principle of Least Privilege

Granting only necessary permissions to perform a task.

Securing Your Data in Google Cloud

Key term

Bucket Lock

Makes Cloud Storage retention policies immutable for compliance.

Securing Your Data in Google Cloud

Key term

Object Versioning

Keeps multiple versions of an object in Cloud Storage.

Securing Your Data in Google Cloud

Key term

Customer-Managed Encryption Keys (CMEK)

Encryption keys managed by the customer using Cloud KMS.

Securing Your Data in Google Cloud

Key term

Authorized View

BigQuery view that grants access to specific data without underlying table access.

Securing Your Data in Google Cloud

Key term

Row-level Security

Restricting access to specific rows in a BigQuery table.

Securing Your Data in Google Cloud

Key term

Column-level Security

Restricting access to specific columns in a BigQuery table.

Securing Your Data in Google Cloud

Key term

Data Residency

Physical location where data is stored and processed.

Securing Your Data in Google Cloud

Memory trick

Cloud Storage and BigQuery Security Best Practices

For BigQuery security, think 'BIG ACLS': BigQuery, IAM, Granular, Access Control, CMEK, Logging, Security.

Securing Your Data in Google Cloud

Exam tip

Cloud Storage and BigQuery Security Best Practices

The exam frequently tests on the differences and use cases for Google-managed, customer-supplied (CSEK), and customer-managed (CMEK) encryption keys for both Cloud Storage and BigQuery. Memorize when each is appropriate and the level of control it provides.

Securing Your Data in Google Cloud

Common mistake

Cloud Storage and BigQuery Security Best Practices

Granting primitive roles (Owner, Editor) instead of specific predefined or custom roles.

Securing Your Data in Google Cloud

Common mistake

Cloud Storage and BigQuery Security Best Practices

Not enabling Bucket Lock for compliance-driven data retention policies.

Securing Your Data in Google Cloud

Common mistake

Cloud Storage and BigQuery Security Best Practices

Forgetting that data is encrypted at rest by default, but not understanding the options for key management (CSEK/CMEK).

Securing Your Data in Google Cloud

Key term

Cloud SQL

Fully managed relational database service on Google Cloud.

Securing Your Data in Google Cloud

Key term

Secret Manager

Service for securely storing and managing sensitive data like API keys.

Securing Your Data in Google Cloud

Key term

Private IP

Internal network connectivity for Cloud SQL, reducing public exposure.

Securing Your Data in Google Cloud

Key term

Authorized Networks

CIDR ranges allowed to connect to Cloud SQL via public IP.

Securing Your Data in Google Cloud

Key term

Cloud SQL Auth Proxy

Securely connects applications to Cloud SQL without public IPs.

Securing Your Data in Google Cloud

Key term

SSL/TLS

Encryption protocol for securing data in transit between client and server.

Securing Your Data in Google Cloud

Memory trick

Cloud SQL Security and Secret Manager

SQL SECRETS: S-Service Accounts, E-Encryption (SSL/TLS), C-Cloud SQL Auth Proxy, R-Restricted Networks, E-External IPs (Authorized Networks), T-Trusted Sources (IAM), S-Secret Manager.

Securing Your Data in Google Cloud

Exam tip

Cloud SQL Security and Secret Manager

The exam frequently tests on secure connectivity methods for Cloud SQL. Memorize that Private IP is preferred for internal GCP services, and Authorized Networks are for public IP. Also, know that Secret Manager is the recommended service for storing database credentials, not hardcoding or environment variables.

Securing Your Data in Google Cloud

Common mistake

Cloud SQL Security and Secret Manager

Hardcoding database credentials directly into application code or configuration files.

Securing Your Data in Google Cloud

Common mistake

Cloud SQL Security and Secret Manager

Using public IP for Cloud SQL without restricting authorized networks, or opening it to '0.0.0.0/0'.

Securing Your Data in Google Cloud

Common mistake

Cloud SQL Security and Secret Manager

Not enforcing SSL/TLS for all Cloud SQL connections, even within private networks.

Securing Your Data in Google Cloud

Key term

Key Management Service (KMS)

Google Cloud service for managing cryptographic keys.

Securing Your Data in Google Cloud

Key term

Customer-Supplied Encryption Keys (CSEK)

Encryption keys generated and managed by the customer outside Google Cloud.

Securing Your Data in Google Cloud

Key term

Key Ring

A logical grouping of cryptographic keys within KMS.

Securing Your Data in Google Cloud

Key term

Key Version

A specific instance of a cryptographic key, used for rotation.

Securing Your Data in Google Cloud

Key term

Symmetric Key

A single key used for both encryption and decryption.

Securing Your Data in Google Cloud

Key term

Asymmetric Key

A pair of keys (public/private) used for encryption/decryption or signing/verification.

Securing Your Data in Google Cloud

Memory trick

KMS Implementation and Best Practices

KMS: Keep My Secrets safe. CMEK: Customer Manages Every Key (in KMS). CSEK: Customer Supplies Every Key (from outside).

Securing Your Data in Google Cloud

Exam tip

KMS Implementation and Best Practices

The exam often tests the distinction between CMEK and CSEK. Remember that CMEK keys are managed within KMS, while CSEK keys are managed entirely by the customer outside Google Cloud and provided on demand. Know which services support CMEK (most) vs. CSEK (Cloud Storage, Compute Engine).

Securing Your Data in Google Cloud

Common mistake

KMS Implementation and Best Practices

Confusing CMEK with CSEK: CMEK keys are in KMS; CSEK keys are external and supplied.

Securing Your Data in Google Cloud

Common mistake

KMS Implementation and Best Practices

Neglecting key rotation: Failing to set up automatic rotation increases risk if a key version is compromised.

Securing Your Data in Google Cloud

Common mistake

KMS Implementation and Best Practices

Over-privileging IAM roles for KMS: Granting broader permissions than necessary violates the principle of least privilege.

Securing Your Data in Google Cloud

Key term

Data Loss Prevention (DLP)

Service to discover, classify, and protect sensitive data.

Securing Your Data in Google Cloud

Key term

InfoType

Pre-defined or custom detector for sensitive data patterns.

Securing Your Data in Google Cloud

Key term

Redaction

Removing sensitive data, replacing it with a placeholder.

Securing Your Data in Google Cloud

Key term

Tokenization

Replacing sensitive data with a non-sensitive token.

Securing Your Data in Google Cloud

Key term

Assured Workloads

Service to meet compliance and residency requirements.

Securing Your Data in Google Cloud

Key term

Compliance Regime

Set of rules (e.g., HIPAA, FedRAMP) enforced by Assured Workloads.

Securing Your Data in Google Cloud

Memory trick

Data Loss Prevention (DLP) and Assured Workloads

DLP is for Detecting, Locating, and Protecting data. Assured Workloads Assures your Workloads meet regulations.

Securing Your Data in Google Cloud

Exam tip

Data Loss Prevention (DLP) and Assured Workloads

On the exam, be prepared to distinguish between DLP's role in content inspection and Assured Workloads' role in environmental compliance. Keywords like 'sensitive data discovery', 'redaction', 'infoTypes' point to DLP. Keywords like 'regulatory compliance', 'data residency', 'personnel access controls' point to Assured Workloads.

Securing Your Data in Google Cloud

Common mistake

Data Loss Prevention (DLP) and Assured Workloads

Confusing DLP with encryption: DLP identifies and acts on sensitive data content, while encryption protects data at rest or in transit regardless of its content.

Securing Your Data in Google Cloud

Common mistake

Data Loss Prevention (DLP) and Assured Workloads

Assuming Assured Workloads automatically protects all data: It provides a compliant environment, but you still need to configure services like DLP within that environment for content-level protection.

Securing Your Data in Google Cloud

Common mistake

Data Loss Prevention (DLP) and Assured Workloads

Not specifying appropriate infoTypes in DLP: If you don't tell DLP what to look for, it won't find it, leading to potential data exposure.

Securing Your Data in Google Cloud

Key term

System Event logs

Records actions by Google Cloud systems modifying resources.

Security Operations & Monitoring

Key term

Findings

Security issues or vulnerabilities identified by SCC.

Security Operations & Monitoring

Key term

Log Sink

Mechanism to export Cloud Audit Logs to other destinations.

Security Operations & Monitoring

Key term

Event Threat Detection

SCC service using ML to detect threats from logs.

Security Operations & Monitoring

Memory trick

Security Command Center and Cloud Audit Logs

SCC: See Critical Concerns. Audit Logs: All Users Did It (and when).

Security Operations & Monitoring

Exam tip

Security Command Center and Cloud Audit Logs

On the exam, remember that Admin Activity and System Event logs are enabled by default, but Data Access logs (except for BigQuery) require explicit enablement. SCC is an organization-level service, not project-level.

Security Operations & Monitoring

Common mistake

Security Command Center and Cloud Audit Logs

Forgetting to enable Data Access logs for non-BigQuery services, leading to incomplete audit trails.

Security Operations & Monitoring

Common mistake

Security Command Center and Cloud Audit Logs

Not activating SCC at the organization level, missing out on centralized security visibility.

Security Operations & Monitoring

Common mistake

Security Command Center and Cloud Audit Logs

Confusing SCC's role with Cloud Logging; SCC analyzes and presents findings, while Logging stores the raw events.

Security Operations & Monitoring

Key term

Cloud Monitoring

Service for collecting metrics, events, and metadata to provide insights into resource usage and performance.

Security Operations & Monitoring

Key term

Cloud Logging

Centralized service for collecting, storing, and analyzing logs from Google Cloud and other sources.

Security Operations & Monitoring

Key term

Chronicle Security Operations

Google Cloud's cloud-native SIEM and SOAR solution for enterprise-wide security analytics.

Security Operations & Monitoring

Key term

SIEM

Security Information and Event Management; aggregates and analyzes security events.

Security Operations & Monitoring

Key term

SOAR

Security Orchestration, Automation, and Response; automates security operations tasks.

Security Operations & Monitoring

Key term

YARA-L

Chronicle's rule language for expressing threat detection logic.

Security Operations & Monitoring

Memory trick

Cloud Monitoring, Logging, and Chronicle for Security

My Logs Chronically Secure: Monitoring for metrics, Logging for logs, Chronicle for SIEM/SOAR, all working together for Security.

Security Operations & Monitoring

Exam tip

Cloud Monitoring, Logging, and Chronicle for Security

Memorize the core function of each service: Monitoring for metrics/alerts, Logging for forensic records, and Chronicle for enterprise-scale SIEM/SOAR. Understand how they integrate.

Security Operations & Monitoring

Common mistake

Cloud Monitoring, Logging, and Chronicle for Security

Confusing Cloud Monitoring with Cloud Logging: Monitoring focuses on metrics and alerts, Logging on the actual event records.

Security Operations & Monitoring

Common mistake

Cloud Monitoring, Logging, and Chronicle for Security

Underestimating Chronicle's scale: It's designed for petabytes of security data across an entire enterprise, not just GCP.

Security Operations & Monitoring

Common mistake

Cloud Monitoring, Logging, and Chronicle for Security

Neglecting to configure Log Sinks: Without proper sinks, critical logs might not reach the necessary analysis tools or archives.

Security Operations & Monitoring

Key term

Event Threat Detection (ETD)

Scans Cloud Logging for advanced threats like cryptomining.

Security Operations & Monitoring

Key term

Container Threat Detection (CTD)

Monitors container runtime for attacks and anomalous behavior.

Security Operations & Monitoring

Key term

Web Security Scanner (WSS)

Scans web applications for common vulnerabilities like XSS.

Security Operations & Monitoring

Key term

Security Command Center

Centralized platform for security management and findings.

Security Operations & Monitoring

Key term

Finding

A detected security issue or vulnerability reported by a service.

Security Operations & Monitoring

Key term

Agentless

Security monitoring without requiring software agents on instances.

Security Operations & Monitoring

Key term

Threat Intelligence

Data about known threats, vulnerabilities, and attack methods.

Security Operations & Monitoring

Memory trick

Threat Detection: Event, Container, and Web Scanners

To remember the three scanners: E.C.W. - 'Every Cloud Workload' needs scanning. E for Event, C for Container, W for Web.

Security Operations & Monitoring

Exam tip

Threat Detection: Event, Container, and Web Scanners

The exam often tests the specific capabilities and integrations of these services. Remember that ETD and CTD are premium features of Security Command Center, while WSS is a standalone service that integrates with SCC. Keywords to spot include 'runtime analysis for containers' (CTD), 'log analysis for advanced threats' (ETD), and 'web application vulnerability scanning' (WSS).

Security Operations & Monitoring

Common mistake

Threat Detection: Event, Container, and Web Scanners

Confusing the scope of each scanner (e.g., thinking WSS scans VMs).

Security Operations & Monitoring

Common mistake

Threat Detection: Event, Container, and Web Scanners

Forgetting that ETD and CTD are part of Security Command Center Premium.

Security Operations & Monitoring

Common mistake

Threat Detection: Event, Container, and Web Scanners

Not understanding that these services generate 'findings' in SCC.

Security Operations & Monitoring

Key term

Security Health Analytics

Scans GCP resources for misconfigurations and compliance violations.

Security Operations & Monitoring

Key term

Policy Intelligence

Suite of tools for understanding and managing IAM policies.

Security Operations & Monitoring

Key term

Policy Analyzer

Helps understand who has access to which resources.

Security Operations & Monitoring

Key term

Policy Troubleshooter

Diagnoses why a user has or doesn't have access.

Security Operations & Monitoring

Key term

Policy Simulator

Tests the impact of IAM policy changes before deployment.

Security Operations & Monitoring

Key term

Recommender

Provides suggestions for rightsizing IAM roles and permissions.

Security Operations & Monitoring

Key term

Security Posture

Overall security status and readiness of an organization.

Security Operations & Monitoring

Memory trick

Security Health Analytics and Policy Intelligence

SHA for 'Scan for Health Alerts,' PI for 'Policies Investigated.'

Security Operations & Monitoring

Exam tip

Security Health Analytics and Policy Intelligence

The exam often tests your understanding of how Security Health Analytics integrates with Security Command Center and its role in identifying misconfigurations. For Policy Intelligence, focus on the individual tools (Analyzer, Troubleshooter, Simulator, Recommender) and their specific functions in IAM management. Keywords to spot include 'misconfiguration detection,' 'IAM policy optimization,' and 'principle of least privilege.'

Security Operations & Monitoring

Common mistake

Security Health Analytics and Policy Intelligence

Confusing Security Health Analytics with Cloud Monitoring; SHA focuses on security misconfigurations, not general operational metrics.

Security Operations & Monitoring

Common mistake

Security Health Analytics and Policy Intelligence

Not understanding that Policy Intelligence is a suite of tools, not a single service, each with a distinct function.

Security Operations & Monitoring

Common mistake

Security Health Analytics and Policy Intelligence

Forgetting that Policy Simulator is for testing changes *before* they are applied, preventing unintended access issues.

Security Operations & Monitoring

Key term

Organization Resource

The root node in the Google Cloud resource hierarchy, representing a company.

Compliance & Governance

Key term

Folder

A container for projects and other folders, used for grouping and policy inheritance.

Compliance & Governance

Key term

Project

The base unit for enabling services, managing APIs, and billing in Google Cloud.

Compliance & Governance

Key term

Organization Policy Service

A service to programmatically control Google Cloud resources via constraints.

Compliance & Governance

Key term

Constraint

A predefined restriction on a Google Cloud service or resource, enforced by policies.

Compliance & Governance

Key term

Policy Inheritance

Policies applied at a higher level in the hierarchy also apply to lower levels.

Compliance & Governance

Memory trick

Resource Manager and Organization Policy Service

ORG-FOLD-PROJ-RES: Organize Folders, Projects, and Resources in a neat hierarchy!

Compliance & Governance

Exam tip

Resource Manager and Organization Policy Service

The exam often tests your understanding of the resource hierarchy and how Organization Policies differ from IAM. Look for keywords like 'centralized control', 'enforce guardrails', or 'prevent specific resource configurations' when identifying Organization Policy questions. Remember that Organization Policies define 'what' can be done, not 'who' can do it.

Compliance & Governance

Common mistake

Resource Manager and Organization Policy Service

Confusing Organization Policies with IAM policies: IAM controls 'who can do what', while Organization Policies control 'what can be done' or 'how resources can be configured'.

Compliance & Governance

Common mistake

Resource Manager and Organization Policy Service

Not testing policies in a non-production environment: Applying a restrictive policy directly to production can cause service outages.

Compliance & Governance

Common mistake

Resource Manager and Organization Policy Service

Forgetting about policy inheritance: A policy set at the Organization level affects everything below it, which can lead to unintended consequences if not considered.

Compliance & Governance

Key term

Essential Contacts

Designated individuals/groups for critical Google Cloud notifications.

Compliance & Governance

Key term

Access Transparency

Logs Google administrator access to customer content for auditing.

Compliance & Governance

Key term

Access Approval

Requires explicit customer consent for Google personnel to access data.

Compliance & Governance

Key term

Compliance

Adherence to rules, regulations, and standards (e.g., HIPAA, GDPR).

Compliance & Governance

Key term

Audit Trail

A chronological record of events to reconstruct activities.

Compliance & Governance

Memory trick

Essential Contacts, Access Transparency, and Approval

Imagine an 'EAT' sandwich: Essential Contacts for the bread (foundation of info), Access Approval for the filling (your control), and Access Transparency for the transparent wrapper (visibility of everything).

Compliance & Governance

Exam tip

Essential Contacts, Access Transparency, and Approval

Memorize the distinct purpose of each service: Essential Contacts for *notifications*, Access Transparency for *visibility/logging*, and Access Approval for *control/explicit consent*. The exam often tests your ability to differentiate these.

Compliance & Governance

Common mistake

Essential Contacts, Access Transparency, and Approval

Confusing Access Transparency (logging) with Access Approval (consent). Transparency logs *after* approval (or attempted access), Approval *before* access.

Compliance & Governance

Common mistake

Essential Contacts, Access Transparency, and Approval

Not configuring Essential Contacts at all levels (org, folder, project) leading to missed critical alerts for specific teams.

Compliance & Governance

Common mistake

Essential Contacts, Access Transparency, and Approval

Assuming Access Transparency prevents access; it only logs it. Access Approval is what provides the preventative control.

Compliance & Governance

Key term

Certificate Authority Service (CAS)

Managed Google Cloud service for private PKI.

Compliance & Governance

Key term

X.509 Certificates

Standard format for public key certificates.

Compliance & Governance

Key term

Private PKI

Internal Public Key Infrastructure for private networks.

Compliance & Governance

Key term

Binary Authorization

Enforces deployment policies for container images.

Compliance & Governance

Key term

Attestation

Cryptographic proof an image passed a check.

Compliance & Governance

Key term

Attestor

Trusted entity that signs attestations.

Compliance & Governance

Key term

Software Supply Chain Security

Securing software from development to deployment.

Compliance & Governance

Memory trick

Certificate Authority Service & Binary Authorization

CAS for 'Certificates Are Secure'; Binary Authorization for 'Block Bad Binaries'.

Compliance & Governance

Exam tip

Certificate Authority Service & Binary Authorization

The exam often tests the *purpose* of these services. For CAS, think 'private PKI management' and 'internal certificates.' For Binary Authorization, think 'deployment policy enforcement' and 'supply chain security' for containerized workloads (GKE, Cloud Run, Anthos). Keywords like 'attestations' and 'attestors' are key for Binary Authorization.

Compliance & Governance

Common mistake

Certificate Authority Service & Binary Authorization

Confusing CAS with public CAs like Let's Encrypt; CAS is for *private* certificates.

Compliance & Governance

Common mistake

Certificate Authority Service & Binary Authorization

Thinking Binary Authorization scans for vulnerabilities; it *enforces* that images *have been* scanned (via attestations), it doesn't do the scanning itself.

Compliance & Governance

Common mistake

Certificate Authority Service & Binary Authorization

Forgetting that Binary Authorization applies to GKE, Cloud Run, and Anthos, not arbitrary VMs.

Compliance & Governance

Key term

Security Policy

Rules and procedures for protecting an organization's information assets.

Compliance & Governance

Memory trick

Security Policy Enforcement and Compliance Strategies

For 'Shared Responsibility Model,' remember 'Google is OF the cloud, you are IN the cloud.'

Compliance & Governance

Exam tip

Security Policy Enforcement and Compliance Strategies

The exam frequently tests your understanding of the shared responsibility model and which Google Cloud service addresses specific compliance challenges (e.g., 'preventing data exfiltration' points to VPC Service Controls, 'enforcing organizational-wide constraints' points to Organization Policy Service).

Compliance & Governance

Common mistake

Security Policy Enforcement and Compliance Strategies

Confusing Google's responsibility for 'security of the cloud' with the customer's responsibility for 'security in the cloud.'

Compliance & Governance

Common mistake

Security Policy Enforcement and Compliance Strategies

Believing that simply enabling a Google Cloud service automatically makes you compliant with all regulations; configuration is key.

Compliance & Governance

Common mistake

Security Policy Enforcement and Compliance Strategies

Underestimating the importance of continuous monitoring and auditing in maintaining compliance over time.

Compliance & Governance