Professional Cloud Security Engineer practice questions
200 free questions with answers and explanations.
- 1.A government agency is migrating highly classified workloads to Google Cloud. They have stringent regulatory requirements that mandate data isolation, sovereign controls, and specific compliance certifications for the underlying infrastructure. They also need to ensure that Google support personnel have limited and controlled access to their environment. Which Google Cloud offering is designed to meet these requirements?Ensuring data protection
- 2.A financial institution is storing highly sensitive customer data in Google Cloud Storage. Due to strict regulatory compliance requirements, they need to ensure that data at rest is encrypted using keys that are managed and controlled exclusively within their own on-premises environment, while still leveraging Google Cloud Storage for scalability and durability. Which Google Cloud service should they use to meet this requirement?Ensuring data protection
- 3.A media company uses Cloud Storage to archive video footage. They need to ensure that specific video files, once uploaded, are immutable for seven years to meet regulatory requirements and that no user, including administrators, can delete or modify these files during this period. How should they configure their Cloud Storage buckets and objects?Ensuring data protection
- 4.A software development team uses Secret Manager to store database credentials and API keys. They need to ensure that these secrets are automatically rotated every 90 days to comply with security best practices, without manual intervention. How should they configure Secret Manager to meet this requirement?Ensuring data protection
- 5.A financial services company needs to process large datasets containing credit card numbers and social security numbers in BigQuery. Before these datasets are stored or analyzed, all sensitive PII must be de-identified using a format-preserving encryption (FPE) technique, ensuring that the de-identified data retains its original format (e.g., credit card numbers remain 16 digits) but is irreversible without the specific encryption key. Which Google Cloud Data Loss Prevention (DLP) de-identification method is most suitable for this requirement?Ensuring data protection
- 6.A financial services company is migrating sensitive customer data to Google Cloud Storage. They need to ensure that all data at rest is encrypted using keys that are centrally managed within Google Cloud and that key access is auditable. They also require high availability and durability for these encryption keys. Which Cloud KMS key type should they use?Ensuring data protection
- 7.A global media company uses Cloud Storage to store high-resolution video assets. They need to ensure that all newly uploaded video files are automatically encrypted with customer-managed encryption keys (CMEK) from a specific Cloud KMS key ring, and that this encryption cannot be bypassed. How should they configure their Cloud Storage buckets to meet this requirement?Ensuring data protection
- 8.A research institution is processing large datasets in BigQuery that contain sensitive health information. They need to ensure that no sensitive data leaves the Google Cloud environment and that all BigQuery datasets are restricted to a specific Virtual Private Cloud (VPC) network. Which security control should they implement?Ensuring data protection
- 9.A global e-commerce company uses BigQuery to analyze customer purchasing patterns. They need to implement a solution that redacts or masks sensitive customer information (such as credit card numbers or personal identifying information) when viewed by analysts, but allows authorized personnel to see the original data for specific compliance audits. Which BigQuery security feature should they configure?Ensuring data protection
- 10.A large e-commerce company uses Google Cloud BigQuery to analyze customer purchasing patterns. They need to implement fine-grained access control to ensure that only authorized analysts can view specific columns containing Personally Identifiable Information (PII), such as email addresses and phone numbers, while other analysts can still query the same tables but see masked or tokenized versions of these sensitive columns. Which BigQuery security feature should they implement?Ensuring data protection
- 11.A company is storing highly sensitive financial transaction data in Cloud Storage buckets. They require an immutable audit trail of all data access and modifications, including who accessed what, when, and from where, for compliance purposes. This audit trail must be retained for seven years and be tamper-proof. Which Google Cloud service combination should be used?Ensuring data protection
- 12.A development team is using Google Cloud Secret Manager to store API keys and database credentials. To enhance security and comply with internal policies, they need to ensure that these secrets are automatically updated with new random values every 90 days. Additionally, they must ensure that only the latest active version of the secret is used by applications, and older versions are automatically disabled after a grace period. Which Secret Manager feature set should they leverage?Ensuring data protection
- 13.A government agency is migrating highly classified workloads to Google Cloud. They have stringent compliance requirements, including data residency, personnel access controls, and operational transparency, which necessitate specific assurances about Google's operational environment. Which Google Cloud service is designed to address these requirements?Ensuring data protection
- 14.A development team is using Google Cloud Secret Manager to store database credentials and API keys. They need to ensure that these secrets are automatically rotated every 90 days without manual intervention to enhance security and reduce the risk of compromise. Which feature of Secret Manager should they configure?Ensuring data protection
- 15.A financial institution is implementing Google Cloud Data Loss Prevention (DLP) to scan and redact sensitive data in Cloud Storage. They need to ensure that when a DLP scan identifies a credit card number, it is automatically replaced with a tokenized value while maintaining referential integrity for analytics purposes. Which DLP transformation method should they use?Ensuring data protection
- 16.A global enterprise needs to ensure that all data stored in Cloud Storage, BigQuery, and Cloud SQL databases is encrypted at rest using encryption keys that are centrally managed and rotated according to a consistent organizational policy. They want to avoid managing individual keys for each service and instead apply a default, consistent encryption standard across new resources. Which Cloud KMS feature, when integrated with these services, best addresses this need?Ensuring data protection
- 17.A global pharmaceutical company is using Google Cloud for its clinical trial data. They have strict regulatory requirements (e.g., HIPAA, GDPR) that mandate data residency, personnel access controls, and support for specific compliance frameworks. They need to ensure their Google Cloud environment automatically adheres to these requirements, including restricting data to specific geographic regions and ensuring Google Cloud personnel access is limited and auditable. Which Google Cloud solution is designed to help customers meet these stringent compliance and sovereignty requirements?Ensuring data protection
- 18.A global e-commerce company uses Cloud SQL for MySQL to store customer order data. They need to implement a solution to ensure that all data at rest in Cloud SQL is encrypted using keys that they fully control and manage outside of Google Cloud, with the ability to revoke access to the keys at any time. Which Cloud KMS feature, combined with Cloud SQL, should they use?Ensuring data protection
- 19.A global banking institution is migrating its core financial applications to Google Cloud. They require that all encryption keys for sensitive customer data are generated and used within a FIPS 140-2 Level 3 certified hardware security module (HSM) and that the cryptographic operations are performed within this secure boundary. The institution prefers to manage these keys directly within Google Cloud's infrastructure but with strong assurances of hardware-backed security. Which Cloud KMS key protection level should they choose?Ensuring data protection
- 20.A global e-commerce company uses Cloud SQL for PostgreSQL to store customer order data. They need to ensure that all data in the database is encrypted at rest and that the encryption keys are stored in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which Cloud SQL encryption option should they choose?Ensuring data protection
- 21.A manufacturing company uses Cloud SQL for PostgreSQL to store sensitive intellectual property data. They need to ensure that all connections to the database from their on-premises network are encrypted and authenticated. They also require that the database instance itself is not directly exposed to the public internet. Which configuration should they implement?Ensuring data protection
- 22.A security team needs to ensure that all administrative activities performed on Google Cloud Storage buckets, such as creating, deleting, or modifying bucket policies, are logged for auditing purposes and retained for a minimum of seven years in an immutable format. Which logging configuration should they implement?Ensuring data protection
- 23.A research institution is processing highly sensitive genetic sequence data in BigQuery. Due to stringent privacy regulations, they must ensure that this data never leaves the Google Cloud network perimeter and that all access to the BigQuery datasets and any associated Cloud Storage buckets is restricted to authorized endpoints within a defined VPC network. Additionally, they need to prevent data exfiltration to unauthorized external destinations. Which Google Cloud security control is specifically designed to establish such a secure perimeter?Ensuring data protection
- 24.A healthcare provider stores patient records in BigQuery. Due to strict regulatory compliance, they need to ensure that specific columns containing highly sensitive health information (PHI) are never visible in plain text to analysts, even if they have full BigQuery data viewer access, but still allow aggregate queries. Which BigQuery security feature should be implemented?Ensuring data protection
- 25.A large enterprise wants to prevent data exfiltration from their Google Cloud environment. They have identified that sensitive data in Cloud Storage buckets should never be accessible from the public internet, even if accidentally misconfigured. They also need to ensure that API calls from their on-premises network to these buckets are allowed. Which two actions should they take?Ensuring data protection
- 26.A company is migrating an on-premises application that uses a custom key management system (KMS) to Google Cloud. They have a strong policy that all encryption keys for data in Cloud Storage and Cloud SQL must remain under the exclusive control of their on-premises KMS and never be exposed to Google Cloud directly. The application needs to continue using these existing keys for encryption and decryption operations. Which Google Cloud service allows this integration?Ensuring data protection
- 27.A company is using Cloud SQL for MySQL and needs to ensure that all network connections to the database instance are encrypted and authenticated, without exposing the database to the public internet. Which configuration should they implement?Ensuring data protection
- 28.A media company stores large volumes of video assets in Cloud Storage. They need a system to automatically scan these assets for embedded sensitive information, such as unredacted personal details in video frames or audio transcripts, before they are published. The system should identify these sensitive data types and then ideally redacting them or flagging them for manual review. Which Google Cloud service is designed to perform this type of content inspection and sensitive data detection?Ensuring data protection
- 29.A software company uses Google Cloud Secret Manager to store API keys for various third-party services. They want to ensure that access to these secrets is granted only to specific service accounts and that these service accounts can only retrieve the latest active version of a secret. Which IAM roles and conditions should be applied?Ensuring data protection
- 30.A security team needs to ensure that all administrative activities performed on Google Cloud resources, especially those related to data protection and access control, are immutable and provable for audit purposes for a period of 10 years. This includes changes to IAM policies, Cloud Storage bucket configurations, and KMS key rings. How can they achieve this immutability for audit logs?Ensuring data protection
- 31.A global media company stores terabytes of video content in Cloud Storage. They need to classify and identify any personally identifiable information (PII) within the video metadata and accompanying text files, and then report on the types and locations of this sensitive data for compliance auditing. Which Google Cloud service should they use?Ensuring data protection
- 32.A media company uses Cloud Storage to archive video footage. They need to restrict access to these archival buckets so that only specific service accounts, used by their video processing pipeline, can read and write objects. Additionally, they want to prevent accidental deletion of the buckets themselves. Which IAM roles and Cloud Storage features should be configured?Ensuring data protection
- 33.A financial services company is migrating sensitive customer data to Google Cloud Storage. They need to ensure that data at rest is encrypted with customer-managed encryption keys (CMEK) and that access to these keys is highly controlled and auditable. Which Google Cloud service should they use to manage these encryption keys?Ensuring data protection
- 34.A compliance team needs to verify that all Google Cloud Storage buckets in their organization have a uniform bucket-level access policy enabled to simplify permissions management and prevent object ACLs from overriding bucket-level policies. They want to automate the detection of non-compliant buckets. Which Google Cloud service should they use?Ensuring data protection
- 35.An organization is migrating an on-premises application that uses a custom key management system (KMS) to Google Cloud. They want to integrate their existing KMS with Google Cloud services to manage encryption keys, ensuring that the keys never leave their on-premises environment while still being usable by Google Cloud services like Cloud Storage and BigQuery. Which Google Cloud KMS feature should they utilize?Ensuring data protection
- 36.A financial institution is storing sensitive customer transaction data in Google Cloud Storage buckets. Due to regulatory requirements, they must ensure that all deletions and modifications of this data are strictly prevented for a period of seven years, even by administrators. Which Cloud Storage feature should be configured to meet this compliance requirement?Ensuring data protection
- 37.A healthcare organization stores patient records in BigQuery. Due to strict compliance requirements, they must ensure that personally identifiable information (PII) within specific columns is automatically identified and masked when queried by non-authorized personnel. Which Google Cloud service should they implement to achieve this?Ensuring data protection
- 38.A healthcare organization uses Google Cloud SQL for PostgreSQL to store patient health information (PHI). Regulatory compliance requires that all encryption keys used for PHI data must be stored in a FIPS 140-2 Level 3 validated hardware security module (HSM) and managed outside of Google's direct control. Which Google Cloud service should be used to meet this specific key management requirement?Ensuring data protection
- 39.A research institution is using BigQuery to process large datasets that include sensitive health information. They need to create a security perimeter to prevent data exfiltration and ensure that BigQuery datasets can only be accessed from specific projects within their organization. They also want to allow authorized users to query data from outside the perimeter but restrict data egress. Which Google Cloud security service should be used?Ensuring data protection
- 40.A compliance team needs to verify that all Google Cloud Storage buckets in their organization have uniform bucket-level access enabled to prevent individual object ACLs from overriding IAM policies. They also want to identify any buckets that deviate from this security standard. Which combination of Google Cloud services should they use?Ensuring data protection
- 41.A security engineer is responsible for monitoring a critical production environment on Google Cloud. They need to ensure that any unusual access patterns, such as a user logging in from an unfamiliar country or an unusual number of failed login attempts, are immediately detected. Which Google Cloud service should be configured to provide real-time alerts for these types of suspicious activities?Managing operations
- 42.A global e-commerce company uses Google Cloud for its infrastructure. They want to proactively monitor for suspicious activities, such as cryptocurrency mining, ransomware, and denial-of-service attacks, across their entire Google Cloud environment. They need a service that automatically analyzes logs for these specific threats and generates alerts. Which Google Cloud service should they use?Managing operations
- 43.A security auditor needs to verify that a Google Cloud organization's IAM policies adhere to the principle of least privilege across all projects. Specifically, they need to identify all users who have been granted the 'roles/editor' role directly on a project, rather than through a custom role with more granular permissions. Which Policy Intelligence tool is best suited for this task?Managing operations
- 44.A large e-commerce company uses Google Cloud for its global operations. Their security team needs a unified view of security findings, vulnerabilities, and compliance status across all projects and folders within their organization. They also want to integrate these findings with their existing Security Information and Event Management (SIEM) system. Which Google Cloud service is best suited to provide this centralized security management and integration capability?Managing operations
- 45.A security engineer is setting up a new Google Cloud project. They need to ensure that all firewall rules created within this project are automatically analyzed against an organizational security policy that prohibits specific egress ports (e.g., port 25). They also want to identify any existing firewall rules that violate this policy and get recommendations for remediation. Which Google Cloud service combination should they use?Managing operations
- 46.A company is using Security Command Center (SCC) Premium. They want to ensure that any new or existing Cloud Storage bucket that is publicly accessible is immediately flagged as a high-priority finding. They also need to ensure that their security team is notified via email within minutes of such a finding. How should they configure Security Command Center and Cloud Monitoring to achieve this?Managing operations
- 47.A financial services company is migrating its critical applications to Google Cloud. They require a centralized security posture management solution that can identify misconfigurations, vulnerabilities, and threats across all their projects and folders, providing a consolidated view for security teams. The solution must also support custom security policies. Which Google Cloud service should be implemented?Managing operations
- 48.A security operations center (SOC) team is responsible for rapidly investigating and responding to security incidents across a vast Google Cloud environment. They need to correlate security events from various sources, including Cloud Logging, Security Command Center, and third-party security tools, over extended periods to detect sophisticated, multi-stage attacks. Which Google Cloud service is designed for this advanced security analytics and threat hunting capability?Managing operations
- 49.A security engineer needs to ensure that specific sensitive log entries, such as those indicating data exfiltration attempts or critical security alerts, are immediately forwarded to a Security Information and Event Management (SIEM) system for real-time analysis and incident response. They want to avoid any delays in log delivery and ensure reliability. Which Cloud Logging feature should be configured?Managing operations
- 50.A retail company is expanding its online presence and needs to ensure that its public-facing web applications comply with PCI DSS requirements. Specifically, they need to regularly assess their Google Cloud environment for misconfigurations that could lead to data breaches, such as publicly exposed storage buckets or overly permissive IAM roles on critical resources. Which Security Command Center service is best suited for this continuous compliance and misconfiguration assessment?Managing operations