Courseiva

PCA · domain

Design for security and compliance

This domain covers designing Google Cloud architectures that protect data and meet regulatory obligations. Expect questions on CMEK and Cloud KMS, VPC firewall rules and hierarchical policies, VPC Service Controls perimeters, IAM least privilege, and audit logging. Scenarios are framed around HIPAA, GDPR, or data residency, and you must pick the control that satisfies the stated requirement.

65 questions17 easy27 medium21 hard

Focused practice

Practice Design for security and compliance questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Design for security and compliance

Be able to select the right Google Cloud control for a stated compliance or security requirement: CMEK via Cloud KMS, VPC Service Controls, firewall rules, Cloud Armor, or audit logs. The most important thing is matching the control to the exact threat and regulatory obligation described.

Choosing Cloud KMS CMEK versus Google-managed or CSEK encryption for data at rest

Using VPC firewall rules, hierarchical firewall policies, and Cloud Armor to restrict traffic

Applying VPC Service Controls perimeters and ingress/egress rules to prevent data exfiltration

Reading Cloud Audit Logs to determine why a resource change such as a firewall rule failed

Watch out for

Common Design for security and compliance exam traps

  • ▸Assuming CMEK alone satisfies compliance; HIPAA and GDPR also require access controls, audit logging, and network restrictions.
  • ▸Confusing Cloud Armor, which filters HTTP(S) load balancer traffic, with VPC firewall rules that govern instance-level traffic.
  • ▸Forgetting that a denied API call appears in audit logs with the specific IAM or policy reason, not as a silent failure.

Question index

All Design for security and compliance questions (65)

Click any question to see the full explanation, or start a practice session above.

1

A healthcare organization stores Protected Health Information (PHI) in Cloud SQL. They have implemented encryption at rest using CMEK and enforce TLS for all connections. To meet HIPAA compliance, they need to ensure that PHI cannot be exfiltrated from the Cloud SQL instance even if an application is compromised. The Cloud SQL instance is accessed by Compute Engine instances in the same VPC using private IPs. The security team wants to add an additional layer of defense against data exfiltration. What should they do?

Hard
2

The firewall rule 'allow-ssh' was not created. According to the audit log, what is the most likely reason?

Hard
3

A financial services company runs a multi-tier application on Compute Engine. They need to restrict network access so that only the web tier can communicate with the application tier, and only the application tier can access the database tier. All VMs are in the same VPC network. What is the most secure way to implement this?

Medium
4

A financial services firm runs a regulated workload on Compute Engine. Auditors require that all data at rest on persistent disks be encrypted with keys the firm controls and can revoke, and that key usage be logged independently of the project's Cloud Audit Logs. The firm's security policy forbids storing key material in the same project as the workload. Which approach meets these requirements?

Hard
5

A healthcare company stores patient records in Cloud Storage and BigQuery. Auditors require that cryptographic keys used to protect this data are generated and stored on hardware security modules, that key material never leaves Google's infrastructure, and that the company retains the ability to control key rotation and revocation. The security team wants the least operational overhead while meeting these requirements. Which key management approach should the architect select?

Medium
6

After executing the command, a security review reveals that the service account sa-bucket-reader can also list buckets in the project, which was not intended. What is the most likely cause?

Easy
7

A software company wants to give a third-party analytics vendor read access to a specific BigQuery dataset containing aggregated, non-sensitive sales data, without creating service account keys that the vendor must store and rotate. The security team also wants to be able to revoke access quickly and to see which vendor identities accessed the data. The vendor already uses its own identity provider that supports OpenID Connect. Which TWO approaches together meet these requirements? (Choose two.)

Hard
8

A company stores sensitive customer data in Cloud Storage buckets. They want to ensure that access to these buckets is only allowed from within their VPC network. Which configuration should they use?

Medium
9

A healthcare organization uses Cloud Storage to store protected health information (PHI). They have a compliance requirement to ensure that all objects in the bucket are encrypted with a customer-managed key (CMK) that is rotated every 90 days. They also need to log all access to the bucket and detect anomalous access patterns. Which combination of Google Cloud services should they use?

Hard
10

An organization is implementing a data loss prevention (DLP) strategy for sensitive data stored in Cloud Storage. They want to automatically detect and redact credit card numbers in CSV files uploaded to a specific bucket. Which TWO Google Cloud services should they combine to achieve this?

Hard
11

A security engineer is configuring VPC Service Controls to protect a project containing BigQuery datasets with PII. They want to prevent data exfiltration while allowing authorized users to query the data from outside the perimeter. Which configuration meets these requirements?

Hard
12

A company runs a Kubernetes cluster on GKE. They need to ensure that pods cannot access Google Cloud APIs unless explicitly allowed through a service account. Which GKE feature should they use?

Medium
13

A media company runs a public web application behind a global external Application Load Balancer. They need to block traffic from specific countries subject to sanctions and rate-limit abusive clients, all without changing application code. Which Google Cloud service should the architect configure?

Easy
14

A company has a fleet of Compute Engine instances that need to access a Cloud Storage bucket. The security team requires that only instances in specific VPC networks can access the bucket, and that the data is encrypted in transit. How can this be achieved?

Medium
15

Which TWO are recommended practices for securing a Kubernetes Engine (GKE) cluster?

Medium
16

A company is using Cloud Load Balancing to expose a web application. They want to protect against common web attacks like SQL injection and cross-site scripting. Which Google Cloud service should they configure?

Medium
17

Which TWO of the following are valid methods to control access to Google Cloud resources using Identity and Access Management (IAM)?

Hard
18

A financial services company runs a PCI-DSS regulated workload on Compute Engine. Auditors require that all administrative access to the VMs is brokered through a single, auditable control plane with short-lived credentials, and that no external IP addresses are assigned to the VMs. Which Google Cloud feature should the architect implement to meet these requirements?

Medium
19

A financial services company is migrating a sensitive customer data application to Google Cloud. The application runs on Compute Engine VMs in a VPC. The security team requires that all data at rest in Cloud Storage and BigQuery must be encrypted with customer-managed encryption keys (CMEK). Additionally, the keys must be stored in a different project than the data, and access to the keys must be audited. The operations team has set up a CMEK key in Cloud KMS in a separate project, assigned the Cloud KMS CryptoKey Encrypter/Decrypter role to the data project's Compute Engine service account, and enabled Cloud Storage and BigQuery to use CMEK. However, when the application tries to read from Cloud Storage, it fails with 'Access Denied.' The Cloud KMS key is in project 'kms-proj' and the data is in project 'data-proj'. What is the most likely cause?

Easy
20

A financial services company must comply with PCI DSS. They use Cloud SQL for MySQL for transaction processing. They need to ensure that all data at rest is encrypted with keys generated and stored in a Hardware Security Module (HSM) and that key rotation occurs every 90 days. Which configuration should they use?

Hard
21

A retail company is designing a Google Cloud landing zone for a regulated workload. They must ensure that encryption keys for Cloud Storage and BigQuery are generated and stored outside Google's infrastructure, with the ability to revoke access immediately. They also must retain detailed records of who accessed the data and when, for seven years. Which TWO configurations should the architect include? (Choose two.)

Medium
22

Match each GCP compute service to its characteristic.

Medium
23

A company is deploying a multi-tier web application on Google Cloud. The application must comply with PCI DSS. Which combination of Google Cloud services should be used to restrict access to the database tier to only the application tier, while also encrypting data at rest and in transit?

Medium
24

A company is migrating its on-premises workloads to Google Cloud. They have strict compliance requirements that all data at rest must be encrypted with customer-managed encryption keys (CMEK). Which Google Cloud service should they use to manage the lifecycle of these keys?

Medium
25

A company uses Cloud KMS to encrypt sensitive data. They need to ensure that encryption key usage is audited and that keys are rotated automatically every 30 days. Which two actions should they take? (Choose two.)

Hard
26

A company needs to ensure that all data stored in Cloud Storage is encrypted at rest with keys that they control and can rotate on demand. They also need to maintain an audit trail of key usage. Which Google Cloud service should they use?

Easy
27

A startup wants to grant a new employee read-only access to view all Compute Engine instances in a project. What is the minimum IAM role they should assign?

Easy
28

A healthcare organization is storing sensitive patient data in Cloud Storage. They need to ensure that all objects are encrypted with a key managed by their on-premises HSM. Which encryption approach should they use?

Hard
29

A data scientist needs read-only access to a Cloud Storage bucket containing training data. What is the least privileged IAM role to grant at the bucket level?

Easy
30

A company is deploying a web application on Compute Engine. They want to ensure that only authenticated users can access the application. Which Google Cloud service should they use?

Easy
31

A financial services firm runs a regulated workload in a Google Cloud organization. Compliance requires that no resource in any project can be created outside a defined set of approved regions, and that violations are blocked before resource creation rather than reported afterward. The organization has many projects and new projects are created frequently. Which approach should the architect implement?

Hard
32

Match each GCP data processing service to its use case.

Medium
33

A multinational retailer must comply with a regulation stating that customer personal data collected in the European Union may not be stored or processed outside the EU, including by support staff. The company uses Google Cloud and wants a platform-level mechanism that enforces this at the data-residency level while still allowing the global analytics team to query aggregated, non-personal results. Which Google Cloud capability should the architect use as the foundation?

Easy
34

A company wants to restrict data exfiltration from its Google Cloud projects by preventing resources from copying data to external IP addresses. Which service should they use?

Easy
35

A company is designing a data processing pipeline in Google Cloud that must be HIPAA compliant. Which three security features should they implement? (Choose three.)

Easy
36

A healthcare company stores PHI in BigQuery. Compliance requires that analysts see masked values for patient names and MRNs, while a small data-engineering group must see unmasked values for pipeline troubleshooting. The policy must be enforced by BigQuery itself, independent of any application code. Which approach should the architect implement?

Hard
37

A government agency must retain Cloud Storage objects for seven years in a bucket that also serves live traffic. Regulators require that no user, including project owners, can delete or shorten retention during that period. The architect needs a control that satisfies this. Which should the architect configure?

Hard
38

A company is migrating to Google Cloud and needs to implement a least-privilege access model. Which THREE Google Cloud services or features support this goal? (Choose three.)

Medium
39

Drag and drop the steps to set up a shared VPC in Google Cloud for a multi-project environment into the correct order.

Medium
40

A small company wants to store sensitive files in Cloud Storage and ensure they are encrypted with a key that they control and rotate automatically every 90 days. They are currently using the default encryption provided by Google Cloud. They need a solution that is easy to manage and does not require manual key rotation. What should they do?

Easy
41

An engineering team runs workloads on Compute Engine instances in a single VPC. The security team wants the instances to reach Google APIs such as Cloud Storage and BigQuery without any traffic traversing the public internet, and without managing service account key files on disk. The architect must choose the configuration that meets both goals. Which approach should the architect recommend?

Medium
42

An organization is implementing a data loss prevention (DLP) strategy for Cloud Storage. They want to automatically scan new objects uploaded to a specific bucket and redact sensitive data. Which service and configuration should they use?

Medium
43

An organization has a security policy that prohibits the use of external IP addresses on Compute Engine instances to reduce attack surface. They want to enforce this policy across all new and existing projects. Which approach should they use?

Hard
44

A government agency must run sensitive analytics in BigQuery while ensuring that analysts can see aggregated results but never the raw values of specific personal data columns. Analysts use SQL and must not be able to bypass the restriction by writing their own queries. The agency also needs to record who queried which columns. Which combination should the architect use?

Hard
45

A company wants to ensure that all access to their Cloud Storage bucket is logged for compliance purposes. Which type of audit log should they enable?

Easy
46

A startup wants to encrypt data at rest in Cloud Storage using Customer-Managed Encryption Keys (CMEK). They have already created a Cloud KMS key ring and key. What additional step is required to enable CMEK for a new Cloud Storage bucket?

Easy
47

A multinational corporation operates in multiple regions and must comply with GDPR. They use Cloud Load Balancing to distribute traffic across regional backends. Their security team wants to block traffic from specific countries (e.g., non-EU countries) at the edge. What should they use?

Hard
48

A financial services firm stores sensitive customer records in Cloud Storage and must ensure that only identities in its corporate domain can read the objects, that no object can ever be made publicly accessible, and that access decisions are evaluated centrally. The firm wants the least administrative overhead while keeping these guarantees across many buckets created by different teams. What should the architect implement?

Hard
49

A financial services company runs a containerized trading platform on Google Kubernetes Engine (GKE). Compliance requires that all inter-pod traffic be encrypted without modifying application code, and that the encryption keys be managed by the company rather than Google. The security team wants to enforce this at the infrastructure level. Which approach should they take?

Medium
50

A company is designing a VPC Service Controls perimeter to protect data stored in Google Cloud. They need to allow access from their on-premises network via a Cloud VPN tunnel while blocking all internet-based access. What is the most secure and manageable approach?

Medium
51

A data engineer needs to analyze data in BigQuery but must mask personally identifiable information (PII) based on user roles. Which service should they use?

Medium
52

A healthcare company stores patient records in a Cloud Storage bucket. Compliance requires that all data be encrypted with customer-managed keys, and that the company can revoke access to the data by disabling the key. They also need to audit every key usage. Which approach should they take?

Hard
53

A retail company is building a new application on Google Cloud. The security team requires that all data at rest be encrypted with keys the company manages, that key usage be auditable, and that the application on Compute Engine never store long-lived credentials on disk. The architect is selecting controls for the design. (Choose two.)

Medium
54

A security team wants to receive alerts when a user attempts to grant the 'roles/owner' role to a member outside of the organization's domain. Which log filter should they use to create a log-based metric?

Easy
55

A multinational corporation must comply with GDPR and requires that all customer data stored in BigQuery be encrypted using customer-managed encryption keys (CMEK) and that the keys are stored in a specific region. Which combination of steps should they take?

Hard
56

A healthcare company stores patient records in Cloud Storage buckets across several projects. Compliance auditors require that no object can ever be made publicly readable, even by a project Owner, and that any attempt to do so must be blocked centrally. The security team must enforce this without breaking existing application access. What should they do?

Medium
57

An e-commerce company exposes a public API through an external HTTP(S) load balancer on Google Cloud. The security team wants to block traffic from known malicious IP ranges and apply rate limiting per client IP, while keeping legitimate customers unaffected. They want the least operational overhead and no changes to backend applications. What should they do?

Medium
58

A company is migrating sensitive customer data to Google Cloud. They need to ensure data is encrypted at rest and in transit. Which Google Cloud service provides a centralized way to manage encryption keys used by Google Cloud services?

Easy
59

Drag and drop the steps to configure a Cloud Load Balancer with a backend service consisting of Compute Engine instances into the correct order.

Medium
60

A company wants to restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read. Which approach should they use?

Medium
61

Which THREE Google Cloud services can be used to implement a zero-trust architecture for network security? (Choose three.)

Hard
62

A company wants to use Cloud Armor to protect their HTTP load balancer from SQL injection attacks. Which rule action should they configure to block malicious requests?

Easy
63

A company wants to automatically rotate cryptographic keys on a schedule without manual intervention. Which service should they use?

Easy
64

A company uses Google Cloud Armor to protect their HTTP load balancer from OWASP Top 10 attacks. After deploying a security policy with pre-configured WAF rules, they notice that some legitimate user requests are being blocked because they match a rule incorrectly. The security team wants to fine-tune the rules to reduce false positives while maintaining strong protection. They also want to evaluate the impact of changes before enforcing them. What should they do?

Medium
65

A company hosts a web application on Google Kubernetes Engine (GKE) and wants to protect against SQL injection attacks. Which service should they configure?

Medium

Frequently asked questions

What does the Design for security and compliance domain cover on the PCA exam?
Be able to select the right Google Cloud control for a stated compliance or security requirement: CMEK via Cloud KMS, VPC Service Controls, firewall rules, Cloud Armor, or audit logs. The most important thing is matching the control to the exact threat and regulatory obligation described.
How many questions are in this domain?
This page lists all 65 Design for security and compliance questions in the PCA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Design for security and compliance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
google-pca GOOGLE-PCA security compliance Practice Questions