Skip to content

Ensuring data protection Questions

Practice questions for Ensuring data protection topic in Google Professional Cloud Security Engineer. 47 questions covering this domain.

47 questions10 easy25 medium12 hard
Q1
medium

A secret uses user-managed replication in several regions. One configured region is unavailable during an update. What happens?

Q2
easy

Which service is designed to store and manage secret values such as passwords and API keys, rather than perform cryptographic operations with encrypti...

Q3
medium

Which statement correctly describes Cloud External Key Manager?

Q4
hard

A company wants Cloud KMS to initiate creation and rotation of coordinated external keys. Which setup is required?

Q5
medium

What does a Binary Authorization attestation represent?

Q6
hard

What is the consequence of losing access to either side of a Cloud EKM key relationship?

Q7
medium

A company uses manually managed external keys with Cloud EKM. Which operational consideration is correct?

Q8
medium

Which Google Cloud service provides vulnerability scanning and metadata storage for containers on Google Cloud?

Q9
easy

Why would a team use Secret Manager versions and aliases for an application secret?

Q10
hard

Which statement correctly distinguishes Binary Authorization enforcement from continuous validation?

Q11
medium

A regulated workload requires secret payloads to be stored only in a customer-selected set of regions. Which Secret Manager replication choice fits th...

Q12
easy

Which Google Cloud service is built to inspect, classify, and de-identify sensitive data such as PII in text, storage systems, and images?

Q13
medium

An organization wants to classify and tag all sensitive data stored in Cloud Storage and BigQuery across the entire organization automatically without...

Q14
medium

A company implements Binary Authorization for all GKE deployments. A developer reports that a valid container image is being blocked at deployment eve...

Q15
hard

A financial company must ensure that its Cloud KMS keys can never be used without its knowledge, even by Google employees. They also need the ability ...

Q16
medium

A data engineering team wants to allow data analysts to query production BigQuery tables containing PII without ever seeing the raw PII values. Which ...

Q17
medium

A security team wants to ensure that Cloud Storage objects in a regulated bucket cannot be deleted or overwritten for a minimum retention period of se...

Q18
easy

Which Cloud KMS key type allows hardware-based cryptographic operations and lets you perform key generation and destruction using a FIPS 140-2 Level 3...

Q19
medium

A Cloud Storage bucket uses a CMEK from Cloud KMS. The security team disables the CMEK key version without destroying it. What happens to access to ob...

Q20
easy

What is the purpose of a data residency organization policy constraint in Google Cloud?

Sign in to see all 47 questions

Create a free account to browse all questions — completely free during our launch phase.