Google Cloud · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
25% of exam · 6 sample questions below
An organization uses Active Directory (AD) on-premises and wants to synchronize user accounts and groups to Google Cloud Identity for SSO with SAML 2.0. The AD contains 50,000 users and 10,000 groups. The solution must support automatic provisioning and deprovisioning of users. Which tool should they use?
Use SAML 2.0 federation with AD FS to synchronize users.
Use Workload Identity Federation to connect AD to Google Cloud.
Use the Cloud Identity API to manually create users and groups.
Use Google Cloud Directory Sync (GCDS) to synchronize users and groups from AD to Cloud Identity.
Google Cloud Directory Sync (GCDS) reads on-premises Active Directory directly and writes users and groups into Cloud Identity, satisfying the 50,000-user and 10,000-group scale without a Microsoft Entra ID dependency. It performs scheduled one-way synchronisation, so accounts removed from AD are deprovisioned in Cloud Identity automatically.
A developer wants to grant a Compute Engine instance access to read objects from a Cloud Storage bucket. The instance runs under a service account. What is the best practice for granting this access?
Create an IAM policy on the bucket that grants access to the instance's external IP address.
Assign the Storage Object Viewer role to the service account attached to the instance.
Attaching the Storage Object Viewer role to the instance's service account grants read-only access to bucket objects via IAM, satisfying least privilege without embedding keys. This is the recommended practice for Compute Engine workloads accessing Cloud Storage.
Use a signed URL with a long expiration time for the instance.
Generate a JSON key for the service account, download it to the instance, and use it in application code.
What is the purpose of Identity-Aware Proxy (IAP) on Google Cloud?
To enforce identity-based access control for web applications and SSH/RDP to VMs without requiring a VPN.
Identity-Aware Proxy sits in front of applications and VM services, verifying user identity and context before granting access. This enforces identity-based access control for web apps and SSH/RDP to VMs, removing the need for a VPN.
To manage firewall rules for VPC networks.
To provide a VPN connection between on-premises and Google Cloud.
To act as a web application firewall (WAF) that blocks SQL injection and XSS attacks.
A DevOps team uses GitHub Actions to deploy infrastructure to Google Cloud. They want to avoid storing long-lived service account keys. Which approach should they use to authenticate from GitHub Actions to Google Cloud?
Grant the service account token creator role to the GitHub Actions runner.
Download a JSON service account key and store it as a GitHub secret.
Use Workload Identity Federation by configuring a workload identity pool and provider for GitHub.
Workload Identity Federation lets GitHub Actions exchange its OIDC token for short-lived Google Cloud credentials via a workload identity pool and provider, eliminating stored service account keys entirely. This directly satisfies the stem's constraint of avoiding long-lived credentials, unlike exporting JSON keys.
Create a Compute Engine instance with a service account and run GitHub Actions from there.
A company wants to use Google Cloud resources but does not have a Google Workspace or Cloud Identity account. They want to manage identities for their users without paying for additional licenses. What is the most cost-effective identity solution?
Use the Compute Engine default service account for all users.
Use Cloud Identity Premium edition.
Use Cloud Identity Free edition.
Cloud Identity Free edition provides Google identities without Workspace licences or per-user charges, satisfying the no-additional-licence constraint. It supplies the Google identity namespace that Google Cloud IAM requires for principals, unlike Microsoft Entra ID, which cannot natively authenticate users into Google Cloud. This makes it the most cost-effective fit for the stated scenario.
Use Google Workspace.
A developer needs to create a custom IAM role that allows only a specific set of permissions for managing Cloud SQL instances. The role should be available at the organization level. Which command should they use?
gcloud iam roles create ROLE_ID --organization=ORGANIZATION_ID --file=role.yaml
The gcloud iam roles create command with the --organization flag scopes the custom role to the entire organisation, matching the requirement. Project- or folder-level flags would restrict availability, so the organisation parameter is essential for org-wide Cloud SQL permissions.
gcloud projects add-iam-policy-binding PROJECT_ID --member=... --role=...
gcloud iam service-accounts create SA_NAME --display-name=...
gcloud organizations add-iam-policy-binding ORGANIZATION_ID --member=... --role=...
Want more Configuring Access Within a Cloud Solution Environment practice?
Practice this domain23% of exam · 6 sample questions below
A company uses Cloud KMS with a key purpose of ENCRYPT_DECRYPT. They need to rotate the key automatically every 30 days. What must they configure?
Set a rotation period of 30 days on the key.
Setting a 30-day rotation period on the Cloud KMS key directly satisfies the automatic rotation requirement. Cloud KMS supports scheduled rotation for symmetric ENCRYPT_DECRYPT keys, generating new key versions at the defined interval while retaining older versions for decryption, so no manual intervention or re-encryption is needed.
Use a cron job to rotate keys manually every 30 days.
Set a rotation period of 30 days on the key ring.
Set a rotation period on the key version.
Which Google Cloud service provides near-real-time logs when Google administrators access your customer content?
Access Transparency
Access Transparency delivers near-real-time logs of Google administrators' actions on your customer content, satisfying the stem's requirement for visibility into Google-side access. Unlike Cloud Audit Logs, which record actions by principals within your own project, Access Transparency specifically captures Google personnel activity, providing the transparency control needed for regulatory and compliance scenarios.
Access Approval
Cloud DLP
Cloud Audit Logs
A company stores API keys in Secret Manager. They want to automatically rotate the secret every 60 days and have a Cloud Function triggered after each rotation to update dependent services. What is the correct approach?
Manually rotate the secret and set a Cloud Scheduler job to invoke the Cloud Function.
Use Cloud Scheduler to call the Secret Manager API to add a new version every 60 days, then trigger a Cloud Function via HTTP.
Set a rotation period on the secret and directly specify a Cloud Function as a webhook in Secret Manager.
Set a rotation period on the secret and configure a Pub/Sub topic for notifications. Create a Cloud Function subscribed to that topic.
Secret Manager rotation schedules the 60-day cycle natively, and publishing rotation events to a Pub/Sub topic lets a subscribed Cloud Function run the dependent-service updates automatically, satisfying both the rotation interval and post-rotation trigger requirements without custom polling.
An organization needs to enforce that all new Cloud Storage buckets are created only in the europe-west1 region to meet data residency requirements. Which method should they use?
Assign the roles/storage.admin IAM role with a condition that restricts region.
Use Assured Workloads to enforce data residency.
Define a bucket policy that allows only europe-west1.
Configure an organization policy with the constraint gcp.resourceLocations to allow only europe-west1.
An organisation policy using gcp.resourceLocations enforces the allowed regions at the organisation level, so every new bucket is constrained to europe-west1 regardless of who creates it. IAM roles and bucket-level settings cannot centrally prevent creation in other regions.
A financial services company uses BigQuery for analytics and needs to implement column-level security such that users with the role 'data_scientist' can see the last four digits of credit card numbers, while the full number is visible only to 'data_owner'. What approach should they use?
Use a policy tag with a data masking rule that masks the full number except last four digits, and grant UNMASKED access to data_owner and MASKED access to data_scientist.
Policy tags apply classification to the credit card column, and the masking rule with UNMASKED access for data_owner and MASKED access for data_scientist enforces the last-four-digits visibility at query time. This satisfies column-level security without duplicating data.
Set an IAM condition on the table that filters the column based on the user's role.
Use row-level security to restrict rows based on role.
Create two separate BigQuery tables (one with masked data, one with full data) and grant access based on role.
What is the purpose of the Cloud DLP InfoType detector CREDIT_CARD_NUMBER?
It encrypts credit card numbers automatically.
It detects credit card numbers in data during inspection.
The CREDIT_CARD_NUMBER InfoType is a built-in detector that identifies payment card numbers during Cloud DLP inspection, matching patterns for major card issuers. It satisfies the requirement to detect credit card numbers in scanned data, enabling classification and redaction.
It redacts credit card numbers from images.
It de-identifies credit card numbers using masking.
Want more Ensuring Data Protection practice?
Practice this domain19% of exam · 6 sample questions below
A company wants to receive real-time notifications when Security Command Center (SCC) detects a high-severity vulnerability in their Google Cloud projects. They need to integrate with their existing SIEM. Which approach should they use?
Create a Pub/Sub notification config in SCC for the desired finding types and have the SIEM subscribe to the Pub/Sub topic.
Security Command Center publishes findings to a Pub/Sub topic via a notification config filtered by severity and finding type. The SIEM subscribes to that topic, receiving near-real-time high-severity vulnerability alerts without polling, satisfying the integration requirement.
Use the SCC API to poll for new findings every minute and push them to the SIEM via a custom script.
Enable Event Threat Detection in SCC Premium tier and configure it to stream findings to Cloud Logging via a log sink.
Configure SCC to send findings to Cloud Logging and set up a log-based metric that triggers a Cloud Function to send to the SIEM.
A DevOps team is implementing Binary Authorization for a GKE cluster. They want to ensure that only container images signed by a specific attestor can be deployed. They have created the attestor and configured Cloud KMS for signing. Which additional step is required to enforce the policy?
Enable the 'gke-binary-authorization' feature flag on the cluster and update the kubeconfig.
Create a Binary Authorization policy that requires at least one attestation and attach it to the GKE cluster.
Creating the policy with `requireAttestationsBy` referencing the named attestor is what actually enforces admission control; the attestor and Cloud KMS key alone merely enable signing. Attaching that policy to the GKE cluster satisfies the stem's constraint that only images signed by that specific attestor deploy.
Create a policy that allows all images and then override it with an admission webhook.
Configure the container registry to block unsigned images by setting a repository-level policy.
A company is using Security Command Center (SCC) Standard tier and wants to detect threats like crypto mining attacks and anomalous IAM activity in their GCP environment. Which built-in service should they enable?
Event Threat Detection
Event Threat Detection is a built-in SCC service that continuously analyses Cloud Logging and other telemetry for threats including cryptomining and anomalous IAM activity. Enabling it satisfies the requirement to detect these specific threat categories without building custom rules.
Security Health Analytics
Web Security Scanner
VM Threat Detection
An organization uses Chronicle SIEM to ingest logs from multiple GCP projects and on-premises firewalls. They need to write a detection rule that triggers when an IP address makes more than 100 failed login attempts across different GCP projects within 10 minutes. Which Chronicle feature should they use?
Dashboard and alerting
Reference list
Unified Data Model (UDM)
YARA-L detection rule
YARA-L is Chronicle's detection language, and its multi-event rules correlate events across sources and time windows using UDM fields. That correlation capability satisfies the requirement to aggregate over 100 failed logins per IP across separate GCP projects within a ten-minute sliding window.
A company wants to scan all container images stored in Artifact Registry for vulnerabilities before deployment. Which Google Cloud service should they use?
Binary Authorization
Cloud Build
Container Analysis
Container Analysis scans Artifact Registry images for OS and language package vulnerabilities, producing findings before deployment. It satisfies the requirement to scan stored container images within Google Cloud, whereas alternatives such as Security Command Center aggregate findings rather than perform the registry-level scanning itself.
Security Command Center
Which Security Command Center (SCC) tier provides built-in compliance monitoring for standards like CIS and PCI DSS?
Neither; compliance monitoring is part of Cloud Audit Logs
Both Standard and Premium
Premium tier
Premium tier adds built-in compliance monitoring against standards including CIS benchmarks and PCI DSS, plus attack path simulation and threat detection. Standard tier only surfaces Security Health Analytics misconfigurations without the compliance dashboards, so it cannot satisfy this requirement.
Standard tier
Want more Managing Operations in a Cloud Solution Environment practice?
Practice this domain22% of exam · 6 sample questions below
A security engineer needs to restrict access to Cloud Storage buckets so that only resources in a specific VPC can reach the Google APIs. Which Google Cloud service should be used?
Firewall Rules
VPC Service Controls
VPC Service Controls builds a service perimeter around Google APIs, restricting Cloud Storage bucket access to resources inside the specified VPC. This satisfies the requirement that only in-VPC resources reach the Google APIs, which IAM alone cannot enforce.
Identity-Aware Proxy
Cloud Armor
An organization wants to enforce a security policy that denies all egress traffic to the internet from all projects in the organization, except for traffic from a specific set of VMs tagged with 'allow-egress'. Which approach should be used?
Create a VPC firewall rule at the organization level to deny all egress, then allow egress for the specific tag.
Use a hierarchical firewall policy at the organization level with a deny-all egress rule and a higher priority allow rule for the tag.
Hierarchical firewall policies apply across projects and cannot be overridden, ensuring baseline enforcement.
Use VPC Service Controls to block egress traffic.
Configure Cloud Armor with a deny-all egress rule and an exception for the tag.
A company uses VPC Service Controls to protect a BigQuery dataset. They need to allow an external on-premises application to query the dataset without being inside the service perimeter. The external application has a static IP address. Which configuration is required?
Add the external IP to an access level and configure an ingress rule in the service perimeter.
An ingress rule with an IP-based access level allows traffic from that IP to cross the perimeter.
Whitelist the external IP in the BigQuery dataset's IAM policy.
Create a Cloud VPN tunnel between the on-premises network and the VPC, and add the tunnel to the service perimeter.
Use Private Google Access on the VPC to allow on-premises traffic.
An engineer needs to block a specific IP address from accessing an HTTPS load balancer. Which Cloud Armor rule should be used?
A VPC firewall rule with a deny ingress for that IP
A custom rule with a 'deny' action and the IP address in the 'src_ip_ranges' field
A custom rule with a deny action and the IP address in the src_ip_ranges field matches on the source IP of incoming connections, which is precisely what the load balancer evaluates before forwarding traffic. This satisfies the requirement to block that specific address at the edge, without affecting other clients.
A Cloud Armor rate limiting rule
A preconfigured rule from the OWASP ModSecurity CRS
A company wants internal VMs to access Google APIs (e.g., Cloud Storage, BigQuery) without traversing the internet. What is the simplest configuration?
Assign external IPs to all VMs and use VPC firewall rules to restrict egress.
Use Cloud NAT to route traffic to Google APIs.
Enable Private Google Access on the subnet where the VMs reside.
Private Google Access lets VMs with only internal IP addresses reach Google APIs and services using internal routing, avoiding the public internet. Enabling it on the subnet satisfies the no-internet-traversal constraint with minimal configuration, requiring no NAT or proxy.
Set up Private Service Connect to googleapis.com.
An organization uses VPC Service Controls in dry-run mode for a project containing Google Cloud Storage. They notice that BigQuery jobs are being logged as violations. How should they interpret this?
The perimeters are logging potential violations; no action has been taken yet.
Dry-run mode only logs what would be denied; it never enforces. The BigQuery entries are therefore potential violations recorded for evaluation, and no traffic has actually been blocked, so the organisation can review impact before enforcing the perimeter.
The dry-run mode is not supported for Cloud Storage projects.
The perimeters are not configured correctly because BigQuery should not be affected.
The perimeters are working correctly and BigQuery access is blocked.
Want more Configuring Network Security practice?
Practice this domain11% of exam · 6 sample questions below
A healthcare organization is required to protect Protected Health Information (PHI) stored in Cloud Storage. They want to automatically detect and redact PHI before storing it. Which Google Cloud service should they use?
Cloud Armor
Cloud Data Loss Prevention (DLP)
Cloud Data Loss Prevention inspects Cloud Storage content using infoType detectors to identify PHI, then applies de-identification transforms such as redaction before storage. This satisfies the requirement to automatically detect and redact PHI, unlike encryption or access-control services.
VPC Service Controls
Security Command Center
A company needs to retain audit logs for 7 years to meet compliance requirements. By default, Cloud Audit Logs are retained for 30 days. What should they do to retain the logs for 7 years?
Increase the default audit log retention period in the Logging settings to 7 years.
Enable Logging export to BigQuery and set table expiration to 7 years.
Use Cloud Functions to copy audit logs daily to Coldline Storage.
Create a log sink to export audit logs to a Cloud Storage bucket with a retention policy set to 7 years.
A log sink routes copies of audit log entries to a Cloud Storage bucket, and the bucket's retention policy locks objects for seven years, exceeding the default 30-day retention. This satisfies the compliance requirement without altering the original log bucket.
A financial institution is deploying a payment application on GKE that must comply with PCI DSS. They need to isolate the cardholder data environment (CDE) from other workloads and ensure only authorized services can communicate. Which combination of controls should they implement?
Use Cloud Armor to inspect all traffic and block non-compliant requests.
Use a separate VPC and VPC Service Controls perimeter for the CDE, and apply Kubernetes Network Policies to restrict pod communication.
A separate VPC plus a VPC Service Controls perimeter isolates the CDE at the network and API boundary, while Kubernetes Network Policies enforce pod-level least-privilege communication. Together these satisfy PCI DSS segmentation and authorised-services-only requirements.
Enable Data Loss Prevention to scan payment data and restrict access.
Deploy the CDE in a separate project and use IAM roles to restrict access.
An organization handles ITAR-controlled data and must restrict Google personnel access to the underlying infrastructure. Which Google Cloud product should they use to enforce this restriction?
Assured Workloads
Assured Workloads enforces ITAR compliance through data residency controls and personnel access restrictions, ensuring only vetted US persons can access the underlying infrastructure. It satisfies the requirement to prevent Google personnel without appropriate clearance from accessing controlled data, unlike standard projects lacking these sovereign controls.
IAM Conditions
VPC Service Controls
Cloud HSM
A company processes personal data of European Union residents on GCP. They need to ensure that data processing is limited to specific purposes and that data subjects can exercise their rights (access, rectification, erasure). Which actions should they take to comply with GDPR?
Use Assured Workloads with EU Regions and Support and enable Access Transparency.
Enable data encryption with CMEK and sign a DPA with Google.
Sign a DPA with Google, implement data subject request workflows, and use Cloud DLP to classify personal data.
A data processing addendum with Google establishes processor obligations and purpose limitation, while request workflows operationalise access, rectification and erasure rights. Cloud DLP classification identifies where personal data resides, supporting the accountability and purpose-limitation requirements of GDPR.
Enable VPC Service Controls and restrict data access to EU regions.
A security engineer wants to test a web application hosted on Compute Engine for vulnerabilities. According to Google Cloud's Acceptable Use Policy, which of the following is true regarding penetration testing?
Penetration testing is allowed only for customers with Enterprise support plans.
All penetration testing requires prior written approval from Google.
Penetration testing is allowed without prior approval, but Denial of Service (DoS) testing is prohibited.
Google Cloud's Acceptable Use Policy permits customers to run penetration tests against their own Compute Engine resources without prior notification or approval, but explicitly prohibits denial-of-service testing. This satisfies the question's constraint by confirming testing is allowed while DoS simulation remains banned.
Testing must be limited to non-production environments only.
Want more Supporting Compliance Requirements practice?
Practice this domainThe PCSE exam has 60 questions and must be completed in 120 minutes. The passing score is 720/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 5 domains: Configuring Access Within a Cloud Solution Environment, Ensuring Data Protection, Managing Operations in a Cloud Solution Environment, Configuring Network Security, Supporting Compliance Requirements. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Google Cloud PCSE exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.