
Google CloudProfessional Cloud Architect
Domain 3Objective 1
3.1 Designing for Security PROFESSIONAL-CLOUD-ARCHITECT Practice Questions (Page 2)
Part of the Designing for security and compliance domain, which accounts for ~17.5% of the PROFESSIONAL-CLOUD-ARCHITECT exam. Google Cloud does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–9 in this domain), expect 5–5 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
23concepts
~17.5%of the exam
Questions 6–10
- 6
A data engineer needs to mask a column containing email addresses in a BigQuery table before sharing it with a non-production team. Which Cloud DLP transformation is designed to replace sensitive values with a token that can be reversed later if needed?
Select an answer first - 7
What is key rotation in Cloud KMS?
Select an answer first - 8
Why should CI/CD pipelines use least-privilege service accounts?
Select an answer first - 9
A security team needs to monitor all attempts to modify IAM policies in their Google Cloud organization. They want to be alerted when any user tries to change a role binding, whether the attempt succeeds or fails. What should they configure?
Select an answer first - 10
A financial services company uses Cloud KMS to encrypt sensitive data. Their compliance policy requires that encryption keys be rotated every 90 days and that old keys remain available to decrypt data encrypted with them. The security team wants to automate this process. What is the recommended approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-ARCHITECT” is a trademark of its owner, used for identification only.