Professional Cloud Security Engineer practice questions

200 free questions with answers and explanations.

Practice test
  1. 101.A global enterprise with highly sensitive data needs to ensure that all virtual machine (VM) images deployed across their Google Cloud organization adhere to a strict set of security policies, including specific operating system versions and patches. They want to prevent the deployment of any non-compliant images. Which Google Cloud service should they use to enforce this?Ensuring compliance
  2. 102.A security auditor needs to ensure that no project in the organization can grant the `roles/owner` role to external users (users outside the organization's primary domain). The auditor also wants to enforce that service accounts cannot be granted `roles/editor` or `roles/owner` roles at the project level. Which Google Cloud service or feature should be used to enforce these restrictions across the entire organization?Configuring access within a cloud solution environment
  3. 103.A financial institution is implementing a new application on Google Cloud that processes highly sensitive customer data. Due to regulatory requirements, all access to this data by Google support personnel must be explicitly approved by the institution's security team. This approval process must generate an audit trail. Which Google Cloud feature is designed to meet this specific requirement?Configuring access within a cloud solution environment
  4. 104.A healthcare organization is using Google Cloud and needs to ensure that they are promptly informed about important events related to their Google Cloud projects that could impact compliance or security, such as impending service deprecations, security bulletins, or policy violations. They require a centralized and reliable mechanism to receive these notifications across different departments. Which Google Cloud service should they use to manage these essential communications?Ensuring compliance
  5. 105.A multinational corporation is expanding its Google Cloud footprint. They have a complex organizational structure with multiple departments, each managing its own projects. They need to aggregate security findings, compliance posture, and potential vulnerabilities from all projects and folders into a single, centralized dashboard for their CISO, providing a unified view of their security health. Which Google Cloud service is designed for this purpose?Ensuring compliance
  6. 106.A development team is building an application that needs to retrieve sensitive configuration parameters from Secret Manager. For security reasons, the access to these secrets should only be allowed during specific business hours (9 AM to 5 PM, Monday to Friday UTC). Which Google Cloud IAM feature can enforce this time-based access control for the service account accessing Secret Manager?Configuring access within a cloud solution environment
  7. 107.A global e-commerce company is expanding its operations and requires the ability to issue and manage its own private X.509 certificates for internal microservices, IoT devices, and mutual TLS authentication, ensuring high availability and compliance with industry standards. They need a managed service that can handle the entire lifecycle of these certificates. Which Google Cloud service should they use?Ensuring compliance
  8. 108.A security team needs to ensure that all service account keys created within a specific Google Cloud project are rotated every 90 days. They want an automated way to identify service accounts with keys older than 90 days and potentially trigger a rotation process. Which Google Cloud service can help identify these non-compliant keys?Configuring access within a cloud solution environment
  9. 109.A media company is developing a new mobile application. They want to allow users to sign in using their existing social media accounts (e.g., Google, Facebook, Twitter) and also support email/password authentication. The solution needs to integrate seamlessly with Google Cloud services for backend processing and secure user data. Which Google Cloud service is best suited for managing these diverse authentication methods?Configuring access within a cloud solution environment
  10. 110.A healthcare organization is migrating patient data to Google Cloud. They require a robust internal Public Key Infrastructure (PKI) to issue and manage certificates for their internal applications, microservices, and IoT devices, ensuring strong authentication and encryption. They need a managed service that integrates well with Google Cloud and offers high availability. Which service should they choose?Ensuring compliance
  11. 111.A security team is implementing a new policy for API key management. They want to ensure that all newly created API keys are restricted to specific IP addresses (e.g., from their corporate VPN) and only allowed to call a predefined set of APIs (e.g., Maps API, Geocoding API). This restriction must be enforced at the time of key creation and apply automatically. How can the security engineer implement this policy?Configuring access within a cloud solution environment
  12. 112.An organization is migrating its existing on-premises network to Google Cloud. They have a complex network infrastructure with many subnets and require granular control over network traffic flow between different virtual machines (VMs) within the same Virtual Private Cloud (VPC) network, as well as between different subnets. They need to implement stateful firewall rules that can inspect and filter traffic based on IP addresses, ports, protocols, and even service accounts. Which Google Cloud feature should they use to achieve this level of network segmentation and control?Ensuring compliance
  13. 113.A large enterprise has recently acquired a smaller company. The acquired company's developers need to access specific Google Cloud projects within the acquiring enterprise's organization. The acquired company uses its own Okta identity provider for user authentication. The security team wants to enable these developers to use their existing Okta credentials to access Google Cloud resources without migrating their identities to Google Cloud Identity. Which Google Cloud service should be configured?Configuring access within a cloud solution environment
  14. 114.A financial institution is deploying a critical application on Google Cloud that must comply with strict regulatory requirements regarding data access and auditability. They need to ensure that Google support personnel only access their data with explicit, time-bound approval, and that all such access is fully logged and auditable. Which Google Cloud service should they implement to meet these requirements?Ensuring compliance
  15. 115.A security engineer needs to create a new service account that will be used by a custom application to publish messages to a specific Pub/Sub topic and subscribe to another specific Pub/Sub topic within the same Google Cloud project. The service account should have no other permissions. Which set of roles should be granted to this service account, and at what resource level?Configuring access within a cloud solution environment
  16. 116.A software development company uses Google Kubernetes Engine (GKE) for deploying its applications. They need to ensure that only container images from their trusted Continuous Integration/Continuous Delivery (CI/CD) pipeline are deployed to production GKE clusters. Images signed by unauthorized keys or from untrusted registries should be blocked. Which Google Cloud service should they implement?Ensuring compliance
  17. 117.A healthcare provider is deploying a new application that processes sensitive patient data. They need to ensure that Google Cloud support personnel can only access this data after explicit, time-bound approval from their security team, and all access attempts are logged and auditable. Which Google Cloud service should they implement to meet this stringent requirement?Ensuring compliance
  18. 118.A government agency is adopting Google Cloud and requires a mechanism to receive notifications about security vulnerabilities, compliance updates, and critical outages that could impact their deployed services. They need to ensure that the correct personnel are always informed, even as teams change. Which Google Cloud service is designed to manage these essential communications?Ensuring compliance
  19. 119.A company requires that all access to highly sensitive data in Cloud Storage buckets must be approved by a designated security team member before access is granted. This approval process should be integrated directly into the Google Cloud IAM workflow. Which Google Cloud feature enables this requirement?Configuring access within a cloud solution environment
  20. 120.A financial institution is implementing a new application on Google Cloud that processes sensitive customer data. Due to strict regulatory requirements, they need to ensure that no single individual has 'break glass' access to the production environment without multiple approvals. Specifically, they want to prevent any single project owner from unilaterally granting themselves or others highly privileged roles on production resources. How can the security engineer enforce this multi-approval mechanism for elevated privileges in Google Cloud?Configuring access within a cloud solution environment
  21. 121.A security analyst is investigating a potential compromise. They need to determine which user or service account generated a specific API key within a Google Cloud project and when it was created. The analyst has access to Cloud Logging for the project and organization. Where should the analyst look for this information?Configuring access within a cloud solution environment
  22. 122.A software-as-a-service (SaaS) provider is building a multi-tenant application on Google Cloud. They need to isolate customer data and resources securely, ensuring that one customer's environment cannot accidentally or maliciously access another's. While IAM provides access control, they require an additional layer of isolation at the network and resource level to create strong logical boundaries between tenants. Which Google Cloud feature is specifically designed to isolate resources and networks for multi-tenant architectures?Ensuring compliance
  23. 123.A large pharmaceutical company uses Google Cloud for its sensitive research data. They need to ensure strict data residency, preventing any data from leaving specific geographical regions. They also want to enforce consistent security configurations across all new projects created within their organization, such as disabling public IP addresses for VMs. Which Google Cloud service combination is best suited for these requirements?Ensuring compliance
  24. 124.A security analyst is investigating a potential compromise. They need to determine which user or service account was responsible for deleting a critical Cloud Storage bucket. The audit trail must be immutable and provide details such as the identity, timestamp, and affected resource. Which Google Cloud logging service should the analyst consult?Configuring access within a cloud solution environment
  25. 125.A consulting firm needs to manage client environments on Google Cloud. Each client has its own project, and the firm wants to logically group these projects by client and then by environment (e.g., 'Client A Dev', 'Client A Prod'). They also need to delegate administrative permissions efficiently so that Client A's administrators can manage all projects under 'Client A' but cannot see or modify anything related to 'Client B'. Which Resource Manager features should they leverage?Ensuring compliance
  26. 126.A development team is deploying a new application to Google Kubernetes Engine (GKE) and requires the pods to securely access Google Cloud Storage (GCS) buckets. The security team mandates that no service account keys should be stored directly within the GKE pods or application code. Which Google Cloud IAM feature should the development team use to meet this requirement?Configuring access within a cloud solution environment
  27. 127.A defense contractor is deploying a highly secure application to Google Kubernetes Engine (GKE). They have a requirement that all sensitive configuration data, such as API keys and database credentials, must be stored and accessed in a manner that provides strong encryption, fine-grained access control, and a full audit trail of all access attempts. Which Google Cloud service is best suited for managing this sensitive data?Ensuring compliance
  28. 128.A research institution is using Google Cloud to process highly sensitive genomic data. They need to ensure that all data at rest in Cloud Storage buckets is encrypted with customer-managed encryption keys (CMEK) rather than Google-managed encryption keys, and that these keys are automatically rotated every 90 days. Additionally, they need to restrict key usage to specific service accounts. Which two Google Cloud services are essential to meet these requirements?Ensuring compliance
  29. 129.A company is implementing a security policy that requires all API keys to have HTTP referrer restrictions applied to them. They want to prevent any API key from being used by unauthorized websites or applications. How can this be enforced for all new and existing API keys across all projects in their organization?Configuring access within a cloud solution environment
  30. 130.A large enterprise with multiple business units is migrating to Google Cloud. They need to establish a hierarchical structure that mirrors their organizational chart, allowing for centralized billing, consistent policy application (e.g., IAM, Organization Policies), and logical grouping of projects for resource management. Which Google Cloud service is primarily responsible for creating and managing this hierarchical structure?Ensuring compliance
  31. 131.A company is migrating its on-premises user directory to Google Cloud. They have a complex Active Directory (AD) structure with multiple organizational units (OUs) and security groups. They need to synchronize user identities and groups from their on-premises AD to Google Cloud Identity to manage access to Google Workspace and Google Cloud resources. The synchronization must be automated and maintain the existing group memberships. Which Google Cloud service should the security engineer configure to achieve this?Configuring access within a cloud solution environment
  32. 132.A global manufacturing company uses Google Cloud and has stringent compliance requirements. They need to ensure that specific types of resources, such as high-performance compute instances or certain database types, are only created within designated projects and never within others, even if a user has IAM permissions to create them. Which Google Cloud service, combined with custom constraints, can enforce this requirement?Ensuring compliance
  33. 133.A development team is deploying a new application to Google Kubernetes Engine (GKE). The application needs to access Google Cloud Storage, Cloud SQL, and publish messages to a Pub/Sub topic. The security team mandates that no service account keys (JSON files) should be distributed or stored in the GKE cluster. How should the application be configured to securely access Google Cloud services?Configuring access within a cloud solution environment
  34. 134.A large enterprise has a complex resource hierarchy in Google Cloud, including multiple organizations, folders, and projects. They need to implement a consistent security policy across the entire organization that mandates specific network configurations, such as disallowing external IP addresses on all new virtual machines, while still allowing some flexibility for specific development projects within a designated folder. How should they design their Organization Policy Service implementation to achieve this balance?Ensuring compliance
  35. 135.A company is using Google Cloud for its customer-facing applications and wants to ensure that all SSL/TLS certificates for its external load balancers are managed securely and automatically renewed. They need a solution that minimizes manual intervention and integrates seamlessly with Google Cloud's networking services. Which service combination provides the best solution?Ensuring compliance
  36. 136.A security engineer needs to configure a service account that will be used by an external third-party application to publish messages to a specific Pub/Sub topic named `projects/my-project/topics/data-ingest`. The service account should only have the minimum necessary permissions for this task and nothing more. Which IAM role should be granted to the service account?Configuring access within a cloud solution environment
  37. 137.A global company uses Google Cloud and has diverse teams across different regions. They want to allow developers to create custom IAM roles for their specific projects, but only within a predefined set of permissions that the central security team has approved. The security team needs to prevent developers from creating custom roles that grant overly broad or unauthorized permissions (e.g., 'iam.serviceAccounts.keyAdmin' or 'resourcemanager.organizations.setIamPolicy'). How can the security engineer enforce this constraint on custom role creation?Configuring access within a cloud solution environment
  38. 138.A security auditor is performing a compliance check and needs to verify that no user in a specific Google Cloud project has been granted the `roles/owner` or `roles/editor` roles directly. Instead, all users should only have custom roles or more granular predefined roles. Which `gcloud` command can be used to list all IAM policy bindings for a project to identify violations?Configuring access within a cloud solution environment
  39. 139.A global enterprise is using Google Cloud and needs to ensure that all new Google Cloud projects are created with specific default IAM policies and billing accounts attached. They want to prevent project creators from bypassing these defaults. Which Google Cloud service should they use to enforce this requirement?Ensuring compliance
  40. 140.A security team needs to implement a policy that prevents any service account from being granted the 'roles/owner' role on any project within their Google Cloud organization. This policy must be enforced globally across all new and existing projects. Which Google Cloud IAM feature should they use to achieve this organization-wide enforcement?Configuring access within a cloud solution environment
  41. 141.A multinational corporation uses Google Cloud across various regions and needs to ensure that critical security and compliance notifications are always routed to the correct teams. They have different teams responsible for security incidents, legal compliance, and technical support, each requiring notifications for specific types of events. Which Google Cloud service should they configure to manage these diverse notification channels effectively?Ensuring compliance
  42. 142.A security engineer is designing an access control strategy for a new Google Cloud project. The project will host multiple applications, each requiring distinct permissions to various Google Cloud services (e.g., Cloud Storage, Cloud SQL, Pub/Sub). The engineer wants to ensure that permissions are highly granular and tailored to the exact needs of each application, minimizing unnecessary privileges. Which IAM best practice should the engineer prioritize?Configuring access within a cloud solution environment
  43. 143.A global healthcare organization uses Google Cloud for sensitive patient data. They need to ensure that all administrative access to their Google Cloud resources by Google support teams is logged and visible to their security and compliance officers. They also need to be able to review the justification for such access, including the specific reason and the Google employee's identity. Which Google Cloud service provides this level of transparency?Ensuring compliance
  44. 144.A project manager needs to grant a new contractor temporary access to a specific Cloud Storage bucket for a data migration task. The contractor should only be able to read and write objects in that single bucket and must have their access automatically revoked after 48 hours. The security engineer wants to achieve this with minimal manual intervention. How should the security engineer configure access?Configuring access within a cloud solution environment
  45. 145.A global enterprise is integrating its on-premises Active Directory with Google Cloud. They have a complex organizational unit (OU) structure and need to ensure that user and group synchronization is highly configurable, allowing for specific OUs to be included or excluded, and attributes to be mapped flexibly. Which Google Cloud service should they use for this integration?Configuring access within a cloud solution environment
  46. 146.A global banking institution is operating sensitive workloads on Google Cloud. They have a strict requirement to prevent data exfiltration and ensure that sensitive data remains within a defined security perimeter, even if an attacker compromises a service account or an application. They need to restrict network access between projects and services to only approved paths and prevent unauthorized movement of data to external networks or unapproved Google Cloud services. Which Google Cloud service is specifically designed to meet these stringent requirements?Ensuring compliance
  47. 147.A company is migrating its legacy applications to Google Cloud, which includes a complex, multi-tier application with strict network segmentation requirements. They need to implement a security policy that allows traffic only on specific ports and protocols between different tiers (e.g., web tier to application tier, application tier to database tier) and explicitly denies all other traffic. This policy needs to be centrally managed and applied consistently across multiple GKE clusters and Compute Engine instances. Which Google Cloud capability should they leverage?Ensuring compliance
  48. 148.A global software company is deploying a new application to Google Kubernetes Engine (GKE). They need to ensure that all container images deployed to their GKE clusters are signed and verified against a trusted authority before they are allowed to run. This is a critical security requirement to prevent unauthorized or tampered images from being executed. Which Google Cloud service is designed to enforce this policy?Ensuring compliance
  49. 149.A financial services company uses Google Cloud for its critical trading platform. Due to strict regulatory requirements, they must be able to demonstrate that any access to their data by Google support personnel is fully transparent and auditable. They need to ensure that they can approve or deny access requests and view detailed logs of all such access. Which two Google Cloud services, when used together, best meet these requirements?Ensuring compliance
  50. 150.A security engineer is investigating an unusual spike in API calls from a specific service account. They need to determine which user or process was responsible for creating this service account and when it was created. Which Google Cloud logging service should the engineer query?Configuring access within a cloud solution environment