Courseiva

GCDL · topic practice

Google Cloud Security practice questions

The Google Cloud Security domain covers how identity, network controls, encryption, and audit visibility protect resources on Google Cloud. Questions present a concrete scenario and ask you to pick the correct service or IAM component, so you must distinguish IAM roles and policies, VPC Service Controls, Cloud EKM, and Access Transparency by their actual function.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Google Cloud Security

What the exam tests

What to know about Google Cloud Security

Match each scenario to the right control: VPC Service Controls for API perimeters, IAM roles and policies for permissions, Access Transparency for Google personnel access, and Cloud KMS or CMEK for encryption at rest. The key skill is separating network, identity, audit, and encryption controls.

Choosing VPC Service Controls to create a service perimeter around Cloud Storage and other APIs

Identifying IAM roles and allow policies as the components that grant permitted actions on resources

Selecting Access Transparency logs to see when Google personnel access customer data and why

Recognizing default encryption at rest with Google-managed or CMEK keys via Cloud KMS

Watch out for

Common Google Cloud Security exam traps

  • ▸Confusing VPC firewall rules or Private Google Access with VPC Service Controls, which actually restrict API access to a perimeter rather than just network paths.
  • ▸Assuming IAM permissions and roles are the same thing; roles are collections of permissions, and the allow policy binds principals to roles.
  • ▸Mixing up Access Transparency, which logs Google personnel access, with Cloud Audit Logs, which record actions by users and services in your project.

Practice set

Google Cloud Security questions

20 questions · select your answer, then reveal the explanation

A security team needs to detect and respond to threats across their cloud environment. Which THREE services should they use together? (Choose 3)

A company needs to encrypt data at rest using keys that they manage, but they want to reduce operational overhead by having Google Cloud host the key management infrastructure. Which TWO options achieve this? (Choose 2)

A security engineer needs to create a VPC Service Controls perimeter that prevents data exfiltration from a project containing sensitive data. The perimeter should allow BigQuery datasets in the project to be accessed only from authorized VMs within the same perimeter. Which step is essential?

A DevOps engineer needs to grant a CI/CD pipeline (running on Compute Engine) permissions to deploy a Cloud Run service. The pipeline uses a service account. What is the correct approach to assign the necessary IAM role to the service account?

A company wants to ensure data encryption at rest using customer-managed keys for Cloud SQL and Cloud Storage. Which TWO actions must they take? (Choose 2)

An engineer needs to prevent data exfiltration from a project by ensuring that Cloud Storage buckets can only be accessed from within a VPC network. Which TWO steps should they take? (Choose 2)

A security team needs to implement the principle of least privilege for a group of data scientists who only need to query BigQuery datasets, but not modify or delete them. Which THREE IAM roles should be granted? (Choose 3)

Which IAM concept defines what actions a user can perform on a resource?

Question 9mediummultiple choice
Read the full Cloud Security explanation →

A company uses Cloud KMS to manage encryption keys. They want to rotate keys automatically every 90 days. How can they achieve this?

Which TWO services help protect against data exfiltration in Google Cloud? (Choose 2)

A company wants to implement the principle of least privilege for a team of developers who need to deploy applications on Compute Engine and monitor logs. Which THREE IAM roles should be granted? (Choose 3)

Question 12easymultiple choice
Read the full Cloud Security explanation →

A security engineer wants to ensure that Google personnel access to customer data stored in Cloud Storage is visible and auditable. Which Google Cloud feature should be enabled?

A financial services company needs to restrict access to its Cloud Storage buckets containing sensitive customer data. The company wants to prevent data exfiltration by ensuring that only authorized VMs in specific VPCs can access the buckets, and that data cannot be copied to unauthorized locations. Which two Google Cloud services should be used together? (Choose two.)

Question 14mediummultiple choice
Read the full VPN explanation →

A company wants to replace its VPN-based remote access with a zero-trust solution that verifies user identity and device health before granting access to internal applications. Which Google Cloud service should they use?

Question 15easymultiple choice
Read the full Cloud Security explanation →

An organization needs to ensure that data stored in Cloud Storage is encrypted using keys that they manage and rotate themselves. Which encryption option should they choose?

Question 16hardmultiple choice
Read the full Cloud Security explanation →

A security team needs to monitor and analyze logs from multiple GCP projects to detect threats across the organization. They require a SIEM solution that can ingest logs from on-premises and other clouds. Which service should they use?

Question 17mediummultiple choice
Read the full Cloud Security explanation →

A company wants to protect its web application running on Google Cloud from DDoS attacks and SQL injection. Which service should they use?

Question 18mediummultiple choice
Read the full Cloud Security explanation →

A data engineering team needs to store and manage database passwords and API keys used by their applications. Which Google Cloud service should they use?

Question 19easymultiple choice
Read the full Cloud Security explanation →

What is the primary purpose of VPC Service Controls?

Question 20hardmultiple choice
Read the full Cloud Security explanation →

A security administrator needs to ensure that Google personnel do not access customer data without explicit authorization. Which service should they use to get logs of Google employee access?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Google Cloud Security sessions

Start a Google Cloud Security only practice session

Every question in these sessions is drawn from the Google Cloud Security domain — nothing else.

Related practice questions

Related GCDL topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCDL exam test about Google Cloud Security?
Match each scenario to the right control: VPC Service Controls for API perimeters, IAM roles and policies for permissions, Access Transparency for Google personnel access, and Cloud KMS or CMEK for encryption at rest. The key skill is separating network, identity, audit, and encryption controls.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Google Cloud Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Google Cloud Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCDL topics?
Use the topic links above to move to related areas, or go back to the GCDL question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCDL exam covers. They are not copied from any real exam or dump site.