Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GOOGLE CLOUD

Google Cloud Professional Cloud Security Engineer

PROFESSIONAL-CLOUD-SECURITY-ENGINEERProfessional Cloud Security Engineer

The Google Cloud Professional Cloud Security Engineer certification validates your ability to design, implement, and manage secure workloads and infrastructure on Google Cloud. It is intended for security practitioners who configure access, protect data, and respond to threats across cloud environments. Earning it demonstrates that you can translate security requirements into resilient, compliant cloud architectures.

364 practice questions · Updated 2026-07-30

5Domains
14Objectives
123Concepts
364Questions

PROFESSIONAL-CLOUD-SECURITY-ENGINEER Curriculum

Every domain, objective, and concept the PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam measures.

1.1 Managing Cloud Identity

6 concepts · 23 questions
  1. Google Cloud Directory Sync (GCDS) configuration
  2. Single sign-on (SSO) with third-party identity provider
  3. Super administrator account management
  4. User lifecycle automation
  5. Programmatic user and group administration
  6. Workforce Identity Federation configuration

1.2 Managing service accounts

7 concepts · 22 questions
  1. Service Account Fundamentals
  2. Default Service Accounts
  3. Creating and Managing Service Accounts
  4. Service Account Key Security
  5. Short-Lived Credentials
  6. Workload Identity Federation
  7. Service Account Impersonation

1.3 Managing authentication

5 concepts · 13 questions
  1. Password Policy Configuration
  2. Session Management Policy
  3. SAML Authentication Setup
  4. OAuth Authorization Configuration
  5. 2-Step Verification Enforcement
  1. IAM Roles and Permissions
  2. Privileged Roles and Separation of Duties
  3. IAM and ACL Permissions
  4. IAM Conditions
  5. IAM Deny Policies
  6. Identity Types and Permission Grants
  7. Resource Hierarchy and Least Privilege
  8. Access Context Manager
  9. Policy Intelligence
  10. Group-Based Permission Management
  11. Privileged Access Manager Use Cases
  12. Privileged Access Manager Configuration

1.5 Defining the resource hierarchy

7 concepts · 20 questions
  1. Resource hierarchy overview
  2. Managing folders and projects at scale
  3. Organization policies overview
  4. Using pre-built organization policies
  5. Creating custom organization policies
  6. Policy inheritance and hierarchy
  7. Access control using resource hierarchy

  1. Cloud NGFW rules and policies
  2. Identity-Aware Proxy (IAP) configuration
  3. Load balancer security features
  4. Certificate Authority Service usage
  5. Layer 7 inspection on Cloud NGFW
  6. Private vs public IP addressing
  7. Google Cloud Armor configuration
  8. Secure Web Proxy deployment
  9. Cloud DNS security settings
  10. API monitoring and restriction

2.2 Configuring boundary segmentation

8 concepts · 17 questions
  1. VPC network security properties
  2. VPC peering configuration
  3. Shared VPC configuration
  4. Firewall rules configuration
  5. Network isolation for N-tier applications
  6. Data encapsulation for N-tier applications
  7. VPC Service Controls use cases
  8. VPC Service Controls configuration

2.3 Establishing private connectivity

9 concepts · 25 questions
  1. Shared VPC
  2. VPC Peering
  3. Private Google Access for on-premises hosts
  4. HA VPN
  5. Cloud Interconnect
  6. Private Google Access for VPC
  7. Restricted Google Access
  8. Private Service Connect
  9. Cloud NAT

  1. SDP discovery
  2. SDP redaction
  3. SDP pseudonymization
  4. Format-preserving encryption (FPE)
  5. BigQuery access control
  6. Cloud Storage access control
  7. Cloud SQL access control
  8. Secret Manager fundamentals
  9. Secret Manager rotation and lifecycle
  10. Compute instance metadata protection
  1. Google default encryption
  2. Customer-managed encryption keys (CMEK)
  3. Cloud External Key Manager (EKM)
  4. Software vs hardware keys
  5. Creating and managing CMEK keys
  6. Creating and managing EKM keys
  7. Key rotation and revocation
  8. Key import
  9. Applying encryption methods
  10. Cloud Storage object lifecycle policies
  11. Confidential Computing concepts
  12. Enabling Confidential Computing

3.3 Securing AI workloads

9 concepts · 33 questions
  1. AI/ML Security Threat Landscape
  2. Data Privacy Controls for AI/ML
  3. Model Security Controls
  4. Secure ML Lifecycle Management
  5. IaaS Security for Training Models
  6. PaaS Security for Training Models
  7. Gemini Enterprise Agent Platform Security Controls
  8. Privacy Controls for Gemini Enterprise Agents
  9. Monitoring and Auditing AI Workloads

  1. CI/CD Security Scanning
  2. Binary Authorization for GKE
  3. Binary Authorization for Cloud Run
  4. Automated VM Image Creation
  5. Automated Container Image Creation
  6. VM Patch Management Automation
  7. Cloud Security Posture Management
  8. Custom Organization Policies
  9. Custom Modules for Security Health Analytics
  10. Drift Detection at Scale
  1. Network Log Sources
  2. Network Log Analysis
  3. Logging Strategy Design
  4. Incident Response Lifecycle
  5. Secure Log Access
  6. Log Export to External Systems
  7. Audit Log Configuration
  8. Security Command Center Monitoring

  1. Compute, Data, Network, and Storage Technical Requirements
  2. Shared Responsibility Model in Google Cloud
  3. Assured Workloads for Compliance
  4. Organizational Policies for Compliance
  5. Access Transparency and Access Approval
  6. Data and Service Regionalization
  7. Google Cloud Environment Scope for Regulatory Compliance
  8. Mapping Compliance Requirements to Google Cloud Services
  9. Network and Access Segmentation for Compliance
  10. Audit Log Coverage for Compliance
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for PROFESSIONAL-CLOUD-SECURITY-ENGINEER, so none is invented.