Professional Cloud Security Engineer (PCSE)
Google Cloud certification for securing cloud deployments.
Getting Started: Exam Essentials
Free knowledge base
Everything from the course in one searchable place: 250 entries. Use it to review before a practice test or look up a word you forgot.
250 results
Google Cloud certification for securing cloud deployments.
Getting Started: Exam Essentials
Major content areas covered by the certification exam.
Getting Started: Exam Essentials
Method where raw scores are converted to a standardized score.
Getting Started: Exam Essentials
Question with one correct answer among several options.
Getting Started: Exam Essentials
Question with two or more correct answers from a list.
Getting Started: Exam Essentials
Identity and Access Management; controls who can do what.
Getting Started: Exam Essentials
Creates security perimeters around sensitive data and services.
Getting Started: Exam Essentials
Cloud Key Management Service; manages cryptographic keys.
Getting Started: Exam Essentials
To remember the domains: 'A Network Data Operation Complies'. (Access, Network, Data, Operations, Compliance)
Getting Started: Exam Essentials
The exam is 2 hours long, with multiple-choice and multiple-select questions. There are no public passing scores; it uses scaled scoring. Memorize the five main exam domains.
Getting Started: Exam Essentials
Focusing too much on theoretical knowledge without understanding practical application.
Getting Started: Exam Essentials
Not reviewing the official exam guide for the most current domain breakdown and topics.
Getting Started: Exam Essentials
Underestimating the importance of hands-on experience with Google Cloud security services.
Getting Started: Exam Essentials
Authoritative Google Cloud service guides and references.
Getting Started: Exam Essentials
In-depth documents on specific security topics and compliance.
Getting Started: Exam Essentials
Source for Google Cloud news, announcements, and articles.
Getting Started: Exam Essentials
Platforms for peer support and shared knowledge on Google Cloud.
Getting Started: Exam Essentials
Hands-on labs for practicing Google Cloud skills.
Getting Started: Exam Essentials
Defines security duties between cloud provider and customer.
Getting Started: Exam Essentials
Layered security approach to protect data and systems.
Getting Started: Exam Essentials
Docs, Best Practices, Blog, Community, Training: 'Do Better By Being Consistent, Trustworthy!'
Getting Started: Exam Essentials
The exam often presents scenarios requiring you to identify the correct Google Cloud service or feature for a security requirement. Knowing where to find the authoritative answer in documentation or best practices is key. Keywords like 'compliance', 'encryption at rest/in transit', 'IAM roles', and 'audit logging' should immediately point you to specific documentation sections.
Getting Started: Exam Essentials
Relying solely on external blogs or outdated articles instead of official Google Cloud documentation for critical details.
Getting Started: Exam Essentials
Ignoring security best practice guides, leading to suboptimal or insecure configurations.
Getting Started: Exam Essentials
Not checking the Google Cloud Blog for recent announcements that might impact security features or exam topics.
Getting Started: Exam Essentials
An identity (user, service account, group) that can be granted access.
Identity & Access Control Fundamentals
A collection of permissions that can be granted to a member.
Identity & Access Control Fundamentals
A specific authorization to perform an action on a resource.
Identity & Access Control Fundamentals
A set of role bindings attached to a resource, defining access.
Identity & Access Control Fundamentals
Security principle: grant only necessary permissions.
Identity & Access Control Fundamentals
Organizational structure (org, folder, project, resource) for policies.
Identity & Access Control Fundamentals
Broad, predefined roles: Owner, Editor, Viewer.
Identity & Access Control Fundamentals
Remember 'MRP': Members get Roles via Policies. This helps you recall the core components of an IAM binding.
Identity & Access Control Fundamentals
Memorize the three primitive roles (Owner, Editor, Viewer) and understand their broad implications. The exam often tests scenarios where these roles are inappropriately used. Also, know that IAM policies are evaluated hierarchically and are 'allow-by-default' if any policy grants permission.
Identity & Access Control Fundamentals
Granting primitive roles (Owner, Editor) instead of more specific predefined roles, leading to over-privileging.
Identity & Access Control Fundamentals
Not using Google Groups for managing user access, making administration complex and error-prone.
Identity & Access Control Fundamentals
Forgetting that IAM policies are inherited down the resource hierarchy, potentially granting unintended access.
Identity & Access Control Fundamentals
User-defined IAM role with specific permissions.
Identity & Access Control Fundamentals
Non-human identity for applications/services.
Identity & Access Control Fundamentals
Simple string for project authentication to public APIs.
Identity & Access Control Fundamentals
Cryptographic key managed and rotated by Google.
Identity & Access Control Fundamentals
Cryptographic key created and managed by the user.
Identity & Access Control Fundamentals
Regularly changing cryptographic keys to enhance security.
Identity & Access Control Fundamentals
Optimistic concurrency control for resource updates.
Identity & Access Control Fundamentals
C-S-A: Custom roles for Control, Service accounts for Systems, API keys for Access. Remember the order of increasing security risk.
Identity & Access Control Fundamentals
Memorize that custom roles are project-level or organization-level resources. Service accounts are identities for applications, not users. API keys are for project identification to specific APIs, not for granting IAM permissions to identities. Always restrict API keys and prefer Google-managed service account keys.
Identity & Access Control Fundamentals
Using predefined roles when a custom role would provide more granular control, leading to over-permissioning.
Identity & Access Control Fundamentals
Embedding service account private keys directly into application code or version control systems.
Identity & Access Control Fundamentals
Creating API keys without any restrictions (e.g., IP address, HTTP referrer, or API limitations), making them vulnerable if exposed.
Identity & Access Control Fundamentals
Logs recording admin activity, data access, and system events.
Identity & Access Control Fundamentals
Tool to understand effective permissions for users/resources.
Identity & Access Control Fundamentals
Synchronizes on-prem directories with Google Cloud identities.
Identity & Access Control Fundamentals
Centralized platform for security management and risk analysis.
Identity & Access Control Fundamentals
Records network flow information for VM instances.
Identity & Access Control Fundamentals
Logs API calls and configuration changes for resources.
Identity & Access Control Fundamentals
Logs API calls that read or modify user-provided data.
Identity & Access Control Fundamentals
Audit Logs: A.D.S. - Admin, Data, System. Remember 'Always Detect Suspicious' activity!
Identity & Access Control Fundamentals
The exam often tests the different types of Cloud Audit Logs (Admin Activity, Data Access, System Event) and which ones are enabled by default. Remember that Data Access logs require explicit enablement and are crucial for auditing data access.
Identity & Access Control Fundamentals
Forgetting to enable Data Access logs, leading to blind spots during security investigations.
Identity & Access Control Fundamentals
Not regularly reviewing IAM policies, which can result in privilege creep over time.
Identity & Access Control Fundamentals
Assuming GCDS synchronizes passwords; it only syncs user and group attributes, not credentials.
Identity & Access Control Fundamentals
Google Cloud service for customer identity and access management (CIAM).
Identity & Access Control Fundamentals
Allows enterprise employees to access GCP using their existing IdP.
Identity & Access Control Fundamentals
Customer Identity and Access Management; for external application users.
Identity & Access Control Fundamentals
System that authenticates users and asserts their identity.
Identity & Access Control Fundamentals
Security Assertion Markup Language; XML-based standard for exchanging auth data.
Identity & Access Control Fundamentals
Authentication layer on top of OAuth 2.0; for verifying user identity.
Identity & Access Control Fundamentals
Cryptographically signed statement of identity from an IdP.
Identity & Access Control Fundamentals
Imagine a 'PLATFORM' for your 'CUSTOMERS' to stand on, and 'WORKFORCE' 'FEDERATING' (joining forces) with Google Cloud.
Identity & Access Control Fundamentals
Memorize the distinction: Identity Platform is for *customers* using your *applications*. Workforce Identity Federation is for your *employees* accessing *Google Cloud* resources. Look for keywords like 'customer login', 'mobile app users' for Identity Platform, and 'enterprise employees', 'existing IdP', 'access GCP' for Workforce Identity Federation.
Identity & Access Control Fundamentals
Confusing Identity Platform (CIAM) with Workforce Identity Federation (enterprise access to GCP).
Identity & Access Control Fundamentals
Trying to use Workforce Identity Federation for customer authentication in a custom application.
Identity & Access Control Fundamentals
Believing Identity Platform replaces Google's core IAM for managing access to GCP resources.
Identity & Access Control Fundamentals
A boundary around Google Cloud resources that restricts API access.
Network Security Architecture
Conditions (e.g., IP, user) allowing trusted external access to a perimeter.
Network Security Architecture
Controls traffic to and from VM instances in a VPC network.
Network Security Architecture
A firewall rule that controls incoming traffic to VM instances.
Network Security Architecture
A firewall rule that controls outgoing traffic from VM instances.
Network Security Architecture
A label applied to VM instances to group them for firewall rules.
Network Security Architecture
Default firewall rules present in every VPC network (e.g., deny all ingress).
Network Security Architecture
To remember VPC Service Controls: 'Perimeters Control Service Data Exfiltration'. Each word reminds you of a key aspect.
Network Security Architecture
The exam frequently tests your understanding of VPC Service Controls' primary purpose: preventing data exfiltration. Know that it protects against unauthorized API calls and data movement to untrusted locations. For firewall rules, remember the implicit rules and how priority works.
Network Security Architecture
Forgetting that VPC Service Controls primarily prevent data exfiltration, not all security threats.
Network Security Architecture
Misunderstanding firewall rule priority, leading to unintended traffic flow or blocks.
Network Security Architecture
Over-permissive firewall rules, exposing services unnecessarily to the internet or internal networks.
Network Security Architecture
DDoS protection and WAF service at Google's network edge.
Network Security Architecture
Web Application Firewall; filters HTTP traffic to protect web apps.
Network Security Architecture
Defends against distributed denial-of-service attacks.
Network Security Architecture
Content Delivery Network; caches content closer to users.
Network Security Architecture
High-performance, global DNS service for domain name resolution.
Network Security Architecture
DNS Security Extensions; cryptographically signs DNS responses for authenticity.
Network Security Architecture
DNS zone for internal name resolution within a VPC network.
Network Security Architecture
Cloud Armor feature using ML to detect and mitigate novel attacks.
Network Security Architecture
To remember the services: 'CAD' for 'Cloud Armor Defends' (DDoS/WAF), 'CDN Delivers' (Content), and 'DNS Directs' (Traffic).
Network Security Architecture
The exam frequently tests your understanding of Cloud Armor's capabilities, especially its integration with Load Balancing and its WAF features for HTTP(S) traffic. Be ready to distinguish between Cloud Armor's DDoS protection and WAF functions.
Network Security Architecture
Assuming Cloud CDN alone provides comprehensive WAF protection; it needs Cloud Armor for that.
Network Security Architecture
Forgetting that Cloud Armor integrates with Load Balancers, not directly with individual VMs.
Network Security Architecture
Not enabling DNSSEC on public Cloud DNS zones, leaving them vulnerable to spoofing.
Network Security Architecture
Distributes public internet traffic globally, offering DDoS protection and high availability.
Network Security Architecture
Establishes secure, encrypted IPsec tunnels over the public internet between networks.
Network Security Architecture
Highly available Cloud VPN with two interfaces and dynamic BGP routing for redundancy.
Network Security Architecture
Provides high-bandwidth, low-latency private connections between on-premises and Google Cloud.
Network Security Architecture
Direct physical connection from your data center to a Google edge location.
Network Security Architecture
Connects your on-premises network to Google Cloud via a service provider's network.
Network Security Architecture
A logical connection over a Cloud Interconnect that carries private IP traffic.
Network Security Architecture
VPN is 'Via Public Net' for secure internet connections. Interconnect is 'In Private' for dedicated, direct links.
Network Security Architecture
The exam often tests your ability to choose the *most appropriate* connectivity solution based on specific requirements like bandwidth, latency, security, and cost. Memorize the key differentiators between Cloud VPN, Dedicated Interconnect, and Partner Interconnect.
Network Security Architecture
Confusing Cloud VPN with Cloud Interconnect: VPN uses the public internet with encryption; Interconnect uses a private, dedicated connection.
Network Security Architecture
Underestimating the security benefits of GELBs: They are not just for load balancing; they are a critical first line of defense.
Network Security Architecture
Choosing Classic VPN for production workloads: HA VPN provides the necessary redundancy and dynamic routing for critical applications.
Network Security Architecture
Centralized network monitoring and diagnostics.
Network Security Architecture
VMs access Google services via internal IPs.
Network Security Architecture
Private consumption of services across VPCs.
Network Security Architecture
VPC publishing a service via Private Service Connect.
Network Security Architecture
VPC accessing a service via Private Service Connect.
Network Security Architecture
An IP address not routable on the public internet.
Network Security Architecture
PGA is for Google APIs, PSC is for all Services (and more Control!).
Network Security Architecture
The exam often tests the distinction between Private Google Access and Private Service Connect. Remember: Private Google Access is simpler, subnet-level, for VMs to Google APIs. Private Service Connect is more granular, uses endpoints, and supports third-party/custom services and consumer-side firewall rules.
Network Security Architecture
Confusing Private Google Access with Private Service Connect; remember their distinct use cases and configuration.
Network Security Architecture
Forgetting to enable Private Google Access on the subnet when trying to access Google APIs from VMs without external IPs.
Network Security Architecture
Not understanding that Private Service Connect can be used for both Google-managed and third-party/custom services.
Network Security Architecture
Granting only necessary permissions to perform a task.
Securing Your Data in Google Cloud
Makes Cloud Storage retention policies immutable for compliance.
Securing Your Data in Google Cloud
Keeps multiple versions of an object in Cloud Storage.
Securing Your Data in Google Cloud
Encryption keys managed by the customer using Cloud KMS.
Securing Your Data in Google Cloud
BigQuery view that grants access to specific data without underlying table access.
Securing Your Data in Google Cloud
Restricting access to specific rows in a BigQuery table.
Securing Your Data in Google Cloud
Restricting access to specific columns in a BigQuery table.
Securing Your Data in Google Cloud
Physical location where data is stored and processed.
Securing Your Data in Google Cloud
For BigQuery security, think 'BIG ACLS': BigQuery, IAM, Granular, Access Control, CMEK, Logging, Security.
Securing Your Data in Google Cloud
The exam frequently tests on the differences and use cases for Google-managed, customer-supplied (CSEK), and customer-managed (CMEK) encryption keys for both Cloud Storage and BigQuery. Memorize when each is appropriate and the level of control it provides.
Securing Your Data in Google Cloud
Granting primitive roles (Owner, Editor) instead of specific predefined or custom roles.
Securing Your Data in Google Cloud
Not enabling Bucket Lock for compliance-driven data retention policies.
Securing Your Data in Google Cloud
Forgetting that data is encrypted at rest by default, but not understanding the options for key management (CSEK/CMEK).
Securing Your Data in Google Cloud
Fully managed relational database service on Google Cloud.
Securing Your Data in Google Cloud
Service for securely storing and managing sensitive data like API keys.
Securing Your Data in Google Cloud
Internal network connectivity for Cloud SQL, reducing public exposure.
Securing Your Data in Google Cloud
CIDR ranges allowed to connect to Cloud SQL via public IP.
Securing Your Data in Google Cloud
Securely connects applications to Cloud SQL without public IPs.
Securing Your Data in Google Cloud
Encryption protocol for securing data in transit between client and server.
Securing Your Data in Google Cloud
SQL SECRETS: S-Service Accounts, E-Encryption (SSL/TLS), C-Cloud SQL Auth Proxy, R-Restricted Networks, E-External IPs (Authorized Networks), T-Trusted Sources (IAM), S-Secret Manager.
Securing Your Data in Google Cloud
The exam frequently tests on secure connectivity methods for Cloud SQL. Memorize that Private IP is preferred for internal GCP services, and Authorized Networks are for public IP. Also, know that Secret Manager is the recommended service for storing database credentials, not hardcoding or environment variables.
Securing Your Data in Google Cloud
Hardcoding database credentials directly into application code or configuration files.
Securing Your Data in Google Cloud
Using public IP for Cloud SQL without restricting authorized networks, or opening it to '0.0.0.0/0'.
Securing Your Data in Google Cloud
Not enforcing SSL/TLS for all Cloud SQL connections, even within private networks.
Securing Your Data in Google Cloud
Google Cloud service for managing cryptographic keys.
Securing Your Data in Google Cloud
Encryption keys generated and managed by the customer outside Google Cloud.
Securing Your Data in Google Cloud
A logical grouping of cryptographic keys within KMS.
Securing Your Data in Google Cloud
A specific instance of a cryptographic key, used for rotation.
Securing Your Data in Google Cloud
A single key used for both encryption and decryption.
Securing Your Data in Google Cloud
A pair of keys (public/private) used for encryption/decryption or signing/verification.
Securing Your Data in Google Cloud
KMS: Keep My Secrets safe. CMEK: Customer Manages Every Key (in KMS). CSEK: Customer Supplies Every Key (from outside).
Securing Your Data in Google Cloud
The exam often tests the distinction between CMEK and CSEK. Remember that CMEK keys are managed within KMS, while CSEK keys are managed entirely by the customer outside Google Cloud and provided on demand. Know which services support CMEK (most) vs. CSEK (Cloud Storage, Compute Engine).
Securing Your Data in Google Cloud
Confusing CMEK with CSEK: CMEK keys are in KMS; CSEK keys are external and supplied.
Securing Your Data in Google Cloud
Neglecting key rotation: Failing to set up automatic rotation increases risk if a key version is compromised.
Securing Your Data in Google Cloud
Over-privileging IAM roles for KMS: Granting broader permissions than necessary violates the principle of least privilege.
Securing Your Data in Google Cloud
Service to discover, classify, and protect sensitive data.
Securing Your Data in Google Cloud
Pre-defined or custom detector for sensitive data patterns.
Securing Your Data in Google Cloud
Removing sensitive data, replacing it with a placeholder.
Securing Your Data in Google Cloud
Replacing sensitive data with a non-sensitive token.
Securing Your Data in Google Cloud
Service to meet compliance and residency requirements.
Securing Your Data in Google Cloud
Set of rules (e.g., HIPAA, FedRAMP) enforced by Assured Workloads.
Securing Your Data in Google Cloud
DLP is for Detecting, Locating, and Protecting data. Assured Workloads Assures your Workloads meet regulations.
Securing Your Data in Google Cloud
On the exam, be prepared to distinguish between DLP's role in content inspection and Assured Workloads' role in environmental compliance. Keywords like 'sensitive data discovery', 'redaction', 'infoTypes' point to DLP. Keywords like 'regulatory compliance', 'data residency', 'personnel access controls' point to Assured Workloads.
Securing Your Data in Google Cloud
Confusing DLP with encryption: DLP identifies and acts on sensitive data content, while encryption protects data at rest or in transit regardless of its content.
Securing Your Data in Google Cloud
Assuming Assured Workloads automatically protects all data: It provides a compliant environment, but you still need to configure services like DLP within that environment for content-level protection.
Securing Your Data in Google Cloud
Not specifying appropriate infoTypes in DLP: If you don't tell DLP what to look for, it won't find it, leading to potential data exposure.
Securing Your Data in Google Cloud
Records actions by Google Cloud systems modifying resources.
Security Operations & Monitoring
Security issues or vulnerabilities identified by SCC.
Security Operations & Monitoring
Mechanism to export Cloud Audit Logs to other destinations.
Security Operations & Monitoring
SCC service using ML to detect threats from logs.
Security Operations & Monitoring
SCC: See Critical Concerns. Audit Logs: All Users Did It (and when).
Security Operations & Monitoring
On the exam, remember that Admin Activity and System Event logs are enabled by default, but Data Access logs (except for BigQuery) require explicit enablement. SCC is an organization-level service, not project-level.
Security Operations & Monitoring
Forgetting to enable Data Access logs for non-BigQuery services, leading to incomplete audit trails.
Security Operations & Monitoring
Not activating SCC at the organization level, missing out on centralized security visibility.
Security Operations & Monitoring
Confusing SCC's role with Cloud Logging; SCC analyzes and presents findings, while Logging stores the raw events.
Security Operations & Monitoring
Service for collecting metrics, events, and metadata to provide insights into resource usage and performance.
Security Operations & Monitoring
Centralized service for collecting, storing, and analyzing logs from Google Cloud and other sources.
Security Operations & Monitoring
Google Cloud's cloud-native SIEM and SOAR solution for enterprise-wide security analytics.
Security Operations & Monitoring
Security Information and Event Management; aggregates and analyzes security events.
Security Operations & Monitoring
Security Orchestration, Automation, and Response; automates security operations tasks.
Security Operations & Monitoring
Chronicle's rule language for expressing threat detection logic.
Security Operations & Monitoring
My Logs Chronically Secure: Monitoring for metrics, Logging for logs, Chronicle for SIEM/SOAR, all working together for Security.
Security Operations & Monitoring
Memorize the core function of each service: Monitoring for metrics/alerts, Logging for forensic records, and Chronicle for enterprise-scale SIEM/SOAR. Understand how they integrate.
Security Operations & Monitoring
Confusing Cloud Monitoring with Cloud Logging: Monitoring focuses on metrics and alerts, Logging on the actual event records.
Security Operations & Monitoring
Underestimating Chronicle's scale: It's designed for petabytes of security data across an entire enterprise, not just GCP.
Security Operations & Monitoring
Neglecting to configure Log Sinks: Without proper sinks, critical logs might not reach the necessary analysis tools or archives.
Security Operations & Monitoring
Scans Cloud Logging for advanced threats like cryptomining.
Security Operations & Monitoring
Monitors container runtime for attacks and anomalous behavior.
Security Operations & Monitoring
Scans web applications for common vulnerabilities like XSS.
Security Operations & Monitoring
Centralized platform for security management and findings.
Security Operations & Monitoring
A detected security issue or vulnerability reported by a service.
Security Operations & Monitoring
Security monitoring without requiring software agents on instances.
Security Operations & Monitoring
Data about known threats, vulnerabilities, and attack methods.
Security Operations & Monitoring
To remember the three scanners: E.C.W. - 'Every Cloud Workload' needs scanning. E for Event, C for Container, W for Web.
Security Operations & Monitoring
The exam often tests the specific capabilities and integrations of these services. Remember that ETD and CTD are premium features of Security Command Center, while WSS is a standalone service that integrates with SCC. Keywords to spot include 'runtime analysis for containers' (CTD), 'log analysis for advanced threats' (ETD), and 'web application vulnerability scanning' (WSS).
Security Operations & Monitoring
Confusing the scope of each scanner (e.g., thinking WSS scans VMs).
Security Operations & Monitoring
Forgetting that ETD and CTD are part of Security Command Center Premium.
Security Operations & Monitoring
Not understanding that these services generate 'findings' in SCC.
Security Operations & Monitoring
Scans GCP resources for misconfigurations and compliance violations.
Security Operations & Monitoring
Suite of tools for understanding and managing IAM policies.
Security Operations & Monitoring
Helps understand who has access to which resources.
Security Operations & Monitoring
Diagnoses why a user has or doesn't have access.
Security Operations & Monitoring
Tests the impact of IAM policy changes before deployment.
Security Operations & Monitoring
Provides suggestions for rightsizing IAM roles and permissions.
Security Operations & Monitoring
Overall security status and readiness of an organization.
Security Operations & Monitoring
SHA for 'Scan for Health Alerts,' PI for 'Policies Investigated.'
Security Operations & Monitoring
The exam often tests your understanding of how Security Health Analytics integrates with Security Command Center and its role in identifying misconfigurations. For Policy Intelligence, focus on the individual tools (Analyzer, Troubleshooter, Simulator, Recommender) and their specific functions in IAM management. Keywords to spot include 'misconfiguration detection,' 'IAM policy optimization,' and 'principle of least privilege.'
Security Operations & Monitoring
Confusing Security Health Analytics with Cloud Monitoring; SHA focuses on security misconfigurations, not general operational metrics.
Security Operations & Monitoring
Not understanding that Policy Intelligence is a suite of tools, not a single service, each with a distinct function.
Security Operations & Monitoring
Forgetting that Policy Simulator is for testing changes *before* they are applied, preventing unintended access issues.
Security Operations & Monitoring
The root node in the Google Cloud resource hierarchy, representing a company.
Compliance & Governance
A container for projects and other folders, used for grouping and policy inheritance.
Compliance & Governance
The base unit for enabling services, managing APIs, and billing in Google Cloud.
Compliance & Governance
A service to programmatically control Google Cloud resources via constraints.
Compliance & Governance
A predefined restriction on a Google Cloud service or resource, enforced by policies.
Compliance & Governance
Policies applied at a higher level in the hierarchy also apply to lower levels.
Compliance & Governance
ORG-FOLD-PROJ-RES: Organize Folders, Projects, and Resources in a neat hierarchy!
Compliance & Governance
The exam often tests your understanding of the resource hierarchy and how Organization Policies differ from IAM. Look for keywords like 'centralized control', 'enforce guardrails', or 'prevent specific resource configurations' when identifying Organization Policy questions. Remember that Organization Policies define 'what' can be done, not 'who' can do it.
Compliance & Governance
Confusing Organization Policies with IAM policies: IAM controls 'who can do what', while Organization Policies control 'what can be done' or 'how resources can be configured'.
Compliance & Governance
Not testing policies in a non-production environment: Applying a restrictive policy directly to production can cause service outages.
Compliance & Governance
Forgetting about policy inheritance: A policy set at the Organization level affects everything below it, which can lead to unintended consequences if not considered.
Compliance & Governance
Designated individuals/groups for critical Google Cloud notifications.
Compliance & Governance
Logs Google administrator access to customer content for auditing.
Compliance & Governance
Requires explicit customer consent for Google personnel to access data.
Compliance & Governance
Adherence to rules, regulations, and standards (e.g., HIPAA, GDPR).
Compliance & Governance
A chronological record of events to reconstruct activities.
Compliance & Governance
Imagine an 'EAT' sandwich: Essential Contacts for the bread (foundation of info), Access Approval for the filling (your control), and Access Transparency for the transparent wrapper (visibility of everything).
Compliance & Governance
Memorize the distinct purpose of each service: Essential Contacts for *notifications*, Access Transparency for *visibility/logging*, and Access Approval for *control/explicit consent*. The exam often tests your ability to differentiate these.
Compliance & Governance
Confusing Access Transparency (logging) with Access Approval (consent). Transparency logs *after* approval (or attempted access), Approval *before* access.
Compliance & Governance
Not configuring Essential Contacts at all levels (org, folder, project) leading to missed critical alerts for specific teams.
Compliance & Governance
Assuming Access Transparency prevents access; it only logs it. Access Approval is what provides the preventative control.
Compliance & Governance
Managed Google Cloud service for private PKI.
Compliance & Governance
Standard format for public key certificates.
Compliance & Governance
Internal Public Key Infrastructure for private networks.
Compliance & Governance
Enforces deployment policies for container images.
Compliance & Governance
Cryptographic proof an image passed a check.
Compliance & Governance
Trusted entity that signs attestations.
Compliance & Governance
Securing software from development to deployment.
Compliance & Governance
CAS for 'Certificates Are Secure'; Binary Authorization for 'Block Bad Binaries'.
Compliance & Governance
The exam often tests the *purpose* of these services. For CAS, think 'private PKI management' and 'internal certificates.' For Binary Authorization, think 'deployment policy enforcement' and 'supply chain security' for containerized workloads (GKE, Cloud Run, Anthos). Keywords like 'attestations' and 'attestors' are key for Binary Authorization.
Compliance & Governance
Confusing CAS with public CAs like Let's Encrypt; CAS is for *private* certificates.
Compliance & Governance
Thinking Binary Authorization scans for vulnerabilities; it *enforces* that images *have been* scanned (via attestations), it doesn't do the scanning itself.
Compliance & Governance
Forgetting that Binary Authorization applies to GKE, Cloud Run, and Anthos, not arbitrary VMs.
Compliance & Governance
Rules and procedures for protecting an organization's information assets.
Compliance & Governance
For 'Shared Responsibility Model,' remember 'Google is OF the cloud, you are IN the cloud.'
Compliance & Governance
The exam frequently tests your understanding of the shared responsibility model and which Google Cloud service addresses specific compliance challenges (e.g., 'preventing data exfiltration' points to VPC Service Controls, 'enforcing organizational-wide constraints' points to Organization Policy Service).
Compliance & Governance
Confusing Google's responsibility for 'security of the cloud' with the customer's responsibility for 'security in the cloud.'
Compliance & Governance
Believing that simply enabling a Google Cloud service automatically makes you compliant with all regulations; configuration is key.
Compliance & Governance
Underestimating the importance of continuous monitoring and auditing in maintaining compliance over time.
Compliance & Governance