Professional Cloud Security Engineer Practice Questions
Prepare for GCP-PCSE with more than an answer.
Unlock the full exam and previous versions
- v1Professional Cloud Security Engineer 180 questions Current
- PCSELegacy Professional Cloud Security Engineer 234 questions Locked
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- Configuring Access25%
- Securing Communications and Establishing Boundary Protection22%
- Ensuring Data Protection23%
- Managing Operations19%
- Supporting Compliance Requirements11%
- 1
True or False: When a new Google Cloud project is created and the Compute Engine API is enabled, the default Compute Engine service account is automatically created and granted the Editor basic role on the project, posing a significant security risk if left unmodified.
Show answer details
Correct answer: A
True. By default, when the Compute Engine API is enabled, Google Cloud creates a default Compute Engine service account (format: [email protected]) and automatically grants it the highly permissive Editor role. Security best practices mandate disabling this behavior via Organization Policies or replacing the default service account with a custom, least-privilege service account.
- 2
A fast-growing tech company frequently hires new developers. The IT administrator currently assigns IAM roles to each developer's individual email address. As the team grows, auditing and maintaining access has become a severe operational bottleneck. What is the Google Cloud best practice to resolve this issue?
Show answer details
Correct answer: B
The Google Cloud security best practice for managing access at scale is to assign IAM roles to Google Groups rather than individual users. This centralizes access management, simplifies auditing, and ensures that when a user leaves the company or changes teams, updating their group membership automatically adjusts their Google Cloud access.
- 3
The security team is auditing the Google Workspace / Cloud Identity environment and discovers that several Super Administrator accounts rely solely on passwords and SMS-based 2-Step Verification. What is the most critical immediate action the team should take to secure these high-privilege accounts against phishing and SIM-swapping attacks?
Show answer details
Correct answer: A
Super Administrator accounts possess ultimate control over the Google Workspace and Google Cloud environment. Because SMS-based 2FA is vulnerable to SIM-swapping and phishing, Google strongly recommends enforcing hardware security keys (like Titan Security Keys) for all Super Admins, as they provide phishing-resistant multi-factor authentication.
- 4
NovaTech is a multi-cloud organization that runs its primary CI/CD pipelines in AWS. These AWS-based pipelines need to deploy infrastructure and upload build artifacts to Google Cloud. The Chief Information Security Officer (CISO) has strictly forbidden the creation and export of long-lived Google Cloud Service Account keys to prevent credential leakage. Which approach is the most secure and optimal way to grant the AWS pipelines access to Google Cloud resources?
Show answer details
Correct answer: B
Workload Identity Federation is the optimal and recommended way to grant on-premises or multi-cloud workloads access to Google Cloud resources without using long-lived service account keys. By configuring an identity pool and an AWS provider, AWS workloads can exchange their AWS STS tokens for short-lived Google Cloud access tokens, eliminating the risk of key leakage.
flowchart LR A[AWS Pipeline] -->|1. AWS STS Token| B(GCP Workload Identity Pool) B -->|2. Exchange Token| A A -->|3. Impersonate| C[GCP Service Account] C -->|4. Access| D[(GCP Resources)] - 5
Aegis Healthcare uses Google Cloud to store sensitive patient records in a specific folder named 'PatientData'. The organization has an IAM Allow policy at the folder level granting the 'Data Analysts' group the
roles/bigquery.dataViewerrole. However, a recent compliance audit requires that a specific contractor team (which is part of the Data Analysts group) must NEVER have access to the 'PatientData' folder under any circumstances. What is the most robust and scalable way to enforce this restriction?Show answer details
Correct answer: B
IAM Deny policies are evaluated before IAM Allow policies. If an IAM Deny policy explicitly denies a permission, the principal cannot perform the action, regardless of any Allow policies they possess. This is the most robust way to ensure a specific group is blocked from accessing sensitive data, even if they inherit broad allow permissions from higher up in the resource hierarchy.
- 6
Zephyr Financial is implementing least privilege across its engineering teams. Site Reliability Engineers (SREs) normally only have Viewer access to production projects. During a P1 incident, they need elevated privileges (e.g.,
roles/compute.admin) to mitigate issues, but these privileges must expire automatically after 2 hours and require approval from an engineering manager. Which Google Cloud service should be configured to meet this requirement?Show answer details
Correct answer: A
Privileged Access Manager (PAM) enables Just-In-Time (JIT) access in Google Cloud. It allows administrators to define entitlements that grant temporary, elevated access to resources. Requesters can ask for this access when needed, optionally requiring approvals, and the access automatically expires after a configured duration.
