Google Professional Cloud Security Engineer Questions and Answers
350 questions organized by topic with detailed explanations
Google
GCP-PCSE
350 questions
5 topics
Updated Jul 2026Configuring access
89 questions21 easy44 medium24 hard~25% of exam
Which IAM role type should generally be avoided in production because it is highly permissive and grants broad access ac...A company wants a custom role for a folder-scoped administration task and includes a folder-specific permission. Which s...A team needs an identity for an application running on Compute Engine to call Google Cloud APIs. Which identity type is ...
Securing communications and establishing boundary protection
72 questions19 easy34 medium19 hard~22% of exam
Before enforcing a new VPC Service Controls perimeter, a team wants to observe violations without denying requests. Whic...Which statement correctly describes VPC firewall rule evaluation?A VM has only an internal IP address and must reach Google APIs and services from its subnet. Which VPC feature is requi...
Ensuring data protection
81 questions19 easy40 medium22 hard~23% of exam
A secret uses user-managed replication in several regions. One configured region is unavailable during an update. What h...Which service is designed to store and manage secret values such as passwords and API keys, rather than perform cryptogr...Which statement correctly describes Cloud External Key Manager?
Managing operations
68 questions15 easy34 medium19 hard~19% of exam
For most Google Cloud services, which audit log type is disabled by default because of its potentially large volume?Which service is Google Cloud's centralized vulnerability and threat reporting platform that also provides asset invento...What happens when Binary Authorization blocks a deployment because an image does not satisfy policy?
All Questions
| # | Question | Topic | Difficulty |
|---|---|---|---|
| 1 | For most Google Cloud services, which audit log type is disabled by default because of its potential... | Managing operations | medium |
| 2 | A secret uses user-managed replication in several regions. One configured region is unavailable duri... | Ensuring data protection | medium |
| 3 | Before enforcing a new VPC Service Controls perimeter, a team wants to observe violations without de... | Securing communications and establishing boundary protection | medium |
| 4 | Which IAM role type should generally be avoided in production because it is highly permissive and gr... | Configuring access | easy |
| 5 | Which service is designed to store and manage secret values such as passwords and API keys, rather t... | Ensuring data protection | easy |
Sign in to see all 350 questions
Create a free account to browse the questions included with the free plan.
Ready to test your knowledge?
Take a full Google Professional Cloud Security Engineer practice test with timed exam simulation.
Start Practice Test