Courseiva

GCDL · topic practice

Trust and security with Google Cloud practice questions

This domain covers Google Cloud's shared responsibility model, IAM, encryption, and compliance tooling, and accounts for roughly 12% of the Cloud Digital Leader exam. Questions are scenario-based: you choose the right Google Cloud security control, identity mechanism, or governance tool for a stated business or regulatory need, rather than configuring products hands-on.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Trust and security with Google Cloud

What the exam tests

What to know about Trust and security with Google Cloud

Match scenarios to Google Cloud controls: Cloud IAM roles and policies, VPC Service Controls, Cloud KMS and CMEK, Security Command Center, and Compliance Reports Manager. Get the shared responsibility split right: Google secures the infrastructure, you secure data, access, and configuration.

Applying the shared responsibility model to Google Cloud versus customer-controlled security duties

Choosing IAM roles, service accounts, and least-privilege policies for a given access scenario

Selecting encryption options: default Google-managed keys, CMEK via Cloud KMS, or CSEK

Identifying Security Command Center, Cloud Armor, and Cloud Audit Logs for monitoring and compliance

Watch out for

Common Trust and security with Google Cloud exam traps

  • ▸Assuming Google encrypts data at rest by default but believing the customer must still enable encryption manually, when default encryption is automatic.
  • ▸Confusing Cloud IAM, which controls Google Cloud resource access, with Cloud Identity, which manages users and authentication across Google services.
  • ▸Treating the shared responsibility model as fixed, when the customer's security duties shift depending on IaaS, PaaS, or SaaS service type.

Practice set

Trust and security with Google Cloud questions

20 questions · select your answer, then reveal the explanation

A security audit finds that a company's application service accounts have been granted broad IAM roles (e.g., Storage Admin on the entire project) when they only need to read specific Cloud Storage buckets. The auditor recommends following the principle of least privilege. What is the most precise way to implement this for the Cloud Storage use case?

A small IT team needs to grant developers the ability to deploy instances in a project but not delete them. Which IAM best practice should they use?

A financial services company needs to ensure that all access to sensitive data in Cloud Storage is logged with information about the user and the reason for access. Which feature should they enable?

Refer to the exhibit. A developer receives this error when trying to create a Compute Engine instance. The developer is authenticated as a user with Project Editor role. What is the most likely cause?

Exhibit

Refer to the exhibit.
```
Error:
# gcloud compute instances create my-instance --zone us-central1-a
ERROR: (gcloud.compute.instances.create) Could not fetch resource:
 - Account 'my-service-account@project-id.iam.gserviceaccount.com' requires permission 'compute.instances.create' on project 'my-project'
```

A company wants to grant a data analyst read-only access to specific BigQuery datasets, but only if the request comes from within the corporate network. Which two Google Cloud tools should they combine to enforce this?

Refer to the exhibit. The IAM policy is applied at the project level. The bucket 'sensitive-data' exists and contains objects. What is the effective access for user alice@example.com?

Exhibit

Refer to the exhibit.

{
  "bindings": [
    {
      "role": "roles/storage.objectViewer",
      "members": [
        "user:alice@example.com",
        "user:bob@example.com"
      ]
    },
    {
      "role": "roles/storage.objectAdmin",
      "members": [
        "user:carol@example.com"
      ],
      "condition": {
        "title": "restrict_to_sensitive_bucket",
        "expression": "resource.name.startsWith('projects/_/buckets/sensitive-data/objects/')"
      }
    }
  ],
  "etag": "BwW3ZJf4G7A="
}

A healthcare organization is migrating a HIPAA-covered application to Google Cloud. The application processes electronic protected health information (ePHI) and must maintain strict data residency within a specific geographic region. The organization has already signed a Business Associate Agreement (BAA) with Google Cloud. During a compliance review, the security team discovers that one of the Cloud Storage buckets containing ePHI is located in the 'US' multi-region, but the organization's data residency policy requires data to be stored only in the United States region (e.g., us-central1). The bucket was created without any enforcement of organization policies. The team also finds that several Compute Engine instances in the us-central1 zone have public IP addresses and are accessible over the internet via SSH, which could expose ePHI in transit. The security team needs to remediate these issues while minimizing downtime and without violating the BAA. Which course of action should the security team take first?

Google Cloud encrypts all customer data at rest by default without any configuration required. A customer asks: 'Do we need to do anything special to encrypt our data stored in Cloud Storage?' What is the correct answer?

A security architect wants to implement a 'never trust, always verify' security approach where no user or service is assumed to be trustworthy based on network location alone. Every access request must be authenticated and authorized regardless of whether it comes from inside or outside the corporate network. Which security model describes this approach?

A company is concerned about which security responsibilities belong to Google versus which belong to them when using Google Cloud's managed database service (Cloud SQL). In the shared responsibility model, which security tasks does Google handle?

A healthcare company needs to store patient data in Google Cloud and must comply with HIPAA (Health Insurance Portability and Accountability Act). Which statement correctly describes how Google Cloud helps them achieve HIPAA compliance?

An organization uses Google Cloud Identity and Access Management (IAM). A new employee is a data engineer who needs to read BigQuery datasets and run queries but should NOT be able to create new datasets, delete tables, or modify IAM policies. Which IAM role should be assigned?

A company wants to ensure that sensitive data (credit card numbers, SSNs) stored in BigQuery is automatically identified and protected. They also want ongoing scanning to detect if any new data violates their data governance policies. Which Google Cloud service provides these capabilities?

When data is transmitted between a user's browser and a Google Cloud-hosted web application over HTTPS, which security protection does this provide?

A company is evaluating Google Cloud and wants to know: what is Access Transparency, and how does it benefit customers with stringent governance requirements?

A company stores its data in Google Cloud. The security team asks: can Google employees access our customer data without our knowledge or consent? What does Google's commitment ensure?

A regulated financial services firm must ensure that its data never leaves a specific geographic region (EU) for compliance with GDPR data residency requirements. Which Google Cloud features help enforce this requirement?

What compliance certification verifies that an organization's Information Security Management System (ISMS) meets internationally recognized standards for managing information security risks?

A company uses Google Workspace for identity. They want employees to use their Google Workspace credentials to access third-party applications (Salesforce, Slack, etc.) without separate passwords for each app. Which technology enables this?

A company's security policy requires all employees to verify their identity using more than just a password when accessing Google Cloud resources. What security feature enforces this requirement?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Trust and security with Google Cloud sessions

Start a Trust and security with Google Cloud only practice session

Every question in these sessions is drawn from the Trust and security with Google Cloud domain — nothing else.

Related practice questions

Related GCDL topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCDL exam test about Trust and security with Google Cloud?
Match scenarios to Google Cloud controls: Cloud IAM roles and policies, VPC Service Controls, Cloud KMS and CMEK, Security Command Center, and Compliance Reports Manager. Get the shared responsibility split right: Google secures the infrastructure, you secure data, access, and configuration.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Trust and security with Google Cloud questions in a focused session?
Yes — the session launcher on this page draws every question from the Trust and security with Google Cloud domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCDL topics?
Use the topic links above to move to related areas, or go back to the GCDL question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCDL exam covers. They are not copied from any real exam or dump site.