GCDL · domain
Google Cloud Security
The Google Cloud Security domain covers how identity, network controls, encryption, and audit visibility protect resources on Google Cloud. Questions present a concrete scenario and ask you to pick the correct service or IAM component, so you must distinguish IAM roles and policies, VPC Service Controls, Cloud EKM, and Access Transparency by their actual function.
Focused practice
Practice Google Cloud Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Google Cloud Security
Match each scenario to the right control: VPC Service Controls for API perimeters, IAM roles and policies for permissions, Access Transparency for Google personnel access, and Cloud KMS or CMEK for encryption at rest. The key skill is separating network, identity, audit, and encryption controls.
Choosing VPC Service Controls to create a service perimeter around Cloud Storage and other APIs
Identifying IAM roles and allow policies as the components that grant permitted actions on resources
Selecting Access Transparency logs to see when Google personnel access customer data and why
Recognizing default encryption at rest with Google-managed or CMEK keys via Cloud KMS
Watch out for
Common Google Cloud Security exam traps
- ▸Confusing VPC firewall rules or Private Google Access with VPC Service Controls, which actually restrict API access to a perimeter rather than just network paths.
- ▸Assuming IAM permissions and roles are the same thing; roles are collections of permissions, and the allow policy binds principals to roles.
- ▸Mixing up Access Transparency, which logs Google personnel access, with Cloud Audit Logs, which record actions by users and services in your project.
Question index
All Google Cloud Security questions (68)
Click any question to see the full explanation, or start a practice session above.
A company has a VPC with multiple subnets and wants to prevent data exfiltration by restricting access to a Cloud Storage bucket from only resources within a defined perimeter. Which Google Cloud service should they use to create an API perimeter around the bucket?
Hard2A security team needs to detect and respond to threats in real time using network traffic analysis and log correlation. Which THREE services should they use? (Choose 3)
Hard3A developer needs to store a database password securely and access it from a Compute Engine VM. The password should be automatically rotated every 90 days. Which Google Cloud service should they use?
Easy4A company wants to protect its web application from common web exploits like SQL injection and cross-site scripting. They also need to block traffic from known malicious IP addresses. Which Google Cloud service should they use?
Medium5A security engineer needs to ensure that a Compute Engine instance can access a Cloud Storage bucket using its own identity, without embedding service account keys in the instance. What should the engineer do?
Hard6An organization needs to ensure that data stored in Cloud Storage is encrypted using keys that they manage and rotate themselves. Which encryption option should they choose?
Easy7A security team wants to find misconfigurations and vulnerabilities across their Google Cloud environment, including VMs, storage, and IAM. Which service provides a unified view of these findings?
Medium8A company wants to implement a zero-trust access model for its internal applications, eliminating the need for a traditional VPN. Employees should be allowed access based on device posture and user identity, not just network location. Which Google Cloud solution should be used?
Medium9A security analyst needs to analyze large volumes of security logs from multiple GCP projects, detect anomalies, and investigate incidents. The solution should support advanced analytics and threat hunting. Which service is best suited?
Medium10A data engineering team needs to store and manage database passwords and API keys used by their applications. Which Google Cloud service should they use?
Medium11A startup wants to secure access to its internal web applications without using a VPN. They need to enforce access based on user identity and device security posture. Which Google Cloud service should they use?
Easy12A security engineer needs to monitor and analyze security logs from multiple GCP projects and on-premises sources in a centralized SIEM. Which Google Cloud service is designed for log management and security analytics at scale?
Medium13A company wants to protect its web application running on Google Cloud from DDoS attacks and SQL injection. Which service should they use?
Medium14A company wants to replace its VPN-based remote access with a solution that grants access to internal web applications based on user identity and device context, without requiring a VPN. Which Google Cloud service should they use?
Medium15A company wants to implement a zero-trust security model for accessing internal applications. Which TWO Google Cloud services should they use together? (Choose 2)
Medium16A developer needs to allow a Compute Engine VM to read from a specific Cloud Storage bucket. Which IAM role should be granted to the VM's service account?
Easy17A company wants to protect its web application deployed on Google Cloud from OWASP Top 10 attacks and also block traffic from specific geographic regions. Which TWO services should they use together? (Choose 2)
Medium18A developer needs to store and manage API keys and certificates in a secure, centralized manner, with automatic rotation and integration with Cloud Functions. Which Google Cloud service should they use?
Medium19Which TWO statements about encryption in transit in Google Cloud are correct? (Choose 2)
Medium20A security team wants to detect and respond to threats across multiple GCP projects, including identifying misconfigurations and vulnerabilities. They need a single pane of glass. Which service provides a unified view of security findings across projects?
Hard21An organization needs to enforce that developers can only create Compute Engine instances in the us-central1 region. Which IAM approach should they use?
Medium22A security team needs to detect and alert on suspicious outbound network traffic from their GCP environment, such as data exfiltration attempts. They require a managed service that analyzes traffic for threats. Which service should they use?
Medium23Which IAM component determines what actions a user is allowed to perform on a resource?
Easy24A company must meet regulatory requirements that restrict where data can be stored and processed. They need to ensure that Google Cloud personnel have limited and audited access to their data. Which combination of services should they use?
Hard25An organization needs to store API keys, database passwords, and certificates securely, with automatic rotation and audit logging. Which Google Cloud service should they use?
Easy26An organization wants to ensure that all data stored in Cloud Storage is encrypted with customer-managed keys that can be rotated on demand. They also need to log every key use for audit compliance. Which combination of services should they use?
Medium27A healthcare company runs a containerized patient-records application on Google Kubernetes Engine. The security team wants to detect and block suspicious network traffic between pods, and also wants to scan container images for known vulnerabilities before deployment. Which combination of Google Cloud services should they use to meet these requirements?
Medium28A company wants to encrypt sensitive data stored in Cloud Storage with a key that is generated and stored on-premises using a hardware security module (HSM). They do not want Google to have access to the key. Which encryption option should they use?
Medium29A company wants to implement a zero-trust security model to replace its legacy VPN for accessing internal web applications. Employees use both company-managed and personal devices. Which Google Cloud service provides context-aware access based on user identity and device posture?
Medium30An organization wants to protect its web application from DDoS attacks and SQL injection. Which Google Cloud service should they deploy?
Medium31A security team needs to monitor and analyze logs from multiple GCP projects to detect threats across the organization. They require a SIEM solution that can ingest logs from on-premises and other clouds. Which service should they use?
Hard32A company uses Cloud SQL and wants to encrypt data at rest with a key that they manage and rotate themselves. They also want to ensure that the encryption happens automatically before data is written to disk. Which configuration should they choose?
Medium33A DevOps engineer wants to audit all actions performed by Google personnel on their customer data stored in Cloud Storage. They need to review logs that show access by Google employees and the reason for access. Which logging feature should they enable?
Hard34A company wants to replace its VPN-based remote access with a solution that grants access based on user identity, device security status, and context (e.g., location, IP). Which Google Cloud service should they use?
Easy35A security engineer needs to analyze network traffic for malicious payloads and anomalies in real-time across multiple VPC networks in a project. The solution must be managed and not require deploying third-party appliances. Which service should they use?
Hard36An administrator wants to enforce that all API calls to a specific Cloud Storage bucket must come from a limited range of IP addresses. Which configuration should they use?
Hard37A company wants to protect sensitive data stored in Cloud Storage from being downloaded by users outside their organization. They also need to prevent data from being copied to external projects. Which TWO services should they use? (Choose two.)
Medium38Which defense-in-depth layer includes measures like access controls, vulnerability management, and intrusion detection systems?
Easy39What is the primary purpose of VPC Service Controls?
Easy40A security administrator needs to ensure that Google personnel do not access customer data without explicit authorization. Which service should they use to get logs of Google employee access?
Hard41A small startup wants to protect its web application from common attacks like SQL injection and cross-site scripting (XSS). They also need DDoS protection. Which Google Cloud security service should they use?
Easy42A security team needs to implement a zero-trust architecture for a web application that is accessed by both internal employees and external partners. They require context-aware access that checks device posture and identity. Which THREE components should they use? (Choose three.)
Hard43Which Google Cloud service provides a fully managed SIEM solution for log analysis, threat detection, and incident response?
Easy44Which Google Cloud security layer is responsible for protecting data stored on disk using either Google-managed or customer-managed encryption keys?
Easy45An organization wants to enforce that all data stored in Cloud Storage buckets is encrypted with a key that they control and rotate periodically. They also need to audit key usage. Which approach should they take?
Medium46A large enterprise wants to enforce the principle of least privilege for its cloud resources. The security team needs to audit all IAM policy changes across the organization and ensure that custom roles are used where predefined roles are too permissive. Which three Google Cloud services or features should be combined to achieve this? (Choose three.)
Hard47A company wants to scan its Cloud Storage buckets for sensitive data like credit card numbers and social security numbers. Which service should they use?
Medium48A company wants to store encryption keys for encrypting data at rest in Cloud Storage, and also needs to automatically rotate the keys every 30 days. Additionally, they require an audit log of key usage. Which TWO services should they use? (Choose two.)
Medium49A company uses Cloud Storage to store sensitive data. They want to enforce that all objects uploaded are encrypted with a customer-managed key that they can rotate and control. What should they configure?
Medium50An organization needs to ensure that data stored in Cloud Storage is encrypted at rest using keys that are rotated every 30 days. They also need to audit who accesses the keys and when. Which THREE services should they use? (Choose 3)
Hard51A company wants to ensure that only API calls from within a specific VPC can access their Cloud Storage buckets, even if the bucket is public. Which Google Cloud feature should they use?
Medium52A company has a requirement to rotate encryption keys every 90 days. They are using Cloud KMS to manage keys for Cloud Storage. What is the correct way to achieve key rotation with minimal impact to existing encrypted objects?
Hard53A company needs to audit all actions performed by administrators on their Google Cloud project, including who accessed what resource and when. Which logging feature should they enable?
Easy54An organization wants to detect and respond to threats across their GCP environment, including finding misconfigurations, vulnerabilities, and potential malicious activity. Which service provides a unified view of security findings?
Medium55Which Google Cloud service provides threat intelligence and incident response capabilities, including access to Mandiant expertise?
Easy56A company wants to detect and prioritize vulnerabilities in their Compute Engine VMs and GKE clusters. They also need a centralized view of security findings across their organization. Which service should they use?
Medium57Which layer of Google's defence-in-depth security model includes the use of TLS for data in transit?
Easy58A security team needs to detect and respond to threats across their Google Cloud environment. Which THREE services should they use together? (Choose 3)
Medium59A company wants to enforce the principle of least privilege by granting a service account only the permissions necessary to publish messages to a specific Pub/Sub topic. Which IAM approach should they use?
Easy60An engineer needs to store database passwords and API keys securely. The secrets must be encrypted at rest with a customer-managed key and automatically rotated every 90 days. Which service should they use?
Medium61An organization needs to protect a web application hosted on Google Cloud from DDoS attacks and SQL injection attempts. They want a managed security service that integrates with Cloud Load Balancing. Which service should they use?
Medium62Which principle states that a user should be granted only the permissions necessary to perform their job functions?
Easy63A security team wants to be alerted when Google Cloud personnel access their customer data. They need logs that show the reason for access and what data was accessed. Which service provides this?
Hard64A company wants to replace its VPN-based remote access with a zero-trust solution that verifies user identity and device health before granting access to internal applications. Which Google Cloud service should they use?
Medium65A small startup is migrating its web application to Google Cloud. The security lead wants to understand how Google protects the underlying infrastructure, including physical data centers, hardware, and the network, while the startup remains responsible for securing its own application code and data. Which security model describes this division of responsibilities?
Easy66A company wants to ensure that its Google Cloud resources can only be accessed from within a specific VPC network, preventing data exfiltration to the internet. They need to enforce this for Cloud Storage and BigQuery APIs. Which service should they use?
Hard67An organization has a compliance requirement to run workloads in specific geographic regions only. They want to prevent any resources from being created outside those regions. Which Google Cloud control should they use?
Hard68Which Google Cloud service helps identify and classify sensitive data such as credit card numbers or personal health information in Cloud Storage and BigQuery?
EasyOther domains
All GCDL exam domains
Frequently asked questions
- What does the Google Cloud Security domain cover on the GCDL exam?
- Match each scenario to the right control: VPC Service Controls for API perimeters, IAM roles and policies for permissions, Access Transparency for Google personnel access, and Cloud KMS or CMEK for encryption at rest. The key skill is separating network, identity, audit, and encryption controls.
- How many questions are in this domain?
- This page lists all 68 Google Cloud Security questions in the GCDL question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Google Cloud Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.