20+ practice questions focused on Designing for Security and Compliance — one of the most tested topics on the Google Professional Cloud Architect exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Designing for Security and Compliance PracticeA company wants to use its existing Active Directory credentials to authenticate users to the GCP Console. Which service should they integrate with?
Explanation: Cloud Identity (or Google Workspace) can be configured with SAML SSO so that an external identity provider — in this case Active Directory Federation Services or Entra ID — authenticates users and issues SAML assertions to the GCP Console. This lets users sign in with existing AD credentials without duplicating accounts in Google. The integration is established by exchanging metadata between AD FS/Entra ID and Google's SAML SSO configuration.
A company uses Cloud Armor to protect an HTTP(S) Load Balancer. They want to block traffic from a specific IP address range during off-peak hours but allow it during peak hours. How can they achieve this?
Explanation: Cloud Armor security policy rules support CEL-based match conditions, and the condition language includes request.time, which lets you scope a rule to a specific time window (e.g., off-peak hours). By combining an IP-range match (srcIpRanges) with a time condition in a single rule, the policy denies the range only during the configured window and allows it otherwise, satisfying the requirement without external automation.
A company wants to enforce that only approved container images can be deployed to GKE. They also want to ensure images are scanned for vulnerabilities before deployment. Which two GCP services should they use? (Choose TWO).
Explanation: Binary Authorization (E) is the GKE-native admission controller that enforces deploy-time policy, allowing only images that meet attestation requirements (e.g., signed by a trusted authority or scanned) to be admitted to the cluster, which directly satisfies the 'only approved images' requirement. Container Analysis API (A) is the underlying service that stores and serves metadata about container images, including vulnerability findings and attestations, and it is what Binary Authorization queries to verify that an image has been scanned and attested before deployment. Together they form the standard GKE supply-chain security pattern: Container Analysis provides the vulnerability/attestation data, and Binary Authorization enforces the policy at admission time. Cloud Security Command Center (B) is a security posture and findings dashboard, not a deploy-time enforcement mechanism, so it cannot block unapproved images. Container Registry vulnerability scanning (C) is a feature that triggers scans and publishes results to Container Analysis, but scanning alone does not enforce that only approved images are deployed. Cloud Build (D) is a CI/CD build service that can run scans or create attestations, but it is not the enforcement or metadata service required here.
A company needs to store secrets used by multiple GCP services. They require automatic rotation of secrets every 30 days and integration with Cloud Functions. Which two GCP services should they use? (Choose TWO).
Explanation: Secret Manager (C) is the correct service for centrally storing and managing secrets, and it natively supports automatic rotation schedules (for example, a 30-day rotation period) plus IAM-based access for multiple GCP services. Cloud Functions (B) is correct because it can be triggered by Secret Manager rotation notifications (via Pub/Sub) to execute the rotation logic, and it can also retrieve secrets at runtime through the Secret Manager API. Cloud Run (A) is a container hosting platform, not a secret store or rotation mechanism, so it does not satisfy the requirement. Cloud KMS (D) manages encryption keys rather than application secrets and does not provide secret rotation for arbitrary credentials. Cloud Scheduler (E) can trigger jobs on a cron schedule but is not a secret store and cannot itself perform secret rotation or integrate as the secret backend.
A company wants to protect a web application from SQL injection and cross-site scripting (XSS) attacks. They also need to block traffic from specific geographic regions. Which three features of Cloud Armor should they use? (Choose THREE).
Explanation: Google Cloud Armor's WAF rules (B) are the correct feature for defending a web application against SQL injection and XSS, because the preconfigured OWASP ModSecurity Core Rule Set signatures (e.g., sqli-v33-stable and xss-v33-stable) detect and block these Layer 7 payload patterns. Geographic restrictions (C) are correct because Cloud Armor security policies can include geo-based rules that allow or deny traffic by source country/region using the origin's geographic location, which directly satisfies the requirement to block specific regions. Rate limiting (A) is correct because Cloud Armor rate-based rules throttle or ban clients that exceed a configured request threshold per interval, protecting the application from abusive or volumetric request floods that often accompany injection/XSS probing. Cloud CDN (D) is not a Cloud Armor security feature; it is a content delivery service and does not itself filter SQLi/XSS or enforce geo-blocking. Adaptive Protection (E) is a Cloud Armor capability that learns baseline traffic and suggests or auto-deploys rules against Layer 7 DDoS, but it is not the feature used to specifically block SQLi/XSS signatures or geographic regions.
+15 more Designing for Security and Compliance questions available
Practice all Designing for Security and Compliance questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Designing for Security and Compliance. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Designing for Security and Compliance questions on the PCA frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Designing for Security and Compliance is tested as part of the Google Professional Cloud Architect blueprint. Practicing with targeted Designing for Security and Compliance questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free PCA practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Designing for Security and Compliance is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Designing for Security and Compliance practice session with instant scoring and detailed explanations.
Start Designing for Security and Compliance Practice →