Skip to content

PCSE Practice Questions

Prepare for PCSE with more than an answer.

234 questions in the full set20 sample questionsUpdated Mar 12, 2026

Unlock the full exam and previous versions

  • v1Professional Cloud Security Engineer 180 questions Locked
  • PCSELegacy Professional Cloud Security Engineer 234 questions Current
  1. 1

    An e-commerce platform running on Google Cloud is experiencing a DDoS attack targeting its external HTTPS load balancer. The security team wants to immediately block traffic from a specific country identified as the primary source of the attack, without affecting legitimate users. What is the fastest and most effective solution?

    Show answer details

    Correct answer: B

    Cloud Armor is Google's Web Application Firewall (WAF) and DDoS mitigation service. It integrates directly with the external HTTPS load balancer. You can create a security policy with a rule that uses geolocation matching (origin.region_code) to deny traffic from a specific country. This is the intended and most effective way to handle such an attack at the edge of Google's network.

  2. 2

    Your company wants to scan all its Cloud Storage buckets across hundreds of projects to discover and classify any stored data that contains personally identifiable information (PII), such as credit card numbers and national identification numbers. The scan should run periodically, and the results must be aggregated into a central project for review by the security team. What is the Google-recommended approach?

    Show answer details

    Correct answer: B

    The discovery feature of Sensitive Data Protection is designed for this exact use case. You can configure a scan at the organization or folder level to automatically discover and profile data across Cloud Storage, BigQuery, and Cloud SQL. The results, which show data risk and sensitivity levels, can be sent to various destinations, including Security Command Center, providing a centralized view for the security team. This is far more efficient and scalable than a manual approach.

  3. 3

    A media company provides its video editors with powerful Compute Engine VMs for rendering. To prevent unauthorized distribution of pre-release content, the security team wants to block these VMs from accessing the public internet while still allowing them to be managed via SSH from the corporate office. The corporate office is connected to the project's VPC via Cloud VPN. What should you configure? (Select TWO)

    Show answer details

    Correct answer: A, C

  4. 4

    A security team needs to ensure that any new service account created within the organization cannot be granted the iam.serviceAccountUser role on itself, which could be used for privilege escalation. This rule must be enforced preventatively and should not be bypassable by project owners. What is the best way to implement this control?

    Show answer details

    Correct answer: D

    This is a specific Organization Policy constraint designed to prevent this exact security risk. By enforcing iam.disableServiceAccountSelfImpersonation at the organization level, you prevent any IAM policy from granting a service account the ability to impersonate itself. This is a preventative control that cannot be overridden at lower levels of the hierarchy, making it the most robust solution.

  5. 5

    You are a security architect for a large enterprise. You need to design a system that allows on-premises systems to privately access and consume services running in a producer VPC on Google Cloud, such as a managed database. The connection must not traverse the public internet, must be highly available, and should use a private, internal IP address for the service endpoint within the consumer's on-premises network. What should you configure?

    graph TD subgraph On-Premises Data Center OnPremApp[On-Premises Application] end subgraph Google Cloud subgraph Consumer VPC Interconnect[Cloud Interconnect] PSC_Endpoint[Private Service Connect Endpoint] end subgraph Producer VPC ManagedDB[(Managed Database)] PSC_Attachment[Private Service Connect Attachment] end end OnPremApp --> Interconnect Interconnect --> PSC_Endpoint PSC_Endpoint --> PSC_Attachment PSC_Attachment --> ManagedDB

    Show answer details

    Correct answer: D

    This scenario perfectly describes the use case for Private Service Connect (PSC) combined with Cloud Interconnect. Cloud Interconnect provides the dedicated, highly available private link from on-premises to Google Cloud. Private Service Connect allows a service producer to expose a service via an internal IP address without the consumer's VPC needing to peer or have routes to the producer's VPC. The consumer creates an endpoint in their own VPC, which can be accessed from their on-premises network over the Interconnect. This provides secure, private, service-oriented connectivity across network boundaries.

  6. 6

    A financial services company is migrating its batch processing workloads to Google Cloud. A key regulatory requirement is that no virtual machine involved in processing can have a public IP address. Additionally, these VMs must be able to pull dependencies from a public container registry and access Google Cloud APIs like BigQuery and Cloud Storage. The security team has mandated the most restrictive network configuration possible. Which configuration meets these stringent requirements?

    Show answer details

    Correct answer: D

    This is the most secure and correct configuration. A Cloud NAT gateway allows the VMs without public IPs to access the public container registry. Using the restricted.googleapis.com virtual IP address ensures that traffic to Google APIs does not traverse the public internet and is protected by VPC Service Controls, which is a more restrictive method than standard Private Google Access.

  7. 7

    A security auditor is reviewing your organization's resource hierarchy. They have identified a critical folder containing production projects. The auditor requires a non-modifiable policy that prevents any user, including Organization Administrators, from linking projects in this critical folder to a non-approved billing account. Which IAM feature should you use to enforce this?

    Show answer details

    Correct answer: B

    IAM Deny policies are evaluated before any allow policies and cannot be overridden by more permissive IAM roles, including Organization Administrator. This makes them ideal for creating preventative guardrails. An Organization Policy could be modified or overridden by a user with sufficient permissions, making it less suitable for a non-modifiable control.

  8. 8

    You are designing a security strategy for a large-scale data analytics platform on Google Cloud. The platform ingests sensitive customer data into Cloud Storage, which is then processed by Dataproc clusters. You need to ensure that the raw data is de-identified before being loaded into a BigQuery data warehouse for analysis. The de-identification must be format-preserving and reversible by a small, authorized group of data custodians for auditing purposes. Which combination of services should you use? (Select TWO)

    Show answer details

    Correct answer: A, B

  9. 9

    A healthcare organization is deploying a new patient portal application on Google Kubernetes Engine (GKE). To comply with HIPAA, they must log all administrator actions and all access events to patient data stored in a backend Cloud SQL database. The security team wants to retain these specific logs for 10 years in a low-cost, immutable storage solution for potential audits. What is the most efficient way to configure this?

    Show answer details

    Correct answer: C

    This approach is the most efficient and meets all requirements. A log sink can be configured with a specific filter to only export the required audit logs. Exporting to Cloud Storage is cost-effective for long-term archival. Applying a retention policy and Bucket Lock ensures the logs are immutable for the specified 10-year period, satisfying audit and compliance needs.

  10. 10

    Your company uses an on-premises Active Directory (AD) as its primary identity provider. You need to grant developers access to Google Cloud projects based on their AD group memberships. The security policy requires that users authenticate directly against the on-premises AD, and their session with Google Cloud should be valid for a maximum of 8 hours. What should you configure to meet these requirements?

    Show answer details

    Correct answer: B

    This solution meets all requirements. Configuring SAML-based SSO ensures that authentication happens directly against the on-premises AD FS. GCDS is used to sync group memberships, allowing for group-based IAM policies in Google Cloud. Session duration is controlled by the identity provider (AD FS in this case), satisfying the 8-hour session limit requirement.

Create an account to continue.