PCA · domain
Designing for Security and Compliance
This domain covers how to design identity, access, network, and data protection on Google Cloud. Questions present a scenario and ask which IAM role, service account, firewall rule, or security service satisfies least-privilege and compliance requirements. Expect to choose between Cloud IAM, IAP, Cloud Armor, VPC Service Controls, Cloud KMS, and Secret Manager, and to reason about service accounts versus user credentials.
Focused practice
Practice Designing for Security and Compliance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Designing for Security and Compliance
Be able to choose the right Google Cloud security control for a scenario and grant least-privilege access. The single most important thing is knowing that IAP requires both enabling the IAP service and granting the IAP-secured Web App User role to users, while service accounts should be attached to instances for API access.
Granting least-privilege IAM roles, including predefined roles like roles/iap.httpsResourceAccessor for Identity-Aware Proxy.
Attaching and using service accounts so Compute Engine instances can call Google Cloud APIs securely.
Configuring Cloud Armor security policies with reCAPTCHA Enterprise and Google Cloud Armor bot management rules.
Using Secret Manager for secret storage, versioning, automatic rotation, and integration with Cloud Functions.
Watch out for
Common Designing for Security and Compliance exam traps
- ▸Assuming IAP alone grants access; you must also grant the IAP-secured Web App User role to each user or group.
- ▸Attaching a service account to an instance after creation without stopping it, or granting broad scopes instead of narrow IAM roles.
- ▸Confusing Cloud Armor with Cloud IAP: Cloud Armor filters at the edge, while IAP authenticates and authorizes users.
Question index
All Designing for Security and Compliance questions (79)
Click any question to see the full explanation, or start a practice session above.
A security team needs to detect and redact personally identifiable information (PII) in documents stored in Cloud Storage before sharing them with external partners. Which two Google Cloud services should they use together? (Choose two.)
Medium2A security team wants to prevent data exfiltration from a GKE cluster to external storage. They need to restrict access to Cloud Storage buckets from the cluster without using private IPs. Which solution should they implement?
Medium3A developer wants to store a database password that is used by a Cloud Function. The password must be automatically rotated every 30 days and accessed securely without storing it in the source code. Which GCP service should they use?
Easy4An engineer needs to grant a user the ability to create and manage service accounts in a project. Which predefined IAM role provides these permissions?
Easy5An organization uses Active Directory (AD) on-premises and wants to synchronize user identities to Google Cloud Identity so that users can access G Suite and GCP resources with their existing credentials. Which service should they use?
Medium6Which two GCP audit log types are available by default? (Choose TWO).
Easy7A company deploys a Kubernetes workload in GKE that needs to access Cloud Storage. They want to avoid managing service account keys. What is the recommended approach?
Hard8An organization wants to enforce that all container images deployed to Google Kubernetes Engine (GKE) clusters are signed by an authorized authority and only those images are allowed to run. Which GCP service should they use?
Easy9A developer needs to securely store a database password that will be used by a Compute Engine instance. The password must be rotated automatically every 30 days. Which service should they use?
Medium10An organization wants to enforce that all container images deployed to Google Kubernetes Engine (GKE) are signed and approved via an attestation authority. Which GCP service should they use?
Easy11An organization uses Active Directory (AD) on-premises. They want to synchronize user accounts and groups to Google Cloud Identity so that users can sign in with their existing AD credentials. Which service should they use?
Medium12A company wants to give a new employee read-only access to all projects in their GCP organization. Which IAM role should they assign at the organization level to grant this access?
Easy13A company wants to use Binary Authorization to enforce that only images signed by their internal CI/CD pipeline can be deployed to their GKE clusters. They have set up Cloud Build to sign images. Which THREE steps are required to configure this? (Choose 3)
Hard14An organization wants to enforce that all container images deployed to their Google Kubernetes Engine (GKE) clusters are signed and have passed a vulnerability scan. Which GCP service should they use to enforce this policy?
Easy15A developer wants to allow a Compute Engine VM to authenticate to Google Cloud APIs without embedding service account keys in the VM image. What is the recommended approach?
Easy16A financial services firm stores sensitive customer transaction data in Cloud Storage buckets. The security team wants to ensure that the data is encrypted at rest with a key that the firm controls, and that the key is automatically rotated every 90 days. They also need to be able to revoke access to the data immediately by disabling the key. Which Google Cloud service and configuration should they use?
Medium17A company wants to allow users to authenticate to a web application running on Compute Engine using their existing corporate Active Directory credentials without exposing the application to the public internet. Which approach should they use?
Medium18A startup wants to grant a contractor limited access to a single Cloud Storage bucket. The contractor should be able to view and download objects, but not delete or overwrite them. Which IAM role should be assigned?
Easy19A security engineer wants to prevent data exfiltration from a project 'prod-data' by ensuring that only approved VPC networks can access BigQuery datasets. Which GCP service should be used?
Medium20Which GCP service can be used to detect and redact sensitive data such as credit card numbers in text files stored in Cloud Storage?
Easy21A company is migrating its on-premises data warehouse to BigQuery. The security team requires that all data at rest in BigQuery is encrypted with keys that the company controls, and that key usage is logged for auditing. They also need to be able to revoke access to the data by disabling the key. Which configuration should they implement?
Medium22A company needs to encrypt data at rest in Cloud Storage using their own keys. They require that the keys are stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 certified. Which key management option should they choose?
Medium23A security engineer needs to restrict access to a Google Cloud project so that only a specific set of IP addresses can reach Cloud Storage buckets. Which feature should be configured?
Easy24A company wants to allow a Kubernetes pod in GKE to authenticate to Google Cloud APIs without storing service account keys in the cluster. Which three components need to be configured to enable Workload Identity? (Choose three.)
Hard25An organization wants to protect an HTTPS load-balanced web application from common web attacks, such as SQL injection and cross-site scripting (XSS), as well as rate-limit traffic from specific IPs. Which three capabilities should they use together? (Choose three.)
Medium26An organization needs to store API keys and database passwords securely in Google Cloud. They want to automatically rotate secrets every 30 days. Which service should they use?
Medium27An organization needs to encrypt data at rest in BigQuery using keys that are rotated every 90 days. They want to manage the keys themselves but cannot store keys on-premises. Which encryption approach should they use?
Hard28A company wants to allow a Kubernetes pod in GKE to access a Cloud Storage bucket using a specific service account without storing long-lived credentials. Which method should be used?
Medium29A company wants to deploy a web application behind an HTTPS Load Balancer and only allow authenticated users from their corporate Active Directory. Which two services should they use together? (Choose two.)
Medium30A company wants to centrally manage firewall rules for all projects in an organization using hierarchical firewall policies. Which three resources can be used in conjunction with hierarchical firewall policies? (Choose three.)
Hard31A company uses Cloud Armor to protect an HTTPS Load Balancer. They want to allow traffic only from users who have passed a reCAPTCHA challenge. Cloud Armor supports which feature for this?
Hard32An organization wants to ensure that only container images signed by an authorized CI/CD pipeline can be deployed to their GKE clusters. Which GCP service should they use?
Easy33A company wants to restrict network access to Cloud SQL instances such that only applications running in a specific VPC can connect. Which GCP feature should they use?
Medium34A company needs to ensure that only applications running in a specific GKE namespace can access a Cloud Storage bucket. Which approach should they use?
Medium35A financial services company must store customer data in a GCP region that is certified for FedRAMP High. They also need to ensure that only authorized personnel can access the data, and that access logs are kept for 10 years. Which combination of services meets these requirements?
Hard36A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that pods can only pull container images from a private Artifact Registry repository and that images are scanned for vulnerabilities before deployment. They also want to prevent pods from being scheduled if they use images from public registries. What should they do?
Medium37A company has a VPC Service Perimeter that protects a project containing BigQuery datasets. They want to allow an external customer's BigQuery job to query data across the perimeter boundary using a private connection. Which configuration is required?
Hard38A developer wants to store a database password securely and have it automatically rotated every 30 days. The password is used by a Compute Engine instance. Which Google Cloud service should they use?
Medium39An organization wants to use VPC Service Controls to protect a Cloud Storage bucket and a BigQuery dataset from data exfiltration. They want to allow access from a specific on-premises network via a Cloud VPN. Which TWO components are required? (Choose 2)
Medium40A data engineer needs to automatically detect and redact sensitive data such as credit card numbers from text files uploaded to Cloud Storage before the data is loaded into BigQuery. Which GCP service should be used?
Hard41A security team needs to detect and redact personally identifiable information (PII) from documents uploaded to Cloud Storage before they are stored. Which GCP service should they use?
Medium42A financial services company runs a regulated workload on Compute Engine in a single project. Auditors require that all data written to persistent disks, including boot disks, is encrypted with keys the company controls and can revoke on demand, without the company operating its own key management infrastructure. The security lead must choose an encryption approach that satisfies this requirement with the least operational overhead. What should the security lead do?
Medium43Which IAM role should be granted to a user who needs to view but not modify resources in a project?
Easy44A data engineer needs to scan a Cloud Storage bucket for personally identifiable information (PII) and de-identify the data before loading it into BigQuery. Which Google Cloud service should they use?
Medium45A DevOps engineer needs to grant a CI/CD pipeline (running in a different Google Cloud project) the ability to deploy resources into a target project. The pipeline uses a service account. What is the best way to grant this access?
Medium46A company wants to encrypt data at rest in Cloud Storage using a key that they generate and manage themselves, not stored in Google Cloud. Which encryption type should they use?
Medium47A company uses Assured Workloads to meet FedRAMP compliance. They need to ensure that only authorized personnel can access data access audit logs for their projects. Which IAM role should they grant to the security team?
Hard48A company wants to enforce that all API calls to GCP services from outside their corporate network come through a specific Cloud VPN tunnel. Which GCP service can enforce this policy?
Medium49A multinational corporation needs to ensure that data stored in Cloud Storage buckets in their Google Cloud organization cannot be accessed from outside their corporate network, even if IAM policies are misconfigured. They want to enforce this at the organization level with minimal administrative overhead. What should they do?
Hard50A healthcare company runs a multi-tenant SaaS platform on Google Cloud. Each tenant has a dedicated folder inside a single organization, with projects for each environment. A recent audit found that a compromised service account in one tenant's dev project could enumerate and read Cloud Storage buckets belonging to other tenants because the service account had been granted roles/storage.admin at the organization level by mistake. The security team wants a preventive control that blocks any future IAM binding that grants a role to a principal at a scope broader than a single project, unless the principal is part of a small break-glass group. They also want the control to apply automatically to all new projects. What should the architect implement?
Hard51A healthcare organization is designing a Google Cloud environment to comply with HIPAA. They need to ensure that all access to sensitive data is logged and that only authorized personnel can access it. They plan to use Cloud Audit Logs and IAM. Which two configurations should they implement? (Choose two.)
Hard52A company wants to use Customer-Managed Encryption Keys (CMEK) for data at rest in Cloud Storage, but also needs to ensure that the keys are stored in a hardware security module (HSM) to meet compliance requirements. Which Cloud KMS key type should they choose?
Medium53A company with multiple projects must ensure that no data can be exfiltrated from a specific project's Cloud Storage buckets to unauthorized locations outside the organization. They also need to allow access only from a corporate VPN IP range. Which configuration meets these requirements?
Hard54A company wants to protect their web application hosted on Google Cloud HTTP(S) Load Balancer from common web attacks like SQL injection and cross-site scripting (XSS). Which GCP service should they use?
Easy55A company wants to use their existing Active Directory for authentication to Google Cloud. They need to sync user and group identities to Cloud Identity and allow users to log in with their corporate credentials. Which two services should they use together?
Medium56A security engineer wants to configure Identity-Aware Proxy (IAP) for an HTTPS load-balanced application to enforce zero-trust access. Users will authenticate with their Google accounts. What is the minimum set of IAM roles needed for a user to access the application behind IAP?
Medium57A healthcare company stores sensitive patient data in Cloud Storage. They must ensure that data is encrypted at rest with a key that they manage, and that the key is automatically rotated every 90 days. They also need to be able to audit key usage. Which approach should they take?
Medium58A company is deploying a multi-tenant SaaS application on GKE. Each tenant's data must be isolated at the network level. They want to use a single GKE cluster but ensure that pods from different tenants cannot communicate with each other. Which GCP feature should they use?
Hard59A company uses Cloud KMS with CMEK to encrypt data stored in BigQuery. They need to audit who has used the encryption key and when. Which type of audit log should they enable?
Hard60A company runs a public-facing web application on Compute Engine instances behind an external HTTP(S) load balancer. They want to protect the application from common web attacks such as SQL injection and cross-site scripting, and they also want to restrict access to known IP ranges. Which Google Cloud service should they use?
Medium61A company wants to implement a zero-trust access model for internal web applications running on Compute Engine. They need to authenticate users using corporate credentials and enforce context-aware access based on device posture and IP address. Which TWO services should they use?
Medium62An organization needs to comply with FedRAMP requirements and restrict data storage to specific regions. They also need to audit all admin activities and data access. Which three components should they implement? (Choose three.)
Hard63A healthcare company stores protected health information in Cloud Storage and BigQuery. Compliance requires that access to this data be auditable and that no single administrator can both modify data and erase the audit trail. The security architect is designing the logging and access model. Which two actions should the architect take? (Choose two.)
Medium64A company wants to enforce that all secrets used by applications running on Compute Engine are rotated automatically every 30 days. Which GCP service should they use to store and manage these secrets?
Medium65A startup runs a public API on Compute Engine behind an external HTTP(S) load balancer. The security team wants to block common web attacks such as SQL injection and cross-site scripting at the edge, with minimal changes to the application, and they want the protection rules to be managed centrally and updated as new signatures are released. What should the architect recommend?
Easy66Which Google Cloud service allows organizations to define perimeters that protect resources and data from exfiltration to other VPCs or networks?
Easy67A security admin wants to audit all 'create' and 'delete' operations on Compute Engine instances in a project for the last 90 days. Which type of audit log should they query?
Medium68A company needs to protect an HTTPS load-balanced web application from OWASP Top 10 attacks, including SQL injection and cross-site scripting. Which GCP service should they enable?
Medium69A financial services company runs workloads on GKE and wants to ensure only container images that have been approved by the security team can be deployed. The approval process involves signing images after vulnerability scanning. Which GCP service should be integrated with GKE to enforce this policy?
Hard70A financial services company stores regulated data in BigQuery datasets. Auditors require that all data access be logged with the identity of the user, the query text, and the timestamp, and that logs be retained for 365 days and be immutable. The security team wants to use Google Cloud-native tools with minimal operational overhead. What should they implement?
Hard71A multinational corporation needs to comply with data residency requirements for EU customer data. They want to ensure that data stored in Cloud Storage, BigQuery, and Cloud SQL for EU customers never leaves the European Union, even by administrators. They also want to detect and remediate any configuration drift that could violate this policy. What should they implement?
Hard72An organization requires that all container images deployed to GKE be signed and verified before deployment. Which GCP service should be used?
Medium73A company wants to control which resources can be accessed by a service account in a specific project. Which IAM policy binding approach should be used?
Easy74A developer needs to grant a Compute Engine instance the ability to read from a Cloud Storage bucket. The instance does not have a service account attached. What should the developer do?
Easy75Your company is designing a secure architecture for a new application on Google Cloud. They need to ensure that service accounts used by the application have only the necessary permissions, and that any use of those service accounts is auditable. Which two actions should they take? (Choose two.)
Hard76An organization runs workloads in multiple Google Cloud projects and wants a single, consistent way to detect and respond to threats such as compromised service accounts and anomalous API calls across all of them. The security operations team needs findings aggregated in one place and wants to reduce the effort of correlating events from Cloud Audit Logs, VPC Flow Logs, and Cloud DNS logs. Which Google Cloud service should the architect recommend?
Hard77A security engineer wants to ensure that all admin activity in their GCP organization is logged and retained for 3 years. They also need to be alerted if a new firewall rule is created. Which logs should they enable?
Medium78A company needs to ensure that only approved container images can be deployed to a GKE cluster. They already use Binary Authorization. What additional step is required to enforce this policy?
Medium79An organization needs to store secrets used by multiple GCP services. They require automatic rotation of secrets every 30 days and integration with Cloud Functions. Which service should they use?
HardOther domains
All PCA exam domains
Frequently asked questions
- What does the Designing for Security and Compliance domain cover on the PCA exam?
- Be able to choose the right Google Cloud security control for a scenario and grant least-privilege access. The single most important thing is knowing that IAP requires both enabling the IAP service and granting the IAP-secured Web App User role to users, while service accounts should be attached to instances for API access.
- How many questions are in this domain?
- This page lists all 79 Designing for Security and Compliance questions in the PCA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Designing for Security and Compliance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.