Step2Study
IT & Technology100% Free

Professional Cloud Security Engineer

Practice bank
200 Qs
Real exam
50 Qs
Time limit
120 min
Passing
The Professional Cloud Security Engineer exam assesses your ability to design, develop, and manage a secure infrastructure on Google Cloud. Candidates should be proficient in all aspects of cloud security, including identity and access management, data protection, network security, and security operations.

Exam blueprint

Configuring access within a cloud solution environment
20%
Configuring network security
20%
Ensuring data protection
20%
Managing operations
20%
Ensuring compliance
20%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 216 min · pass 70% · 200 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Professional Cloud Security Engineer practice test questions

Sample questions from the 200-question bank, with answers and explanations.

All questions
  1. 1. A global e-commerce company uses Cloud SQL for PostgreSQL to store customer order data. They need to ensure that all data in the database is encrypted at rest and that the encryption keys are stored in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which Cloud SQL encryption option should they choose?

    Ensuring data protection

    • A. Customer-supplied encryption keys (CSEK)
    • B. Database-level encryption with a third-party key manager
    • C. Google-managed encryption keys (GMEK)
    • D. Customer-managed encryption keys (CMEK) with Cloud KMS
    Show answer

    D. Customer-managed encryption keys (CMEK) with Cloud KMS

    Cloud SQL supports Customer-managed encryption keys (CMEK) via Cloud Key Management Service (KMS). Cloud KMS offers various key types, including those backed by Cloud HSM, which is FIPS 140-2 Level 3 validated. This allows the company to meet their specific compliance requirement for key storage.

  2. 2. A healthcare provider stores patient records in BigQuery. Due to strict regulatory compliance, they need to ensure that specific columns containing highly sensitive health information (PHI) are never visible in plain text to analysts, even if they have full BigQuery data viewer access, but still allow aggregate queries. Which BigQuery security feature should be implemented?

    Ensuring data protection

    • A. Authorized views with column exclusion
    • B. Row-level security policies
    • C. Column-level security with data masking
    • D. Dataset access controls with data obfuscation
    Show answer

    C. Column-level security with data masking

    Column-level security with data masking allows specific columns to be masked (e.g., partially hidden or tokenized) for users who do not have the appropriate permissions, while still allowing queries on the masked data for aggregate analysis. This meets the requirement of never showing plain text PHI but still allowing aggregate queries.

  3. 3. A media company uses Cloud Storage to archive video footage. They need to ensure that specific video files, once uploaded, are immutable for seven years to meet regulatory requirements and that no user, including administrators, can delete or modify these files during this period. How should they configure their Cloud Storage buckets and objects?

    Ensuring data protection

    • A. Apply a bucket-level retention policy of seven years and enable 'Object Lock' for the bucket.
    • B. Apply a bucket-level retention policy of seven years and grant only 'Storage Object Creator' role.
    • C. Apply a bucket-level retention policy of seven years and enable 'Uniform bucket-level access'.
    • D. Use object versioning and set a lifecycle rule to delete old versions after seven years.
    Show answer

    A. Apply a bucket-level retention policy of seven years and enable 'Object Lock' for the bucket.

    A bucket-level retention policy with Object Lock enabled ensures that objects are immutable and cannot be deleted or modified for the specified duration, even by administrators with 'Owner' roles, thus meeting the strict immutability and regulatory requirements.

  4. 4. A financial services company needs to process large datasets containing credit card numbers and social security numbers in BigQuery. Before these datasets are stored or analyzed, all sensitive PII must be de-identified using a format-preserving encryption (FPE) technique, ensuring that the de-identified data retains its original format (e.g., credit card numbers remain 16 digits) but is irreversible without the specific encryption key. Which Google Cloud Data Loss Prevention (DLP) de-identification method is most suitable for this requirement?

    Ensuring data protection

    • A. Replacement with a fixed value
    • B. CryptoReplaceFfxFpe
    • C. Redaction
    • D. InfoType transformation
    Show answer

    B. CryptoReplaceFfxFpe

    CryptoReplaceFfxFpe (Format-Preserving Encryption with FFX mode) is specifically designed to replace sensitive data with an encrypted value that maintains the original format, such as the number of digits in a credit card number. This method is irreversible without the key, making it suitable for strong de-identification while preserving data utility for analysis.

  5. 5. A research institution is processing highly sensitive genetic sequence data in BigQuery. Due to stringent privacy regulations, they must ensure that this data never leaves the Google Cloud network perimeter and that all access to the BigQuery datasets and any associated Cloud Storage buckets is restricted to authorized endpoints within a defined VPC network. Additionally, they need to prevent data exfiltration to unauthorized external destinations. Which Google Cloud security control is specifically designed to establish such a secure perimeter?

    Ensuring data protection

    • A. Shared VPC
    • B. VPC Network Peering
    • C. VPC Service Controls
    • D. Cloud VPN
    Show answer

    C. VPC Service Controls

    VPC Service Controls create a security perimeter around Google Cloud resources (like BigQuery datasets and Cloud Storage buckets) to restrict data movement and access only from authorized networks and clients. It prevents data exfiltration and ensures that sensitive data remains within the defined perimeter, meeting all the specified requirements.

  6. 6. A financial services company is migrating sensitive customer data to Google Cloud Storage. They need to ensure that all data at rest is encrypted using keys that are centrally managed within Google Cloud and that key access is auditable. They also require high availability and durability for these encryption keys. Which Cloud KMS key type should they use?

    Ensuring data protection

    • A. Customer-supplied encryption keys (CSEK)
    • B. Hardware-backed keys (Cloud HSM)
    • C. External keys (Cloud EKM)
    • D. Software-backed keys
    Show answer

    B. Hardware-backed keys (Cloud HSM)

    Hardware-backed keys (Cloud HSM) in Cloud KMS provide a FIPS 140-2 Level 3 validated hardware security module for key generation and storage, ensuring high security, availability, and durability. Key access is centrally managed and auditable through Cloud KMS and Cloud Audit Logs.

  7. 7. A global media company uses Cloud Storage to store high-resolution video assets. They need to ensure that all newly uploaded video files are automatically encrypted with customer-managed encryption keys (CMEK) from a specific Cloud KMS key ring, and that this encryption cannot be bypassed. How should they configure their Cloud Storage buckets to meet this requirement?

    Ensuring data protection

    • A. Set a default object ACL for the bucket to enforce CMEK.
    • B. Apply an Organization Policy constraint to enforce CMEK for all Cloud Storage buckets.
    • C. Use a Cloud Functions trigger to re-encrypt objects with CMEK after upload.
    • D. Configure the bucket's default encryption to use the specified CMEK key.
    Show answer

    D. Configure the bucket's default encryption to use the specified CMEK key.

    Configuring the bucket's default encryption to use a specified CMEK key ensures that all new objects uploaded to that bucket are automatically encrypted with CMEK. This setting also prevents uploads of unencrypted objects or objects encrypted with Google-managed keys.

  8. 8. A research institution is processing large datasets in BigQuery that contain sensitive health information. They need to ensure that no sensitive data leaves the Google Cloud environment and that all BigQuery datasets are restricted to a specific Virtual Private Cloud (VPC) network. Which security control should they implement?

    Ensuring data protection

    • A. BigQuery Authorized Views
    • B. Private Google Access
    • C. VPC Service Controls
    • D. Cloud VPN
    Show answer

    C. VPC Service Controls

    VPC Service Controls create security perimeters around Google Cloud resources (like BigQuery datasets) to prevent data exfiltration. It ensures that data remains within a defined perimeter and can only be accessed from authorized networks, directly addressing the requirement of preventing data from leaving the Google Cloud environment and restricting access to a specific VPC.

  9. 9. A global banking institution is migrating its core financial applications to Google Cloud. They require that all encryption keys for sensitive customer data are generated and used within a FIPS 140-2 Level 3 certified hardware security module (HSM) and that the cryptographic operations are performed within this secure boundary. The institution prefers to manage these keys directly within Google Cloud's infrastructure but with strong assurances of hardware-backed security. Which Cloud KMS key protection level should they choose?

    Ensuring data protection

    • A. EXTERNAL
    • B. SOFTWARE
    • C. EXTERNAL_VPC
    • D. HSM
    Show answer

    D. HSM

    The HSM key protection level in Cloud KMS ensures that keys are generated and used within FIPS 140-2 Level 3 certified hardware security modules. This meets the requirement for hardware-backed security and cryptographic operations within a secure boundary, while still allowing the keys to be managed within Google Cloud's infrastructure.

  10. 10. A government agency is migrating highly classified workloads to Google Cloud. They have stringent regulatory requirements that mandate data isolation, sovereign controls, and specific compliance certifications for the underlying infrastructure. They also need to ensure that Google support personnel have limited and controlled access to their environment. Which Google Cloud offering is designed to meet these requirements?

    Ensuring data protection

    • A. Confidential Computing
    • B. Assured Workloads
    • C. Cloud Security Command Center Premium
    • D. Dedicated Interconnect
    Show answer

    B. Assured Workloads

    Assured Workloads is specifically designed for customers with stringent compliance and sovereignty requirements, such as government agencies. It helps enforce compliance by providing controls over data residency, personnel access (e.g., limiting Google support to specific geographies or personnel), and ensuring workloads run on certified infrastructure (e.g., FedRAMP, IL4, IL5).

  11. 11. A development team is using Google Cloud Secret Manager to store API keys and database credentials. To enhance security and comply with internal policies, they need to ensure that these secrets are automatically updated with new random values every 90 days. Additionally, they must ensure that only the latest active version of the secret is used by applications, and older versions are automatically disabled after a grace period. Which Secret Manager feature set should they leverage?

    Ensuring data protection

    • A. Secret Manager access control via IAM conditions
    • B. Secret Manager versioning and manual rotation
    • C. Secret Manager replication policies
    • D. Secret Manager automatic rotation with a custom rotation function
    Show answer

    D. Secret Manager automatic rotation with a custom rotation function

    Secret Manager's automatic rotation feature, combined with a custom rotation function (typically a Cloud Function), allows secrets to be programmatically updated at a specified interval (e.g., 90 days). This rotation process creates new secret versions and can be configured to automatically disable older versions after a grace period, meeting all requirements.

  12. 12. A government agency is migrating highly classified workloads to Google Cloud. They have stringent compliance requirements, including data residency, personnel access controls, and operational transparency, which necessitate specific assurances about Google's operational environment. Which Google Cloud service is designed to address these requirements?

    Ensuring data protection

    • A. VPC Service Controls
    • B. Security Command Center
    • C. Assured Workloads
    • D. Confidential Computing
    Show answer

    C. Assured Workloads

    Assured Workloads helps customers meet specific compliance and regulatory requirements by providing predefined environments that enforce data residency, personnel access, support, and operational controls tailored to various compliance regimes (e.g., FedRAMP, IL4, C5).

  13. 13. A development team is using Google Cloud Secret Manager to store database credentials and API keys. They need to ensure that these secrets are automatically rotated every 90 days without manual intervention to enhance security and reduce the risk of compromise. Which feature of Secret Manager should they configure?

    Ensuring data protection

    • A. Secret Manager automatic rotation with a custom rotation function.
    • B. IAM conditions to restrict secret access after 90 days.
    • C. Cloud KMS key rotation for the secrets' encryption keys.
    • D. Secret Manager versioning with a Cloud Functions trigger for rotation.
    Show answer

    A. Secret Manager automatic rotation with a custom rotation function.

    Secret Manager's automatic rotation feature, combined with a custom rotation function (typically implemented as a Cloud Function), is designed to automatically generate and rotate new secret versions at a specified interval, such as every 90 days, without manual intervention.

  14. 14. A financial institution is implementing Google Cloud Data Loss Prevention (DLP) to scan and redact sensitive data in Cloud Storage. They need to ensure that when a DLP scan identifies a credit card number, it is automatically replaced with a tokenized value while maintaining referential integrity for analytics purposes. Which DLP transformation method should they use?

    Ensuring data protection

    • A. CryptoReplaceFfxFpe
    • B. Redaction
    • C. De-identification
    • D. RecordTransformations
    Show answer

    A. CryptoReplaceFfxFpe

    To maintain referential integrity while replacing sensitive data with a tokenized value, the CryptoReplaceFfxFpe transformation method is the most suitable. It uses format-preserving encryption to generate consistent, tokenized outputs for the same input values.

  15. 15. A global enterprise needs to ensure that all data stored in Cloud Storage, BigQuery, and Cloud SQL databases is encrypted at rest using encryption keys that are centrally managed and rotated according to a consistent organizational policy. They want to avoid managing individual keys for each service and instead apply a default, consistent encryption standard across new resources. Which Cloud KMS feature, when integrated with these services, best addresses this need?

    Ensuring data protection

    • A. Cloud KMS default key for a project or folder
    • B. Cloud KMS key rings with specific key purposes
    • C. Customer-Supplied Encryption Keys (CSEK)
    • D. Cloud External Key Manager (EKM)
    Show answer

    A. Cloud KMS default key for a project or folder

    Configuring a Cloud KMS default key at the project or folder level allows new resources created in supported services (like Cloud Storage, BigQuery, Cloud SQL) to automatically use that specified customer-managed encryption key (CMEK) for encryption at rest. This centralizes key management and ensures consistent application of the organizational encryption policy without manual configuration for each resource.

  16. 16. A global pharmaceutical company is using Google Cloud for its clinical trial data. They have strict regulatory requirements (e.g., HIPAA, GDPR) that mandate data residency, personnel access controls, and support for specific compliance frameworks. They need to ensure their Google Cloud environment automatically adheres to these requirements, including restricting data to specific geographic regions and ensuring Google Cloud personnel access is limited and auditable. Which Google Cloud solution is designed to help customers meet these stringent compliance and sovereignty requirements?

    Ensuring data protection

    • A. VPC Service Controls
    • B. Organization Policy Service
    • C. Cloud Identity and Access Management (IAM)
    • D. Assured Workloads
    Show answer

    D. Assured Workloads

    Assured Workloads directly addresses stringent compliance and sovereignty requirements by providing a Google Cloud environment that helps enforce data residency, restrict Google personnel access, and align with specific compliance frameworks like HIPAA, PCI DSS, and FedRAMP. It automates the configuration of controls to meet these mandates.

  17. 17. A global e-commerce company uses Cloud SQL for MySQL to store customer order data. They need to implement a solution to ensure that all data at rest in Cloud SQL is encrypted using keys that they fully control and manage outside of Google Cloud, with the ability to revoke access to the keys at any time. Which Cloud KMS feature, combined with Cloud SQL, should they use?

    Ensuring data protection

    • A. Customer-Supplied Encryption Keys (CSEK) for Cloud SQL.
    • B. Customer-Managed Encryption Keys (CMEK) via Cloud KMS.
    • C. Cloud HSM keys integrated with Cloud SQL.
    • D. Cloud External Key Manager (EKM) with Cloud KMS.
    Show answer

    D. Cloud External Key Manager (EKM) with Cloud KMS.

    To achieve full control and management of encryption keys outside of Google Cloud, with the ability to revoke access at any time, Cloud External Key Manager (EKM) is the correct choice. EKM allows Google Cloud services to use keys residing in an external, customer-managed key management system, with Cloud KMS acting as an intermediary.

  18. 18. A compliance team needs to verify that all Google Cloud Storage buckets in their organization have uniform bucket-level access enabled to prevent individual object ACLs from overriding IAM policies. They also want to identify any buckets that deviate from this security standard. Which combination of Google Cloud services should they use?

    Ensuring data protection

    • A. Cloud Audit Logs and Cloud Logging.
    • B. Cloud Monitoring and Cloud Alerting.
    • C. Cloud Asset Inventory and Security Health Analytics.
    • D. Data Loss Prevention (DLP) and Cloud Security Scanner.
    Show answer

    C. Cloud Asset Inventory and Security Health Analytics.

    Cloud Asset Inventory provides a centralized inventory of all Google Cloud assets, including Cloud Storage buckets and their configurations. Security Health Analytics (part of Security Command Center) can then scan this inventory for compliance deviations, such as buckets without uniform bucket-level access enabled, and report them.

  19. 19. A financial institution is storing highly sensitive customer data in Google Cloud Storage. Due to strict regulatory compliance requirements, they need to ensure that data at rest is encrypted using keys that are managed and controlled exclusively within their own on-premises environment, while still leveraging Google Cloud Storage for scalability and durability. Which Google Cloud service should they use to meet this requirement?

    Ensuring data protection

    • A. Cloud External Key Manager (EKM)
    • B. Default Google-managed encryption keys
    • C. Cloud HSM with customer-supplied encryption keys (CSEK)
    • D. Cloud Key Management Service (KMS) with customer-managed encryption keys (CMEK)
    Show answer

    A. Cloud External Key Manager (EKM)

    Cloud External Key Manager (EKM) allows organizations to encrypt data in Google Cloud using keys that are managed and stored outside of Google's infrastructure, meeting strict regulatory requirements for external key control.

  20. 20. A company is storing highly sensitive financial transaction data in Cloud Storage buckets. They require an immutable audit trail of all data access and modifications, including who accessed what, when, and from where, for compliance purposes. This audit trail must be retained for seven years and be tamper-proof. Which Google Cloud service combination should be used?

    Ensuring data protection

    • A. Cloud Logging with Cloud Audit Logs and export to Cloud SQL.
    • B. Cloud Logging with Cloud Audit Logs and export to BigQuery.
    • C. Cloud Monitoring with custom metrics and alerts.
    • D. Cloud Audit Logs with export to a WORM-compliant Cloud Storage bucket.
    Show answer

    D. Cloud Audit Logs with export to a WORM-compliant Cloud Storage bucket.

    Cloud Audit Logs automatically records administrative activities and data access for Cloud Storage. Exporting these logs to a Cloud Storage bucket configured with Object Lock in WORM (Write Once, Read Many) mode ensures immutability and long-term retention for compliance, making the audit trail tamper-proof for seven years.

  21. 21. A software development team uses Secret Manager to store database credentials and API keys. They need to ensure that these secrets are automatically rotated every 90 days to comply with security best practices, without manual intervention. How should they configure Secret Manager to meet this requirement?

    Ensuring data protection

    • A. Implement a Cloud Function triggered by a Pub/Sub topic to rotate secrets.
    • B. Configure a rotation schedule directly in the Secret Manager UI or gcloud CLI.
    • C. Set an expiration date on the secret version and manually create a new version.
    • D. Use Cloud Scheduler to trigger a custom application that updates the secret.
    Show answer

    B. Configure a rotation schedule directly in the Secret Manager UI or gcloud CLI.

    Secret Manager provides a built-in feature to configure an automatic rotation schedule for secrets. This allows you to specify a rotation period (e.g., 90 days) and a Cloud Function that will be invoked to perform the actual secret update, simplifying compliance with rotation policies.

  22. 22. A security team needs to ensure that all administrative activities performed on Google Cloud Storage buckets, such as creating, deleting, or modifying bucket policies, are logged for auditing purposes and retained for a minimum of seven years in an immutable format. Which logging configuration should they implement?

    Ensuring data protection

    • A. Enable Data Access logs for Cloud Storage and export them to BigQuery.
    • B. Enable Admin Activity logs for Cloud Storage and configure a Cloud Storage bucket as a sink with a retention policy.
    • C. Enable Admin Activity logs for Cloud Storage and export them to a Pub/Sub topic for real-time processing.
    • D. Enable System Event logs for Cloud Storage and stream them to Security Command Center.
    Show answer

    B. Enable Admin Activity logs for Cloud Storage and configure a Cloud Storage bucket as a sink with a retention policy.

    Admin Activity logs record administrative actions, including creating, deleting, or modifying bucket policies. Exporting these logs to a Cloud Storage bucket configured as a sink, with an appropriate retention policy and Object Lock enabled, will ensure they are retained for seven years in an immutable format for auditing.

  23. 23. A global e-commerce company uses BigQuery to analyze customer purchasing patterns. They need to implement a solution that redacts or masks sensitive customer information (such as credit card numbers or personal identifying information) when viewed by analysts, but allows authorized personnel to see the original data for specific compliance audits. Which BigQuery security feature should they configure?

    Ensuring data protection

    • A. Data Loss Prevention (DLP) API for BigQuery
    • B. BigQuery column-level security with data masking
    • C. BigQuery row-level security
    • D. Authorized views with data transformation
    Show answer

    B. BigQuery column-level security with data masking

    BigQuery column-level security with data masking allows sensitive data within specific columns to be obfuscated for most users, while still permitting full access to raw data for authorized roles, precisely matching the requirement.

  24. 24. A manufacturing company uses Cloud SQL for PostgreSQL to store sensitive intellectual property data. They need to ensure that all connections to the database from their on-premises network are encrypted and authenticated. They also require that the database instance itself is not directly exposed to the public internet. Which configuration should they implement?

    Ensuring data protection

    • A. Configure Cloud SQL with a public IP address and Cloud Armor for IP whitelisting.
    • B. Configure Cloud SQL with a public IP address and enforce SSL/TLS.
    • C. Configure Cloud SQL with a private IP address and Cloud VPN/Interconnect, enforcing SSL/TLS.
    • D. Configure Cloud SQL with a private IP address and Cloud DNS, enforcing SSL/TLS.
    Show answer

    C. Configure Cloud SQL with a private IP address and Cloud VPN/Interconnect, enforcing SSL/TLS.

    Using a private IP address for Cloud SQL ensures the instance is not exposed to the public internet. Connecting from on-premises via Cloud VPN or Cloud Interconnect establishes a secure, private network path. Enforcing SSL/TLS encrypts and authenticates the traffic over this private connection, meeting all requirements.

  25. 25. A large enterprise wants to prevent data exfiltration from their Google Cloud environment. They have identified that sensitive data in Cloud Storage buckets should never be accessible from the public internet, even if accidentally misconfigured. They also need to ensure that API calls from their on-premises network to these buckets are allowed. Which two actions should they take?

    Ensuring data protection

    • A. Set Object ACLs to private and configure a BigQuery Authorized View.
    • B. Use `storage.admin` role for all access and enable bucket versioning.
    • C. Enable uniform bucket-level access on the buckets and configure a VPC Service Controls perimeter.
    • D. Disable public access prevention on the buckets and use Cloud VPN for on-premises access.
    Show answer

    C. Enable uniform bucket-level access on the buckets and configure a VPC Service Controls perimeter.

    Uniform bucket-level access ensures that all objects in a bucket inherit IAM policies from the bucket, effectively preventing object ACLs from making data publicly accessible. A VPC Service Controls perimeter further prevents data exfiltration by creating a security boundary around Cloud Storage, and it allows defining ingress rules to permit API calls from trusted on-premises networks.

Professional Cloud Security Engineer flashcards

Tap a card to flip it. 137 flashcards in the full deck.

  • Cloud SQL CMEK with Cloud HSM

    Flip card

    Using Customer-managed encryption keys (CMEK) for Cloud SQL, where the keys themselves are protected by Google Cloud's FIPS 140-2 Level 3 validated Hardware Security Module (HSM) via Cloud KMS.

    • Provides enhanced control over encryption keys.
    • Meets strict compliance requirements like FIPS 140-2 Level 3.
    • Keys are stored and operations performed within an HSM.
    Study this card →
  • BigQuery Column-level Security with Data Masking

    Flip card

    A BigQuery feature that allows you to define policies to mask (transform) data in specific columns based on user permissions, ensuring sensitive information is never exposed in plain text while still enabling analytical operations.

    • Applies to columns, not rows.
    • Masks data based on user roles/permissions.
    • Allows aggregate queries on masked data.
    Study this card →
  • Cloud Storage Retention Policy with Object Lock

    Flip card

    A Cloud Storage feature that enforces immutability on objects within a bucket for a specified duration, preventing deletion or modification by any user, including administrators, to meet regulatory or compliance requirements.

    • Applies to all objects in a bucket (or specific objects if configured).
    • Prevents deletion and modification for the retention period.
    • Works even for users with 'Owner' permissions.
    Study this card →
  • DLP CryptoReplaceFfxFpe

    Flip card

    A Google Cloud DLP de-identification method that uses format-preserving encryption (FFX mode) to replace sensitive data with an encrypted value that retains the original data's format and character set.

    • Preserves data format (e.g., length, character type).
    • Irreversible without the encryption key.
    • Useful for maintaining data utility in analytics while de-identifying.
    Study this card →
  • VPC Service Controls

    Flip card

    A Google Cloud security feature that allows you to create a security perimeter around sensitive Google Cloud resources to mitigate data exfiltration risks.

    • Restricts operations on supported services to authorized networks.
    • Prevents data movement to unauthorized locations.
    • Enhances compliance for highly sensitive workloads.
    Study this card →
  • Cloud KMS Hardware-backed Keys (Cloud HSM)

    Flip card

    A Cloud KMS key type that uses FIPS 140-2 Level 3 validated Hardware Security Modules (HSMs) to generate, store, and perform cryptographic operations, offering enhanced security, high availability, and durability for encryption keys within Google Cloud.

    • Keys generated and stored in FIPS 140-2 Level 3 HSMs.
    • Offers strongest security guarantees for keys within GCP.
    • Integrated with Cloud KMS for central management and auditing.
    Study this card →
  • Cloud Storage Default CMEK

    Flip card

    A Cloud Storage bucket setting that automatically encrypts all new objects uploaded to the bucket with a specified Customer-Managed Encryption Key (CMEK), preventing uploads of objects encrypted with other methods.

    • Applies to new objects uploaded to the bucket.
    • Enforces a specific Cloud KMS key for encryption.
    • Prevents bypassing CMEK by disallowing other encryption types.
    Study this card →
  • Cloud KMS Key Protection Levels

    Flip card

    Cloud KMS offers different protection levels for cryptographic keys, determining how and where the key material is stored and cryptographic operations are performed.

    • SOFTWARE: Keys stored in software.
    • HSM: Keys stored in hardware security modules (FIPS 140-2 Level 3).
    • EXTERNAL: Keys managed by an external key manager (Cloud EKM).
    Study this card →
  • Assured Workloads

    Flip card

    A Google Cloud offering that helps customers meet compliance and regulatory requirements by establishing a secure and compliant environment for sensitive workloads.

    • Enforces data residency and sovereign controls.
    • Limits Google personnel access based on geography.
    • Supports various compliance regimes (FedRAMP, IL4/IL5, C5, etc.).
    Study this card →
  • Secret Manager Automatic Rotation

    Flip card

    A Google Cloud Secret Manager feature that automates the process of updating secrets at a specified interval, typically using a Cloud Function to generate and apply new secret values.

    • Enhances security by regularly changing credentials.
    • Reduces operational overhead for secret management.
    • Supports custom logic for secret generation and update.
    Study this card →
  • Google Cloud Assured Workloads

    Flip card

    A Google Cloud service that helps customers meet specific compliance and regulatory requirements by providing predefined, compliance-focused environments that enforce data residency, personnel access controls, and operational transparency.

    • Provides compliance-specific environments (e.g., FedRAMP, C5).
    • Enforces data residency and personnel access controls.
    • Offers operational transparency and support tailored to compliance.
    Study this card →
  • Cloud KMS Default Key

    Flip card

    A Cloud KMS feature that allows you to specify a default Customer-Managed Encryption Key (CMEK) at the project or folder level, which is then automatically applied to new resources in supported Google Cloud services.

    • Simplifies CMEK adoption across an organization.
    • Ensures consistent encryption policy enforcement.
    • Reduces manual configuration for new resources.
    Study this card →
  • Cloud External Key Manager (EKM)

    Flip card

    A Cloud KMS feature that allows Google Cloud services to encrypt data using keys managed in an external, third-party key management system outside of Google Cloud, providing customers with full control and the ability to revoke key access.

    • Keys reside in an external KMS, not Google Cloud.
    • Cloud KMS acts as an intermediary to use the external keys.
    • Provides ultimate control over key lifecycle and revocation.
    Study this card →
  • Cloud Asset Inventory & Security Health Analytics for Compliance

    Flip card

    Cloud Asset Inventory provides a comprehensive inventory of all Google Cloud assets and their metadata, while Security Health Analytics (within Security Command Center) analyzes this inventory to detect misconfigurations and compliance violations against security standards.

    • Cloud Asset Inventory catalogs all resources and their configurations.
    • Security Health Analytics detects common misconfigurations (e.g., disabled UBLA).
    • Used for security posture management and compliance auditing.
    Study this card →
  • Cloud Audit Logs with WORM Storage

    Flip card

    Google Cloud's built-in auditing service combined with immutable storage to create tamper-proof records of activity for compliance.

    • Records admin and data access events.
    • WORM (Write Once, Read Many) ensures immutability.
    • Critical for regulatory compliance and forensic analysis.
    Study this card →
  • Cloud SQL Private IP with Hybrid Connectivity and SSL/TLS

    Flip card

    Configuring Cloud SQL with a private IP address, establishing secure private network connectivity from on-premises via Cloud VPN or Cloud Interconnect, and enforcing SSL/TLS for encrypted and authenticated database connections.

    • Private IP removes public internet exposure.
    • Cloud VPN/Interconnect provides secure hybrid connectivity.
    • SSL/TLS encrypts and authenticates client-server traffic.
    Study this card →
  • VPC Service Controls & Uniform Bucket-Level Access for Cloud Storage

    Flip card

    A combination of security controls to prevent data exfiltration from Cloud Storage buckets and enforce consistent access policies.

    • Uniform bucket-level access simplifies and centralizes permissions.
    • VPC Service Controls creates a security perimeter around services.
    • Together, they prevent public access and data exfiltration.
    Study this card →
  • Cloud SQL Private IP with SSL/TLS

    Flip card

    Configuring Cloud SQL instances to use an internal Private IP address and enforcing SSL/TLS for all connections, ensuring secure and private network access.

    • Database is not exposed to the public internet.
    • Connections are encrypted (SSL/TLS).
    • Access is restricted to authorized VPC networks.
    Study this card →
  • Data Loss Prevention (DLP) API

    Flip card

    A Google Cloud service that helps discover, classify, and protect sensitive data (infoTypes) across various data sources and content types, including text, images, and structured data.

    • Identifies over 150 built-in infoTypes (e.g., credit card numbers, SSN).
    • Supports de-identification methods like redaction, tokenization, FPE.
    • Can scan data at rest and in transit.
    Study this card →
  • Secret Manager Access with IAM Conditions

    Flip card

    Using IAM roles combined with IAM Conditions to grant granular access to Secret Manager resources, such as restricting access to only the latest version of a secret or specific actions.

    • Role 'Secret Manager Secret Accessor' grants payload access.
    • IAM Conditions filter access based on resource attributes or request properties.
    • 'resource.name' can filter by secret or version path.
    Study this card →
  • Cloud Audit Logs with Bucket Lock

    Flip card

    Exporting Cloud Audit Logs to a Cloud Storage bucket that has a Bucket Lock policy applied, ensuring the logs are immutable and cannot be deleted or modified for a specified retention period.

    • Provides WORM compliance for audit trails.
    • Essential for regulatory and legal requirements.
    • Protects against tampering, even by privileged users.
    Study this card →
  • Cloud Storage Retention Policy & Object Roles

    Flip card

    Configuring Cloud Storage with specific IAM roles for granular object access and a bucket retention policy to prevent accidental data deletion and enforce immutability.

    • IAM roles (e.g., `objectViewer`, `objectCreator`) ensure least privilege.
    • Bucket retention policy locks objects for a specified duration.
    • Helps prevent accidental data loss and ensures compliance.
    Study this card →
  • Cloud Key Management Service (KMS)

    Flip card

    A cloud-hosted key management service that lets you manage cryptographic keys for your cloud services in the same way you manage keys on-premises.

    • Manages symmetric and asymmetric encryption keys.
    • Integrates with many Google Cloud services for CMEK.
    • Provides auditing and access control for keys.
    Study this card →
  • Cloud Storage Bucket Lock

    Flip card

    A feature that allows you to configure a retention policy on a Cloud Storage bucket, preventing objects from being deleted or modified for a specified duration.

    • Enforces immutability on objects.
    • Protects against accidental or malicious deletion/modification.
    • Adheres to WORM (Write Once, Read Many) principles.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.