Courseiva

CCNA Pca Security Compliance Questions

75 of 79 questions · Page 1/2 · Pca Security Compliance topic · Answers revealed

1
Multi-Selectmedium

A security team needs to detect and redact personally identifiable information (PII) in documents stored in Cloud Storage before sharing them with external partners. Which two Google Cloud services should they use together? (Choose two.)

Select 2 answers
A.Cloud Data Loss Prevention (DLP) API
B.Cloud Storage
C.Cloud KMS
D.Cloud Dataflow
E.Cloud NAT
AnswersA, B

The Cloud DLP API inspects content, identifies PII using infoType detectors, and performs de-identification such as redaction or masking. It satisfies the detection and redaction requirement directly, providing the inspection engine that processes documents before external sharing.

Why this answer

The Cloud Data Loss Prevention (DLP) API (A) is the correct service for detecting and redacting personally identifiable information, since it provides infoType detectors and de-identification transforms such as redaction, masking, and tokenization that can scan and sanitize sensitive data. Cloud Storage (B) is also correct because the documents being scanned and shared reside in Cloud Storage buckets, and DLP integrates directly with Cloud Storage to inspect and de-identify objects in place or on export. Together, DLP performs the PII detection and redaction while Cloud Storage holds the source and destination documents, matching the scenario's requirement to sanitize files before external sharing.

Cloud KMS (C) only manages encryption keys and cannot detect or redact PII content. Cloud Dataflow (D) is a data processing pipeline service that could orchestrate jobs but does not itself provide PII detection or redaction logic. Cloud NAT (E) is a networking service for outbound internet access and is unrelated to data inspection or redaction.

Exam trap

PCA often tests whether candidates confuse the service that detects/redacts sensitive data (DLP) with services that merely move, encrypt, or process it (Dataflow, KMS, Storage).

2
MCQmedium

A security team wants to prevent data exfiltration from a GKE cluster to external storage. They need to restrict access to Cloud Storage buckets from the cluster without using private IPs. Which solution should they implement?

A.Configure firewall rules to block outbound traffic to Cloud Storage
B.Enable Cloud Armor on the GKE cluster
C.Use Private Google Access for on-premises access
D.Implement VPC Service Controls with a service perimeter
AnswerD

VPC Service Controls builds a service perimeter around the GKE cluster's project, blocking Cloud Storage access from outside the perimeter even over public IPs. This satisfies the no-private-IP constraint by enforcing an identity- and network-independent boundary against exfiltration.

Why this answer

VPC Service Controls use service perimeters to protect resources and prevent data exfiltration from authorized networks, including GKE clusters, to external resources.

3
MCQeasy

A developer wants to store a database password that is used by a Cloud Function. The password must be automatically rotated every 30 days and accessed securely without storing it in the source code. Which GCP service should they use?

A.Cloud KMS
B.Cloud Runtime Configuration
C.Secret Manager
D.Firestore
AnswerC

Secret Manager stores the password securely and supports automatic rotation schedules, so the Cloud Function retrieves it at runtime rather than embedding it in source code. This satisfies both the 30-day rotation and secure-access constraints.

Why this answer

Secret Manager is the GCP service purpose-built for storing, accessing, and rotating secrets like database passwords. It supports automatic rotation schedules (including 30-day intervals) via Cloud Functions or Pub/Sub notifications, and Cloud Functions can access secrets at runtime using the Secret Manager API with IAM controls, keeping credentials out of source code.

Exam trap

PCA often tests the distinction between Cloud KMS (encryption keys) and Secret Manager (application secrets), so candidates who see 'password' and think 'encryption' incorrectly choose Cloud KMS.

How to eliminate wrong answers

Option A is wrong because Cloud KMS is for managing encryption keys (CMEK), not for storing and rotating application secrets like passwords; it does not provide secret versioning or rotation of arbitrary secret values. Option B is wrong because Cloud Runtime Configuration (Runtime Configurator) is deprecated and was intended for dynamic configuration, not secure secret storage with rotation. Option D is wrong because Firestore is a NoSQL document database and storing passwords there lacks the security, audit, and rotation features of Secret Manager.

4
MCQeasy

An engineer needs to grant a user the ability to create and manage service accounts in a project. Which predefined IAM role provides these permissions?

A.roles/owner
B.roles/iam.serviceAccountAdmin
C.roles/editor
D.roles/iam.workloadIdentityUser
AnswerB

roles/iam.serviceAccountAdmin grants the full set of service account management permissions — creating, deleting, updating and viewing service accounts, plus binding IAM policies on them — matching the requirement to create and manage service accounts within the project.

Why this answer

The predefined role roles/iam.serviceAccountAdmin provides permissions to create and manage service accounts within a project. It includes actions like creating, deleting, and updating service accounts, as well as managing their IAM policies. This role is specifically designed for service account administration.

Exam trap

The trap is confusing serviceAccountAdmin with serviceAccountUser or owner. Candidates might think owner is needed, but it's over-privileged. The key is to know the specific predefined role for managing service accounts.

How to eliminate wrong answers

Option A is wrong because roles/owner grants full control over all resources in the project, which is excessive and violates least privilege. Option C is wrong because roles/editor allows broad edit access but does not include the specific permissions to manage service accounts. Option D is wrong because roles/iam.workloadIdentityUser is used to allow a service account to impersonate another service account, not to manage service accounts.

5
MCQmedium

An organization uses Active Directory (AD) on-premises and wants to synchronize user identities to Google Cloud Identity so that users can access G Suite and GCP resources with their existing credentials. Which service should they use?

A.Cloud Identity-Aware Proxy (IAP)
B.Federation with Google Identity Platform
C.Cloud Directory Sync
D.SAML SSO
AnswerC

Cloud Directory Sync reads users and groups from on-premises Active Directory via LDAP, then provisions and updates matching identities in Cloud Identity, letting users authenticate to G Suite and GCP with existing credentials. It satisfies the synchronisation requirement without federation.

Why this answer

Google Cloud Directory Sync (GCDS) is the tool designed to synchronize users, groups, and organizational units from on-premises Active Directory (or LDAP) to Google Cloud Identity or Google Workspace. It runs on-premises, reads from AD via LDAP, and provisions matching identities in Google, enabling users to sign in with existing credentials.

Exam trap

PCA often tests the difference between directory synchronization (GCDS) and authentication federation (SAML SSO), so candidates who focus on 'existing credentials' pick SAML SSO instead of the sync tool.

How to eliminate wrong answers

Option A is wrong because Cloud Identity-Aware Proxy (IAP) is an access control layer for applications, not an identity synchronization service. Option B is wrong because Federation with Google Identity Platform is for federating authentication (e.g., SAML/OIDC) rather than synchronizing directory objects like users and groups from AD. Option D is wrong because SAML SSO enables single sign-on but does not synchronize user identities into Cloud Identity; it relies on the IdP for authentication without provisioning directory entries.

6
Multi-Selecteasy

Which two GCP audit log types are available by default? (Choose TWO).

Select 2 answers
A.Admin Activity audit logs
B.System Event audit logs
C.Cloud Audit Logs
D.Policy Denied audit logs
E.Data Access audit logs
AnswersA, B

Admin Activity audit logs record API calls that modify resource configuration or metadata, and GCP writes them automatically for every project at no cost. They are always enabled and cannot be disabled, satisfying the requirement for a log type available by default.

Why this answer

Admin Activity audit logs (A) are enabled by default and always written for free, capturing administrative operations that modify resource configurations or metadata, such as creating a VM or changing IAM policies. System Event audit logs (B) are also enabled by default and record Google Cloud system-generated actions that modify resources, such as live migration of a VM or automatic restart by a scheduler, and they cannot be disabled. Cloud Audit Logs (C) is not a log type but the overall umbrella service comprising Admin Activity, Data Access, System Event, and Policy Denied logs, so it is not one of the two default types.

Policy Denied audit logs (D) are only written when a security policy such as VPC Service Controls denies a request, and Data Access audit logs (E) are disabled by default (except for BigQuery) and must be explicitly enabled per service, so neither is available by default.

Exam trap

PCA often tests the distinction between always-on audit logs (Admin Activity, System Event) and opt-in logs (Data Access, Policy Denied), tricking candidates into selecting Data Access because it sounds fundamental.

7
MCQhard

A company deploys a Kubernetes workload in GKE that needs to access Cloud Storage. They want to avoid managing service account keys. What is the recommended approach?

A.Use the default Compute Engine service account on the node.
B.Store a service account key in a Kubernetes secret and mount it.
C.Use Workload Identity to map the Kubernetes service account to a GCP service account.
D.Use Cloud Key Management Service to encrypt the service account key.
AnswerC

Workload Identity federates Kubernetes service accounts to GCP service accounts via the GKE metadata server, issuing short-lived credentials automatically. This removes the need to create, distribute, or rotate service account keys, meeting the keyless requirement.

Why this answer

Workload Identity is the recommended way for GKE workloads to authenticate to Google Cloud services without managing long-lived service account keys. It binds a Kubernetes service account (KSA) to a Google Cloud service account (GSA) via IAM, and the GKE metadata server issues short-lived credentials to the pod automatically. This eliminates key rotation, storage, and leakage risks.

Exam trap

PCA often tests the misconception that encrypting or storing a service account key (KMS or Kubernetes secret) is a secure alternative — the exam wants you to recognize that eliminating keys entirely via Workload Identity is the only keyless option.

How to eliminate wrong answers

Option A is wrong because using the node's default Compute Engine service account grants every pod on the node the same broad permissions, violating least privilege and still relying on node-level credentials. Option B is wrong because storing a service account key in a Kubernetes secret reintroduces the exact key-management problem the company wants to avoid — keys are long-lived, can leak, and require rotation. Option D is wrong because KMS encrypts the key but does not eliminate it; the key still exists, must be decrypted by the workload, and remains a long-lived credential to manage.

8
MCQeasy

An organization wants to enforce that all container images deployed to Google Kubernetes Engine (GKE) clusters are signed by an authorized authority and only those images are allowed to run. Which GCP service should they use?

A.Cloud Key Management Service (Cloud KMS)
B.Binary Authorization
C.Cloud Build
D.Artifact Registry
AnswerB

Binary Authorization enforces deploy-time attestation, admitting only container images whose signatures match an authorised attestor policy. It intercepts the GKE admission path, so unsigned or unauthorised images are rejected before running. This satisfies the stem's requirement that only images signed by an authorised authority execute.

Why this answer

Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed on GKE. It works by enforcing attestations that are created by authorized authorities after verifying the image's signature. This allows you to enforce that only images signed by an authorized authority are allowed to run.

Exam trap

The trap is confusing Binary Authorization with Cloud KMS or Artifact Registry. Candidates might think that signing images with Cloud KMS is enough, but enforcement requires Binary Authorization. Also, Cloud Build can sign but not enforce.

How to eliminate wrong answers

Option A is wrong because Cloud KMS is a key management service used to create and manage cryptographic keys, but it does not enforce deployment policies. Option C is wrong because Cloud Build is a CI/CD service that can build and sign images, but it does not enforce that only signed images run. Option D is wrong because Artifact Registry is a repository for container images, but it does not enforce signing or deployment policies.

9
MCQmedium

A developer needs to securely store a database password that will be used by a Compute Engine instance. The password must be rotated automatically every 30 days. Which service should they use?

A.Cloud KMS
B.Cloud Storage with encryption
C.Environment variables
D.Secret Manager
AnswerD

Secret Manager stores the database password as a versioned secret and supports rotation schedules, satisfying the 30-day automatic rotation constraint. A Compute Engine instance retrieves it at runtime via its service account, so the credential never sits in code or instance metadata.

Why this answer

Google Cloud Secret Manager is designed to store, manage, and rotate secrets such as database passwords, API keys, and certificates. It supports automatic rotation schedules via Pub/Sub notifications and Cloud Functions or Cloud Run, making it the correct choice for a password that must rotate every 30 days. Cloud KMS manages encryption keys, not application secrets.

Exam trap

PCA often tests the confusion between Cloud KMS (encryption key management) and Secret Manager (application secret storage and rotation), trapping candidates who pick KMS for password storage.

How to eliminate wrong answers

Option A is wrong because Cloud KMS manages cryptographic keys for encryption/decryption, not arbitrary application secrets like database passwords, and it does not provide secret rotation scheduling. Option B is wrong because Cloud Storage with encryption stores objects but does not provide secret management, versioning of secrets, or automatic rotation. Option C is wrong because environment variables are not secure storage — they can be exposed in logs, process listings, and crash dumps, and they offer no rotation mechanism.

10
MCQeasy

An organization wants to enforce that all container images deployed to Google Kubernetes Engine (GKE) are signed and approved via an attestation authority. Which GCP service should they use?

A.Binary Authorization
B.Container Registry
C.Cloud Armor
D.Cloud Security Scanner
AnswerA

Binary Authorization enforces deploy-time admission control on GKE, verifying cryptographic signatures and attestations produced by trusted authorities before a container image is admitted. This directly satisfies the stem's requirement that images be signed and approved via an attestation authority, blocking unsigned or unapproved images at deployment.

Why this answer

Binary Authorization is the Google Cloud service that enforces deploy-time security controls on GKE by allowing only container images that are signed and attested by trusted authorities. It integrates with GKE admission controllers to block unsigned or unattested images. This directly matches the requirement to enforce signed and approved images via an attestation authority.

Exam trap

The trap is confusing image storage (Container Registry) with image admission control (Binary Authorization); candidates often pick the registry because it is where images live, but it does not enforce signing.

How to eliminate wrong answers

Option B is wrong because Container Registry (now Artifact Registry) is a storage and management service for container images; it does not enforce signing or attestation policies at deployment. Option C is wrong because Cloud Armor is a WAF and DDoS protection service for HTTP(S) load balancing; it does not validate container image signatures. Option D is wrong because Cloud Security Scanner (now Web Security Scanner) scans web applications for vulnerabilities; it does not enforce image signing or attestation.

11
MCQmedium

An organization uses Active Directory (AD) on-premises. They want to synchronize user accounts and groups to Google Cloud Identity so that users can sign in with their existing AD credentials. Which service should they use?

A.Cloud Identity Platform
B.Google Cloud Directory Sync
C.Cloud Identity-Aware Proxy
D.Security Command Center
AnswerB

Google Cloud Directory Sync provisions users and groups from on-premises Active Directory into Cloud Identity, letting accounts authenticate with existing AD credentials. It synchronises directory data rather than federating sign-in, which suits the stated requirement to mirror accounts and groups.

Why this answer

Google Cloud Directory Sync (GCDS) is the official tool for synchronizing users, groups, and other directory data from an on-premises Active Directory or LDAP directory to Google Cloud Identity or Google Workspace. It runs on-premises, reads from AD, and provisions accounts in Google Cloud, allowing users to sign in with their existing AD credentials (often via SAML federation or password sync).

Exam trap

PCA often tests the distinction between directory synchronization (GCDS) and authentication federation (SAML), and candidates may choose Cloud Identity Platform or IAP thinking they handle AD sync.

How to eliminate wrong answers

Option A is wrong because Cloud Identity Platform is a customer identity and access management (CIAM) service for building authentication into applications, not for directory synchronization from AD. Option C is wrong because Cloud Identity-Aware Proxy (IAP) is a zero-trust access control service for applications running on Google Cloud, not a directory sync tool. Option D is wrong because Security Command Center is a security and risk management platform, not an identity synchronization service.

12
MCQeasy

A company wants to give a new employee read-only access to all projects in their GCP organization. Which IAM role should they assign at the organization level to grant this access?

A.roles/owner
B.roles/editor
C.roles/viewer
D.roles/orgadmin
AnswerC

roles/viewer grants read-only access to all GCP resources within the organisation, including every project beneath it. Assigning it at the organisation level satisfies the stem's requirement for organisation-wide read-only visibility, since the role inherits down the resource hierarchy to all current and future projects.

Why this answer

The roles/viewer role grants read-only access to all resources within the organization, including all projects, making it the correct choice for a new employee who needs read-only access across all projects. Assigning it at the organization level ensures the permission is inherited by all projects, folders, and resources beneath. This follows the principle of least privilege for read-only access.

Exam trap

PCA often tests the difference between basic roles (viewer, editor, owner) and their scope — candidates may pick roles/editor thinking it is needed to 'access' projects, but editor grants write access, violating the read-only requirement, while roles/viewer is the correct least-privilege choice.

How to eliminate wrong answers

Option A is wrong because roles/owner grants full control over all resources, including the ability to manage IAM policies and billing — far more than read-only access and a violation of least privilege. Option B is wrong because roles/editor grants read and write access (create, modify, delete resources) but not IAM management — still excessive for a read-only requirement. Option D is wrong because roles/orgadmin is a role for managing organization-level IAM policies and administrative settings, not for reading project resources; it is an administrative role, not a data-access role.

13
Multi-Selecthard

A company wants to use Binary Authorization to enforce that only images signed by their internal CI/CD pipeline can be deployed to their GKE clusters. They have set up Cloud Build to sign images. Which THREE steps are required to configure this? (Choose 3)

Select 3 answers
A.Create an attestation for each container image using Cloud Build
B.Create a Binary Authorization policy that requires attestations for the GKE cluster
C.Create an attestor in Binary Authorization
D.Store the signing keys in Cloud HSM
E.Grant the GKE service account the roles/container.deployer role
AnswersA, B, C

Cloud Build must generate a cryptographic attestation (a signed note stored in Artifact Registry) for each image, proving it passed the pipeline. Binary Authorization then verifies this attestor signature at admission time, satisfying the constraint that only CI/CD-signed images deploy to GKE.

Why this answer

Option C is correct because Binary Authorization requires an attestor resource, which defines the cryptographic key pair (via Cloud KMS) and is used to verify attestations; without creating an attestor, no attestation can be validated. Option A is correct because the CI/CD pipeline (Cloud Build) must create a signed attestation for each container image after building it, proving the image was produced by the trusted pipeline. Option B is correct because a Binary Authorization policy must be configured to require attestations from that attestor for the GKE cluster, otherwise the cluster will not enforce the signature requirement.

Option D is not required: signing keys can be managed in Cloud KMS, and Cloud HSM is only an optional key protection level, not a mandatory step. Option E is not required: roles/container.deployer is unrelated to Binary Authorization enforcement and does not configure attestation verification.

Exam trap

PCA often tests the three required components of attestation-based Binary Authorization — candidates add optional hardening steps like Cloud HSM key storage or IAM role grants, mistaking them for mandatory configuration steps.

14
MCQeasy

An organization wants to enforce that all container images deployed to their Google Kubernetes Engine (GKE) clusters are signed and have passed a vulnerability scan. Which GCP service should they use to enforce this policy?

A.Cloud Build
B.Artifact Registry
C.IAM
D.Binary Authorization
AnswerD

Binary Authorization enforces deploy-time attestations on GKE, admitting only images signed by trusted authorities and carrying vulnerability-scan attestations. This directly satisfies the stem's requirement that images be both signed and scanned before deployment, blocking non-compliant images at admission rather than merely detecting them afterwards.

Why this answer

Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed to GKE or Cloud Run. It works by requiring attestations (cryptographically signed proofs) that images have been built by a trusted builder and passed required checks such as vulnerability scanning. If an image lacks the required attestation, the admission controller rejects the deployment.

Exam trap

PCA often tests the difference between services that scan images (Artifact Registry/Container Analysis) and the service that enforces deployment-time policy (Binary Authorization); candidates frequently pick the scanning service instead of the enforcement service.

How to eliminate wrong answers

Option A is wrong because Cloud Build is a CI/CD service that builds and tests images but does not enforce admission policies at deploy time. Option B is wrong because Artifact Registry stores and scans container images but does not block deployments based on attestations. Option C is wrong because IAM controls who can perform actions on GCP resources, not whether a specific container image meets security attestation requirements.

15
MCQeasy

A developer wants to allow a Compute Engine VM to authenticate to Google Cloud APIs without embedding service account keys in the VM image. What is the recommended approach?

A.Use Cloud KMS to encrypt a service account key and store it in a bucket
B.Use a service account impersonation flow
C.Attach a service account to the VM instance
D.Create a service account key and store it in the VM's startup script
AnswerC

Attaching a service account to the VM lets Compute Engine supply short-lived credentials through the instance metadata server, so applications call Google Cloud APIs without embedded keys. This removes the key distribution and rotation risk that static service account keys in images create.

Why this answer

Attaching a service account to a Compute Engine VM instance is the recommended approach because it provides the VM with automatically rotated, short-lived credentials via the metadata server. Applications on the VM can call the metadata server to obtain access tokens without any key files. This eliminates the risk of key leakage and manual rotation.

Exam trap

The trap here is confusing service account impersonation with direct attachment; candidates may think impersonation is needed for VMs, but impersonation is for users or services acting as another identity, not for a VM's native authentication.

How to eliminate wrong answers

Option A is wrong because encrypting a service account key with Cloud KMS and storing it in a bucket still requires the VM to retrieve and decrypt the key, which introduces key management overhead and potential exposure. Option B is wrong because service account impersonation is typically used by human users or services that need to act as another service account, not as the primary method for a VM to authenticate to APIs. Option D is wrong because embedding a service account key in a startup script exposes the key in instance metadata and logs, which is a security anti-pattern.

16
MCQmedium

A financial services firm stores sensitive customer transaction data in Cloud Storage buckets. The security team wants to ensure that the data is encrypted at rest with a key that the firm controls, and that the key is automatically rotated every 90 days. They also need to be able to revoke access to the data immediately by disabling the key. Which Google Cloud service and configuration should they use?

A.Use Customer-Managed Encryption Keys (CMEK) with Cloud KMS, set a rotation period of 90 days, and disable the key to revoke access.
B.Use Customer-Supplied Encryption Keys (CSEK) and store the keys in a secure vault, rotating them manually every 90 days.
C.Use Google-managed encryption keys and configure a Cloud Scheduler job to rotate the keys every 90 days.
D.Use Cloud HSM to generate keys, and configure Cloud Storage to use those keys with a 90-day rotation policy.
AnswerA

CMEK allows you to use your own keys in Cloud KMS to encrypt data in Cloud Storage. You can configure automatic rotation every 90 days, and disabling the key immediately prevents decryption, effectively revoking access. This meets all requirements: control over encryption, automatic rotation, and immediate revocation.

Why this answer

Customer-Managed Encryption Keys (CMEK) with Cloud KMS allow organizations to control the encryption keys used for data at rest in Cloud Storage. You can set an automatic rotation period, such as 90 days, and disabling the key immediately revokes access to the data. This satisfies the requirements for control, automatic rotation, and immediate revocation.

Exam trap

The trap here is confusing CMEK with CSEK; CSEK requires you to manage keys entirely, without Cloud KMS rotation or disablement features.

17
MCQmedium

A company wants to allow users to authenticate to a web application running on Compute Engine using their existing corporate Active Directory credentials without exposing the application to the public internet. Which approach should they use?

A.Configure a Cloud VPN and allow only corporate IP addresses in firewall rules
B.Set up Identity-Aware Proxy (IAP) and sync Active Directory to Cloud Identity
C.Use Cloud Load Balancing with SSL and client certificates
D.Configure Cloud NAT and assign static IPs to users
AnswerB

IAP enforces identity verification at the load balancer, letting corporate Active Directory users reach the private Compute Engine app without a public IP. Syncing AD to Cloud Identity federates those credentials, satisfying both the authentication and no-public-exposure constraints.

Why this answer

Identity-Aware Proxy (IAP) provides zero-trust access control to applications without exposing them to the public internet, and it integrates with Cloud Identity. By syncing on-premises Active Directory to Cloud Identity (via GCDS or federation), users can authenticate with their corporate credentials through IAP, which enforces IAM policies before allowing access to the Compute Engine-hosted app.

Exam trap

PCA often tests whether candidates confuse network-level access controls (VPN, firewall rules, client certs) with identity-based zero-trust access (IAP), and whether they understand that IAP requires Cloud Identity integration for AD credentials.

How to eliminate wrong answers

Option A is wrong because a Cloud VPN with IP-based firewall rules exposes the application to anyone on the corporate network and does not provide identity-based authentication — it's network-level, not user-level, access control. Option C is wrong because SSL with client certificates provides mutual TLS authentication but does not integrate with Active Directory credentials and still requires exposing the load balancer publicly. Option D is wrong because Cloud NAT provides outbound internet access for private instances and static IPs for egress — it has nothing to do with inbound user authentication or AD integration.

18
MCQeasy

A startup wants to grant a contractor limited access to a single Cloud Storage bucket. The contractor should be able to view and download objects, but not delete or overwrite them. Which IAM role should be assigned?

A.roles/storage.admin
B.roles/storage.objectAdmin
C.roles/storage.objectCreator
D.roles/storage.objectViewer
AnswerD

roles/storage.objectViewer grants read-only access to objects, permitting viewing and downloading but excluding delete or overwrite permissions. This satisfies the least-privilege constraint of limiting the contractor to a single bucket without mutation rights, unlike objectAdmin or objectCreator.

Why this answer

The roles/storage.objectViewer role grants read-only access to objects in a bucket, including listing and downloading objects, but does not allow modification or deletion.

19
MCQmedium

A security engineer wants to prevent data exfiltration from a project 'prod-data' by ensuring that only approved VPC networks can access BigQuery datasets. Which GCP service should be used?

A.Private Google Access
B.Cloud Armor
C.Cloud NAT
D.VPC Service Controls
AnswerD

VPC Service Controls builds a service perimeter around BigQuery, restricting access to approved VPC networks and blocking data exfiltration even by authorised identities. This directly enforces the network-origin constraint on the prod-data project's datasets, which IAM alone cannot achieve.

Why this answer

VPC Service Controls create a service perimeter around GCP resources such as BigQuery datasets, restricting access to only approved VPC networks and identities. By placing the 'prod-data' project inside a perimeter and defining access levels, the engineer can block data exfiltration from unapproved networks. This is the GCP-native control designed specifically for this scenario.

Exam trap

The trap is confusing network-level controls (Private Google Access, Cloud NAT) with API-level perimeter controls (VPC Service Controls) that actually restrict data access to approved networks.

How to eliminate wrong answers

Option A is wrong because Private Google Access only allows VM instances without external IPs to reach Google APIs; it does not restrict which networks can access BigQuery. Option B is wrong because Cloud Armor protects HTTP(S) load-balanced applications from web attacks, not BigQuery data access. Option C is wrong because Cloud NAT provides outbound internet access for private instances; it has no role in restricting BigQuery access.

20
MCQeasy

Which GCP service can be used to detect and redact sensitive data such as credit card numbers in text files stored in Cloud Storage?

A.Security Command Center
B.Cloud Key Management Service
C.Cloud Audit Logs
D.Cloud Data Loss Prevention (DLP)
AnswerD

Cloud DLP inspects Cloud Storage objects using infoType detectors that recognise credit card numbers and other sensitive patterns, then redacts or masks the matches. It satisfies the detection-and-redaction requirement directly, unlike encryption or access-control services that never examine file contents.

Why this answer

Cloud Data Loss Prevention (DLP) is a fully managed service designed to discover, classify, and protect sensitive data. It uses built-in infoType detectors (e.g., CREDIT_CARD_NUMBER, US_SOCIAL_SECURITY_NUMBER) to scan text files in Cloud Storage and can redact or mask the findings. The other services do not provide data inspection and redaction capabilities.

Exam trap

PCA often tests the misconception that security management tools like Security Command Center or audit logs can detect and redact sensitive data, when in fact only Cloud DLP provides data inspection and de-identification capabilities.

How to eliminate wrong answers

Option A is wrong because Security Command Center is a security posture management and threat detection service that aggregates findings from other tools; it does not scan file contents for sensitive data or perform redaction. Option B is wrong because Cloud Key Management Service manages encryption keys and cryptographic operations, not data inspection or redaction. Option C is wrong because Cloud Audit Logs record administrative and data access activities for auditing purposes; they do not analyze file contents for sensitive information.

21
MCQmedium

A company is migrating its on-premises data warehouse to BigQuery. The security team requires that all data at rest in BigQuery is encrypted with keys that the company controls, and that key usage is logged for auditing. They also need to be able to revoke access to the data by disabling the key. Which configuration should they implement?

A.Use BigQuery default encryption and enable Cloud Audit Logs for BigQuery.
B.Use Customer-Supplied Encryption Keys (CSEK) for BigQuery, and store the keys in a secure vault.
C.Use Cloud HSM to generate keys, and configure BigQuery to use those keys for encryption.
D.Use Customer-Managed Encryption Keys (CMEK) for BigQuery, and enable Cloud KMS audit logs.
AnswerD

CMEK allows you to use your own keys in Cloud KMS to encrypt BigQuery data. Enabling Cloud KMS audit logs records all key usage, including encryption and decryption operations. Disabling the key immediately revokes access to the data. This meets all requirements: customer-controlled keys, key usage logging, and revocation capability.

Why this answer

Customer-Managed Encryption Keys (CMEK) for BigQuery allow you to use your own keys in Cloud KMS to encrypt data at rest. Enabling Cloud KMS audit logs records all key usage, satisfying the auditing requirement. Disabling the key revokes access to the data.

This configuration meets all security requirements.

Exam trap

The trap here is thinking BigQuery supports Customer-Supplied Encryption Keys (CSEK); it does not, and CMEK is the correct mechanism for customer-controlled keys.

22
MCQmedium

A company needs to encrypt data at rest in Cloud Storage using their own keys. They require that the keys are stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 certified. Which key management option should they choose?

A.Google-managed encryption keys
B.Customer-Supplied Encryption Keys (CSEK)
C.Customer-Managed Encryption Keys (CMEK) with Cloud HSM
D.Customer-Managed Encryption Keys (CMEK) with Cloud KMS
AnswerC

CMEK with Cloud HSM lets the customer retain control of the key while Cloud HSM stores it in a hardware security module validated to FIPS 140-2 Level 3. This satisfies the explicit HSM and certification constraint that software-backed or Google-managed keys cannot meet.

Why this answer

CMEK with Cloud HSM is correct because it lets the customer own and control the key while the key material is generated, stored, and used inside a FIPS 140-2 Level 3 validated hardware security module managed by Google Cloud. This satisfies both the 'customer-managed keys' requirement and the explicit HSM/FIPS 140-2 Level 3 mandate. Cloud KMS software keys (option D) are FIPS 140-2 Level 1/2 only, so they fail the HSM requirement.

Exam trap

PCA often tests the distinction between 'customer-managed' and 'hardware-backed' — candidates see 'CMEK' in option D and pick it, forgetting that Cloud KMS software keys do not meet FIPS 140-2 Level 3, which only Cloud HSM provides.

How to eliminate wrong answers

Option A is wrong because Google-managed encryption keys are fully controlled by Google, so the customer has no ownership or rotation control and cannot meet the 'their own keys' requirement. Option B is wrong because CSEK keys are supplied by the customer at request time and are never stored in Cloud KMS or an HSM — they are held in memory by the client, so they cannot satisfy a FIPS 140-2 Level 3 HSM storage requirement. Option D is wrong because standard Cloud KMS software-protected keys are not backed by an HSM and only meet FIPS 140-2 Level 1 (with some Level 2 aspects), not Level 3.

23
MCQeasy

A security engineer needs to restrict access to a Google Cloud project so that only a specific set of IP addresses can reach Cloud Storage buckets. Which feature should be configured?

A.VPC Service Controls
B.IAM Conditions
C.Firewall Rules
D.Cloud Armor
AnswerA

VPC Service Controls create a service perimeter around the project, blocking access from outside approved networks regardless of IAM permissions. This satisfies the IP-based restriction requirement by enforcing perimeter ingress rules, though note that Cloud Storage access via the Google Cloud console or APIs is contained within the perimeter boundary.

Why this answer

VPC Service Controls creates a service perimeter around Google Cloud resources like Cloud Storage buckets, enforcing context-aware access based on attributes such as the source IP address of the caller. By defining an access level that includes only the specified IP ranges and binding it to the perimeter, requests from outside those IPs are denied even if the caller has valid IAM permissions. This is the only option that provides network-origin-based restriction at the project/service level for Cloud Storage.

Exam trap

The trap here is confusing network-layer controls (firewall rules, Cloud Armor) with service-level perimeter controls (VPC Service Controls) that can enforce IP-based access to managed services like Cloud Storage.

How to eliminate wrong answers

Option B is wrong because IAM Conditions can only evaluate attributes of the principal, resource, or request (e.g., time, resource name, tags) and cannot restrict based on the caller's source IP address. Option C is wrong because VPC firewall rules apply only to traffic within a VPC network and do not govern access to Google Cloud managed services like Cloud Storage, which are accessed via public APIs outside the VPC. Option D is wrong because Cloud Armor protects HTTP(S) load balancer backends against web attacks and cannot restrict access to Cloud Storage buckets.

24
Multi-Selecthard

A company wants to allow a Kubernetes pod in GKE to authenticate to Google Cloud APIs without storing service account keys in the cluster. Which three components need to be configured to enable Workload Identity? (Choose three.)

Select 3 answers
A.Google Cloud service account
B.Kubernetes service account with annotation
C.Firewall rule to allow traffic to metadata server
D.IAM policy binding granting the GCP SA roles/iam.workloadIdentityUser on the GCP SA
E.Cloud NAT for outbound access
AnswersA, B, D

The Google Cloud service account is the identity the pod impersonates to call Google Cloud APIs. It must exist and be granted the required IAM roles, forming the target of the Workload Identity mapping that removes the need for downloaded keys.

Why this answer

Workload Identity requires: (1) a Google Cloud IAM service account (GCP SA), (2) a Kubernetes service account (KSA) annotated with the GCP SA email, and (3) an IAM policy binding between the KSA and GCP SA to allow impersonation.

25
Multi-Selectmedium

An organization wants to protect an HTTPS load-balanced web application from common web attacks, such as SQL injection and cross-site scripting (XSS), as well as rate-limit traffic from specific IPs. Which three capabilities should they use together? (Choose three.)

Select 3 answers
A.Cloud Armor rate limiting
B.Cloud CDN
C.Cloud Armor WAF rules
D.Cloud Load Balancing logging
E.Cloud Armor IP blacklist/whitelist
AnswersA, C, E

Cloud Armor rate limiting enforces per-IP throttling at the Google Cloud edge, satisfying the requirement to restrict traffic from specific addresses. Combined with its preconfigured WAF rules for SQL injection and XSS, it addresses the attack-mitigation constraint directly, protecting the HTTPS load-balanced backend without application changes.

Why this answer

Cloud Armor WAF rules (C) are correct because Cloud Armor's preconfigured WAF rulesets, based on the ModSecurity core rule set, are specifically designed to detect and block common web attacks like SQL injection and XSS at the load balancer edge. Cloud Armor rate limiting (A) is correct because it lets you define rate-based rules that throttle or ban clients exceeding a request threshold, which directly addresses rate-limiting traffic from specific IPs. Cloud Armor IP blacklist/whitelist (E) is correct because it allows allow/deny rules scoped to specific source IP addresses or CIDR ranges, which is needed to block or permit traffic from particular IPs.

Cloud CDN (B) is not correct because it is a content caching and delivery service, not a security control for WAF or rate limiting. Cloud Load Balancing logging (D) is not correct because it only records request data for visibility and auditing; it does not block attacks or enforce rate limits.

26
MCQmedium

An organization needs to store API keys and database passwords securely in Google Cloud. They want to automatically rotate secrets every 30 days. Which service should they use?

A.Cloud Storage with bucket-level encryption
B.Cloud Key Management Service (Cloud KMS)
C.Secret Manager
D.Cloud Runtime Configurator
AnswerC

Secret Manager stores API keys and database passwords as versioned secrets, and its rotation schedules trigger Pub/Sub notifications every 30 days so rotation can be automated. This directly satisfies the stem's requirement for secure storage plus automatic 30-day rotation, unlike Cloud KMS, which manages encryption keys rather than application credentials.

Why this answer

Secret Manager supports automatic rotation with a rotation period and can trigger a Cloud Function to generate a new secret version.

27
MCQhard

An organization needs to encrypt data at rest in BigQuery using keys that are rotated every 90 days. They want to manage the keys themselves but cannot store keys on-premises. Which encryption approach should they use?

A.Default Google-managed encryption
B.Customer-Managed Encryption Keys (CMEK) with Cloud KMS
C.Cloud HSM
D.Customer-Supplied Encryption Keys (CSEK)
AnswerB

CMEK with Cloud KMS lets the organisation generate, rotate and manage its own key material inside Google Cloud, satisfying the 90-day rotation requirement without on-premises key storage. BigQuery decrypts data using these keys, so control stays with the customer while keys never leave Cloud KMS.

Why this answer

CMEK with Cloud KMS lets the organization own and control the key material while Google Cloud stores and manages the keys in KMS, satisfying the requirement to manage keys themselves without on-premises storage. Cloud KMS supports automatic rotation schedules (e.g., every 90 days) and integrates natively with BigQuery so that data at rest is encrypted with the customer's key. This gives the customer control over key lifecycle, access, and revocation while meeting the no-on-premises constraint.

Exam trap

PCA often tests the distinction between CMEK (customer controls key lifecycle in Cloud KMS) and CSEK (customer supplies and stores raw keys), so candidates who see 'manage keys themselves' and jump to CSEK miss the 'cannot store keys on-premises' constraint.

How to eliminate wrong answers

Option A is wrong because default Google-managed encryption does not give the customer control over keys or the ability to rotate them on a customer-defined 90-day schedule. Option C is wrong because Cloud HSM is a hardware security module offering within Cloud KMS for FIPS 140-2 Level 3 key protection, not a separate encryption approach for BigQuery data at rest; it can be used with CMEK but is not the answer by itself. Option D is wrong because Customer-Supplied Encryption Keys (CSEK) require the customer to supply and store the raw key material themselves (typically on-premises or in their own vault), which directly violates the constraint that keys cannot be stored on-premises.

28
MCQmedium

A company wants to allow a Kubernetes pod in GKE to access a Cloud Storage bucket using a specific service account without storing long-lived credentials. Which method should be used?

A.Assign the service account directly to the GKE node pool
B.Create a JSON key for a service account and mount it as a secret in the pod
C.Use Workload Identity to bind the Kubernetes service account to a Google Cloud service account
D.Use Application Default Credentials on the pod
AnswerC

Workload Identity federates a Kubernetes service account with a Google Cloud service account via the cluster's workload identity pool, issuing short-lived tokens. The pod therefore accesses Cloud Storage without any long-lived service account key stored in the cluster.

Why this answer

Workload Identity is the recommended way to allow a Kubernetes pod in GKE to access Google Cloud services like Cloud Storage using a specific service account without long-lived credentials. It binds a Kubernetes service account to a Google Cloud service account, and the pod uses the Kubernetes service account to obtain short-lived credentials via the GKE metadata server. This eliminates the need for JSON keys.

Exam trap

PCA often tests the misconception that mounting service account keys is acceptable, but the exam emphasizes keyless authentication via Workload Identity.

How to eliminate wrong answers

Option A is wrong because assigning the service account to the node pool grants all pods on that node the same permissions, violating least privilege and not allowing per-pod service accounts. Option B is wrong because creating and mounting JSON keys introduces long-lived credentials that must be managed and rotated, which is insecure. Option D is wrong because Application Default Credentials on the pod would still require a service account key or the node's service account, not a specific service account without long-lived credentials.

29
Multi-Selectmedium

A company wants to deploy a web application behind an HTTPS Load Balancer and only allow authenticated users from their corporate Active Directory. Which two services should they use together? (Choose two.)

Select 2 answers
A.Identity-Aware Proxy (IAP)
B.VPC Service Controls
C.Cloud NAT
D.Cloud Identity
E.Cloud Armor
AnswersA, D

Identity-Aware Proxy enforces authentication and authorisation at the load balancer layer, verifying user identity before granting access to the backend application. It integrates with external identity providers, satisfying the requirement to restrict access to authenticated corporate Active Directory users.

Why this answer

Identity-Aware Proxy (IAP) [CORRECT] is the right choice because it enforces authentication and authorization at the application layer for HTTPS Load Balancer backends, verifying user identity before any request reaches the web application. Cloud Identity [CORRECT] is also correct because it can federate with the corporate Active Directory (via SAML or secure LDAP), providing the identity source that IAP uses to authenticate and authorize corporate users. Together, IAP and Cloud Identity let the company restrict access to authenticated AD users without exposing the app publicly.

VPC Service Controls is incorrect because it guards GCP API/service perimeters rather than end-user web application authentication. Cloud NAT is incorrect because it provides outbound internet access for private instances, not user authentication. Cloud Armor is incorrect because it provides WAF/DDoS protection and IP-based rules, not identity-based authentication against Active Directory.

Exam trap

PCA often tests the combination of IAP and Cloud Identity for AD-integrated access — candidates may pick Cloud Armor thinking it handles authentication, but Cloud Armor is a WAF, not an identity provider.

30
Multi-Selecthard

A company wants to centrally manage firewall rules for all projects in an organization using hierarchical firewall policies. Which three resources can be used in conjunction with hierarchical firewall policies? (Choose three.)

Select 3 answers
A.Compute Engine instance
B.Organization node
C.Project
D.VPC network
E.Folder
AnswersB, C, E

Hierarchical firewall policies are defined at the organisation node, which is the root of the resource hierarchy. Attaching policy there lets rules cascade to every folder and project beneath it, satisfying the requirement for centralised firewall management across all projects.

Why this answer

Hierarchical firewall policies in Google Cloud are attached at nodes of the resource hierarchy, and the three valid attachment points are the organization node (B), folders (E), and projects (C). Option B is correct because an organization-level policy applies to all resources beneath the organization and serves as the topmost layer of hierarchical firewall rules. Option E is correct because folders sit between the organization and projects, allowing policies to be scoped to a subset of projects within the hierarchy.

Option C is correct because a project-level policy applies to that project's resources and is evaluated after organization and folder policies. Options A and D are not valid attachment points: a Compute Engine instance (A) is a compute resource governed by the policies, not a node where a hierarchical firewall policy is attached, and a VPC network (D) is associated with VPC firewall rules, not hierarchical firewall policies.

Exam trap

PCA often tests the misconception that hierarchical firewall policies can be applied to VPC networks or instances directly, confusing them with VPC firewall rules.

31
MCQhard

A company uses Cloud Armor to protect an HTTPS Load Balancer. They want to allow traffic only from users who have passed a reCAPTCHA challenge. Cloud Armor supports which feature for this?

A.WAF rules with reCAPTCHA
B.Preconfigured WAF rules
C.Adaptive Protection
D.Rate limiting
AnswerA

Cloud Armor's reCAPTCHA integration is configured through WAF rules using the recaptcha action, which challenges or redirects clients to a reCAPTCHA assessment before allowing traffic to the HTTPS Load Balancer. This enforces the requirement that only users passing the challenge reach the backend.

Why this answer

Cloud Armor supports reCAPTCHA integration through WAF rules that use the 'token.recaptcha_session.score' or 'token.recaptcha_action.score' attributes to allow, deny, or redirect traffic based on the reCAPTCHA assessment score. This is configured as a security policy rule with a reCAPTCHA challenge action, enabling the load balancer to enforce human verification before granting access.

Exam trap

PCA often tests whether candidates confuse Cloud Armor's reCAPTCHA enforcement with Adaptive Protection or preconfigured WAF rules; the key is recognizing that only WAF rules with reCAPTCHA token attributes can enforce human verification.

How to eliminate wrong answers

Option B is wrong because preconfigured WAF rules are OWASP ModSecurity-style signatures (e.g., for SQLi, XSS, LFI) and do not perform reCAPTCHA challenges. Option C is wrong because Adaptive Protection uses ML to detect and mitigate Layer 7 DDoS and application attacks; it does not enforce reCAPTCHA verification. Option D is wrong because rate limiting throttles request volume per client (e.g., per IP or header) and cannot verify that a user passed a reCAPTCHA challenge.

32
MCQeasy

An organization wants to ensure that only container images signed by an authorized CI/CD pipeline can be deployed to their GKE clusters. Which GCP service should they use?

A.Artifact Registry
B.Binary Authorization
C.Cloud Security Scanner
D.Cloud Build
AnswerB

Binary Authorization enforces deploy-time attestations, admitting only images whose signatures originate from your authorised CI/CD attestor. This directly satisfies the stem's constraint that solely pipeline-signed container images reach GKE clusters, blocking unsigned or tampered images before admission.

Why this answer

Binary Authorization is the GCP service that enforces deploy-time attestation, ensuring that only container images signed by trusted authorities (such as an authorized CI/CD pipeline) can be deployed to GKE clusters. It uses attestors and attestations created via Container Analysis, and policies can be set to allow only images with valid attestations. This directly satisfies the requirement to restrict deployments to pipeline-signed images.

Exam trap

PCA often tests whether candidates confuse Artifact Registry (storage) with Binary Authorization (admission control); the trap is picking Artifact Registry because it sounds like it controls image provenance, when only Binary Authorization enforces signed-image deployment.

How to eliminate wrong answers

Option A is wrong because Artifact Registry is a container image repository for storing and managing images; it does not enforce deployment admission control or signature verification. Option C is wrong because Cloud Security Scanner (now Web Security Scanner) scans App Engine, Compute, and GKE web apps for vulnerabilities; it does not gate image deployment. Option D is wrong because Cloud Build is a CI/CD service that builds images; while it can sign images, it does not enforce that only signed images are deployed to GKE.

33
MCQmedium

A company wants to restrict network access to Cloud SQL instances such that only applications running in a specific VPC can connect. Which GCP feature should they use?

A.Private Service Connect
B.Private Service Access
C.VPC peering
D.Private Services Access
AnswerB

Private Service Access enables private connectivity to Google-managed services such as Cloud SQL from a VPC using private IP addresses. This is the recommended approach.

Why this answer

Private Service Access (PSA) is the GCP feature that allows private connectivity from a VPC network to Google-managed services like Cloud SQL. It uses VPC peering with the Google-managed service's VPC to enable private IP communication. Private Service Connect, on the other hand, is used for publishing services to consumers, not for consuming services like Cloud SQL.

34
MCQmedium

A company needs to ensure that only applications running in a specific GKE namespace can access a Cloud Storage bucket. Which approach should they use?

A.Use Workload Identity to bind the Kubernetes service account to a GCP service account with appropriate IAM roles
B.Use VPC Service Controls to restrict the bucket to only the GKE cluster's VPC
C.Use firewall rules to allow traffic only from the GKE cluster's pod CIDR
D.Use Cloud Armor to restrict access based on source IP
AnswerA

Workload Identity federates a Kubernetes service account to a Google Cloud service account, so pods in that namespace receive the service account's IAM permissions when accessing Cloud Storage. This satisfies the namespace-scoped constraint, since only workloads using the bound Kubernetes service account obtain the bucket's IAM roles.

Why this answer

Workload Identity allows binding a Kubernetes service account to a GCP service account. Then, IAM can be granted to that GCP service account for the Cloud Storage bucket.

35
MCQhard

A financial services company must store customer data in a GCP region that is certified for FedRAMP High. They also need to ensure that only authorized personnel can access the data, and that access logs are kept for 10 years. Which combination of services meets these requirements?

A.Cloud HSM and Cloud Audit Logs
B.VPC Service Controls with Cloud DLP
C.Cloud KMS with CMEK and Cloud Audit Logs
D.Assured Workloads with Cloud Audit Logs and IAM
AnswerD

Assured Workloads enforces FedRAMP High controls within a compliant GCP region, satisfying the certification constraint. IAM restricts data access to authorised personnel only, while Cloud Audit Logs captures administrative and data-access activity, retained for 10 years via a custom log bucket retention policy. Together they meet all three requirements.

Why this answer

Assured Workloads is the GCP service designed to enforce regulatory compliance frameworks such as FedRAMP High by applying policy controls, restricting data residency to compliant regions, and enforcing personnel access controls (including support access restrictions). Combining it with Cloud Audit Logs (for the 10-year retention requirement via log sinks to a long-term bucket) and IAM (for least-privilege access) directly satisfies all three stated requirements.

Exam trap

The trap here is assuming that encryption services (Cloud KMS, Cloud HSM) or perimeter services (VPC Service Controls) satisfy regulatory compliance requirements — the PCA exam expects candidates to recognize that Assured Workloads is the dedicated service for enforcing compliance frameworks like FedRAMP High, HIPAA, and IL4.

How to eliminate wrong answers

Option A is wrong because Cloud HSM provides FIPS 140-2 Level 3 key protection but does not enforce FedRAMP High data residency or personnel access controls, and Cloud Audit Logs alone does not guarantee 10-year retention without a configured log sink. Option B is wrong because VPC Service Controls provides perimeter security against data exfiltration and Cloud DLP classifies sensitive data, but neither enforces FedRAMP High region certification or personnel access restrictions. Option C is wrong because Cloud KMS with CMEK gives customer-managed encryption keys and Cloud Audit Logs provides logging, but neither addresses FedRAMP High compliance boundaries or the personnel access requirement — CMEK is about key control, not regulatory workload isolation.

36
MCQmedium

A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that pods can only pull container images from a private Artifact Registry repository and that images are scanned for vulnerabilities before deployment. They also want to prevent pods from being scheduled if they use images from public registries. What should they do?

A.Enable Container Analysis API and use an admission controller to block images from public registries.
B.Configure a private GKE cluster and use network policies to block egress to public registries.
C.Use Binary Authorization with a policy that requires attestations from a vulnerability scanner, and configure the GKE cluster to only allow images from the private Artifact Registry.
D.Use Anthos Config Management with a policy that denies pods using public images, and enable vulnerability scanning in Artifact Registry.
AnswerC

Binary Authorization enforces deploy-time policies, such as requiring attestations that images have been scanned. It can also restrict images to specific registries. Configuring the cluster to only allow images from the private registry ensures pods cannot use public images. This combination meets both the scanning and registry restriction requirements.

Why this answer

Binary Authorization is the managed service for enforcing deploy-time policies on GKE, including requiring attestations from vulnerability scanners and restricting images to trusted registries. Configuring the cluster to only allow images from the private Artifact Registry ensures that public images cannot be used. Together, they meet the security requirements.

Exam trap

The trap here is assuming that vulnerability scanning alone prevents deployment of vulnerable images, when enforcement requires Binary Authorization attestations.

37
MCQhard

A company has a VPC Service Perimeter that protects a project containing BigQuery datasets. They want to allow an external customer's BigQuery job to query data across the perimeter boundary using a private connection. Which configuration is required?

A.Remove the project from the service perimeter temporarily.
B.Create an ingress rule in the service perimeter that allows access from the external customer's VPC network.
C.Use Access Transparency to log cross-perimeter access.
D.Grant the external customer's service account the BigQuery User role.
AnswerB

An ingress rule in the VPC Service Perimeter explicitly permits access from the external customer's VPC network, allowing their BigQuery job to cross the perimeter boundary over a private connection while keeping the perimeter enforced for all other traffic.

Why this answer

VPC Service Controls perimeters block access to protected services (like BigQuery) from outside the perimeter by default. To allow an external customer's BigQuery job to query data across the boundary using a private connection, you must create an ingress rule in the service perimeter that specifies the source (the external VPC network or project) and the allowed identities, services, and resources. Ingress rules are the designed mechanism for permitting inbound cross-perimeter access without removing the project from protection.

Exam trap

PCA often tests the distinction between IAM roles and VPC Service Controls, so the trap is assuming that granting an IAM role alone can bypass a service perimeter.

How to eliminate wrong answers

Option A is wrong because removing the project from the perimeter eliminates the protection entirely and is not a targeted, auditable solution — it defeats the purpose of the perimeter. Option C is wrong because Access Transparency logs access by Google personnel, not cross-perimeter customer access, so it does not enable the connection. Option D is wrong because granting the BigQuery User role is an IAM permission, not a perimeter control; IAM alone cannot bypass VPC Service Controls, which operate at a different layer.

38
MCQmedium

A developer wants to store a database password securely and have it automatically rotated every 30 days. The password is used by a Compute Engine instance. Which Google Cloud service should they use?

A.Secret Manager
B.Cloud Storage with customer-supplied encryption keys
C.Cloud Key Management Service (Cloud KMS)
D.Environment variables in Compute Engine
AnswerA

Secret Manager stores credentials as versioned secrets and supports rotation schedules, satisfying the 30-day automatic rotation constraint. Compute Engine instances retrieve the password via the API using their attached service account, so no credential is hard-coded. Rotation creates a new version while the prior version remains accessible, avoiding downtime.

Why this answer

Secret Manager is purpose-built for storing, versioning, and rotating secrets such as database passwords, API keys, and certificates. It supports automatic rotation via Cloud Functions or Pub/Sub triggers on a schedule (e.g., every 30 days), and Compute Engine instances can retrieve secrets at runtime using the Secret Manager API with IAM-controlled access. This directly satisfies both the secure storage and automatic rotation requirements.

Exam trap

The PCA exam often tests the confusion between Cloud KMS (encryption key management) and Secret Manager (application secret storage and rotation) — candidates must recognize that database passwords and API keys belong in Secret Manager, while encryption keys belong in KMS.

How to eliminate wrong answers

Option B is wrong because Cloud Storage with customer-supplied encryption keys stores objects but does not provide secret versioning, rotation, or runtime retrieval APIs designed for credentials — CSEK is about encryption key control, not secret lifecycle management. Option C is wrong because Cloud KMS manages encryption keys (used to encrypt data), not application secrets like passwords; KMS keys can be rotated, but that rotates the encryption key, not the database password itself. Option D is wrong because environment variables in Compute Engine store values in instance metadata or startup scripts in plaintext, are visible to anyone with metadata access, and have no rotation or versioning capability — a well-known anti-pattern for secrets.

39
Multi-Selectmedium

An organization wants to use VPC Service Controls to protect a Cloud Storage bucket and a BigQuery dataset from data exfiltration. They want to allow access from a specific on-premises network via a Cloud VPN. Which TWO components are required? (Choose 2)

Select 2 answers
A.A service perimeter that includes the Cloud Storage bucket and BigQuery dataset
B.An access level that includes the IP range of the on-premises network
C.Cloud Interconnect (Dedicated or Partner)
D.VPC firewall rules allowing traffic from on-premises
E.Private Google Access enabled on the VPC subnet
AnswersA, B

A service perimeter defines the security boundary that encloses both the Cloud Storage bucket and BigQuery dataset, preventing data exfiltration across its edge. Including these resources satisfies the stem's requirement to protect them, since VPC Service Controls only enforces restrictions on services listed within the perimeter's protected resources.

Why this answer

Option A is correct because a service perimeter is the fundamental VPC Service Controls construct that defines the boundary around protected resources; the Cloud Storage bucket and BigQuery dataset must be enclosed within the perimeter for VPC Service Controls to restrict access to them and prevent data exfiltration. Option B is correct because access levels define the conditions under which requests from outside the perimeter are allowed; to permit the specific on-premises network, an access level must include that network's IP range (CIDR), which is then bound to the perimeter via ingress rules. Option C is not required because Cloud VPN already provides the connectivity; Cloud Interconnect is an alternative dedicated/partner connection and is not mandated by VPC Service Controls.

Option D is not required because VPC firewall rules govern VM-level traffic and do not control access to Google APIs protected by VPC Service Controls. Option E is not required because Private Google Access only affects how VMs reach Google APIs internally and is unrelated to authorizing on-premises access through a service perimeter.

Exam trap

The trap is that candidates assume network connectivity components (Cloud VPN, Interconnect, firewall rules) are part of VPC Service Controls, when in fact only the service perimeter and access level are the required logical constructs.

40
MCQhard

A data engineer needs to automatically detect and redact sensitive data such as credit card numbers from text files uploaded to Cloud Storage before the data is loaded into BigQuery. Which GCP service should be used?

A.Cloud Data Loss Prevention (DLP) API
B.Cloud KMS
C.Cloud Audit Logs
D.Cloud Vision API
AnswerA

The Cloud DLP API inspects content using infoType detectors, identifying credit card numbers and other sensitive patterns, then applies de-identification transforms such as redaction. It integrates with Cloud Storage and BigQuery pipelines, so text files can be sanitised before loading, satisfying the automatic detection-and-redaction requirement.

Why this answer

Cloud Data Loss Prevention (DLP) API is purpose-built to discover, classify, and redact sensitive data such as credit card numbers, social security numbers, and other PII from text and structured content. It can be integrated into a pipeline that scans files in Cloud Storage before loading into BigQuery, applying de-identification transformations like masking or tokenization. No other listed service provides sensitive-data detection and redaction capabilities.

Exam trap

The trap is confusing security services: candidates may pick Cloud KMS thinking encryption equals redaction, or Cloud Audit Logs thinking auditing equals data protection; the key is recognizing that only DLP performs content inspection and de-identification.

How to eliminate wrong answers

Option B is wrong because Cloud KMS manages encryption keys and performs cryptographic operations; it does not inspect content for sensitive data patterns or redact them. Option C is wrong because Cloud Audit Logs record administrative and data access activity for auditing; they do not scan or transform data content. Option D is wrong because Cloud Vision API performs image analysis tasks such as label detection and OCR; it is not designed for PII detection or redaction in text files.

41
MCQmedium

A security team needs to detect and redact personally identifiable information (PII) from documents uploaded to Cloud Storage before they are stored. Which GCP service should they use?

A.Cloud Audit Logs
B.Cloud Data Loss Prevention (DLP) API
C.Security Command Center
D.Access Transparency
AnswerB

Cloud DLP API inspects and de-identifies sensitive data such as PII, satisfying the requirement to redact before storage. Its `deidentify` method applies infoType detectors and transformation techniques like masking or tokenisation directly to uploaded content, so documents reach Cloud Storage already sanitised rather than relying on post-storage scanning.

Why this answer

Cloud Data Loss Prevention (DLP) API is purpose-built to inspect, classify, and de-identify sensitive data such as PII, PHI, and credentials. It can scan Cloud Storage objects and apply infoType detectors (e.g., US_SOCIAL_SECURITY_NUMBER, EMAIL_ADDRESS) with redaction, masking, tokenization, or bucketing transforms before the data is persisted. This directly matches the requirement to detect and redact PII prior to storage.

Exam trap

PCA often tests the misconception that Cloud Audit Logs or Security Command Center can inspect and redact data content, when in fact only DLP performs content-level PII detection and de-identification.

How to eliminate wrong answers

Option A is wrong because Cloud Audit Logs only record administrative and data-access activity (who did what, when, where) — they do not inspect content or redact PII. Option C is wrong because Security Command Center aggregates findings and posture data across GCP assets but does not perform content-level PII detection or redaction on uploaded objects. Option D is wrong because Access Transparency provides logs about Google personnel access to customer data, not a data-inspection or redaction engine.

42
MCQmedium

A financial services company runs a regulated workload on Compute Engine in a single project. Auditors require that all data written to persistent disks, including boot disks, is encrypted with keys the company controls and can revoke on demand, without the company operating its own key management infrastructure. The security lead must choose an encryption approach that satisfies this requirement with the least operational overhead. What should the security lead do?

A.Enable Confidential VM on all instances so that memory and disk contents are protected by encryption keys generated and held inside the hardware.
B.Rely on Google-managed encryption keys, which rotate automatically, and use Cloud External Key Manager to wrap the keys after the fact.
C.Configure customer-managed encryption keys (CMEK) in Cloud KMS and set the project-level default key so new persistent disks are encrypted with the company's key.
D.Use customer-supplied encryption keys (CSEK) passed to the Compute Engine API so the company holds the raw key material outside of Google Cloud.
AnswerC

CMEK lets the company own and rotate the key material in Cloud KMS while Google manages the HSM-backed infrastructure. Setting a project-level default key ensures every newly created persistent disk, including boot disks, is encrypted with that key, and disabling or destroying the key version makes the data unreadable, satisfying revocability without the company running its own key infrastructure.

Why this answer

CMEK in Cloud KMS is the correct fit because the company retains ownership and control of the key while Google operates the HSM-backed key infrastructure. Setting a project-level default key ensures new persistent disks and boot disks use the company's key automatically, and disabling a key version immediately makes the data inaccessible, meeting the revocability requirement with minimal operational effort.

Exam trap

The trap here is assuming that Confidential VM or CSEK provides revocable company-controlled disk encryption, when only CMEK with a project default key satisfies both control and low overhead.

43
MCQeasy

Which IAM role should be granted to a user who needs to view but not modify resources in a project?

A.roles/editor
B.roles/viewer
C.roles/owner
D.roles/browser
AnswerB

roles/viewer grants read-only access to all project resources, satisfying the requirement to view without modifying. It excludes write permissions such as create, update or delete, so the user cannot alter resources. This is the most basic predefined role providing the least privilege needed for the stated task.

Why this answer

The roles/viewer role grants read-only access to all resources within a project, allowing the user to view but not modify them. This aligns with the principle of least privilege for a user who only needs to inspect resources. It includes permissions to list and get resources but not to create, update, or delete.

Exam trap

PCA often tests the distinction between primitive roles, and candidates may incorrectly choose roles/browser thinking it provides view access, but it lacks permissions to view resource contents.

How to eliminate wrong answers

Option A is wrong because roles/editor grants read-write access, allowing modification of resources, which exceeds the requirement. Option C is wrong because roles/owner grants full control, including managing access and billing, which is far beyond viewing. Option D is wrong because roles/browser is a basic role that grants read access to browse resources but does not include permissions to view all resource details (e.g., it lacks get permissions on some resource types), so it is not sufficient for viewing all resources in a project.

44
MCQmedium

A data engineer needs to scan a Cloud Storage bucket for personally identifiable information (PII) and de-identify the data before loading it into BigQuery. Which Google Cloud service should they use?

A.Cloud DLP
B.Cloud Dataprep
C.Cloud Composer
D.Cloud Data Fusion
AnswerA

Cloud DLP's infoType detectors scan Cloud Storage objects directly, identifying PII such as names, emails and credit card numbers. Its de-identification transforms — masking, tokenisation, bucketing — then redact or replace those findings before the data lands in BigQuery, satisfying the stem's requirement to de-identify prior to loading.

Why this answer

Cloud DLP (Data Loss Prevention) is the correct service because it is specifically designed to scan, classify, and de-identify sensitive data such as PII. It can inspect data in Cloud Storage and apply de-identification transformations like masking, tokenization, or redaction before loading into BigQuery. This is a core use case for Cloud DLP.

Exam trap

PCA often tests the distinction between data integration and data security services; candidates may choose Cloud Dataprep or Data Fusion for PII tasks, but Cloud DLP is the dedicated service for detection and de-identification.

How to eliminate wrong answers

Option B is wrong because Cloud Dataprep is a data preparation tool for cleaning and transforming data, but it does not have built-in PII detection and de-identification capabilities like Cloud DLP. Option C is wrong because Cloud Composer is a workflow orchestration service (managed Apache Airflow) and does not perform data scanning or de-identification itself. Option D is wrong because Cloud Data Fusion is a data integration service for building ETL pipelines, but it relies on other services like Cloud DLP for PII detection; it is not the primary service for that purpose.

45
MCQmedium

A DevOps engineer needs to grant a CI/CD pipeline (running in a different Google Cloud project) the ability to deploy resources into a target project. The pipeline uses a service account. What is the best way to grant this access?

A.Use VPC peering to allow cross-project access.
B.Use Cloud NAT to enable communication.
C.Add the service account email as a member of the target project with appropriate roles.
D.Create a new service account in the target project and share the key with the pipeline.
AnswerC

Why this answer

Cross-project IAM access in Google Cloud is granted by adding the service account's email as a principal (member) on the target project and binding it to the required roles. IAM is global and project-scoped, so the pipeline's service account in Project A can be granted roles/editor or specific deploy roles in Project B without any network-level configuration. This is the canonical, least-privilege approach for CI/CD cross-project deployments.

Exam trap

PCA often tests the misconception that cross-project access requires network plumbing (VPC peering, Cloud NAT) or a duplicate service account, when IAM principal binding on the target project is the correct and simplest answer.

How to eliminate wrong answers

Option A is wrong because VPC peering only connects network routes between VPCs; it does not grant IAM permissions and is irrelevant to service account authorization. Option B is wrong because Cloud NAT provides outbound internet address translation for private instances and has nothing to do with cross-project IAM access. Option D is wrong because creating a new service account in the target project and sharing its key violates key-management best practices, creates credential sprawl, and is unnecessary when IAM allows direct cross-project principal binding.

46
MCQmedium

A company wants to encrypt data at rest in Cloud Storage using a key that they generate and manage themselves, not stored in Google Cloud. Which encryption type should they use?

A.Default encryption
B.Cloud HSM
C.CSEK
D.CMEK with Cloud KMS
AnswerC

Customer-supplied encryption keys (CSEKs) let you generate and manage the key material yourself; Google Cloud never stores it, satisfying the requirement that the key not reside in Google Cloud. The key is supplied per request and used transiently, unlike CMEK, where key material lives in Cloud KMS.

Why this answer

Customer-Supplied Encryption Keys (CSEK) allow you to provide your own AES-256 key with each Cloud Storage request; Google Cloud uses the key to encrypt/decrypt data but does not store the key. This matches the requirement of a self-generated, self-managed key not stored in Google Cloud. CMEK, by contrast, stores the key in Cloud KMS.

Exam trap

PCA often tests the distinction between CMEK (key stored in Cloud KMS) and CSEK (key supplied per request, never stored by Google) — candidates frequently pick CMEK thinking 'customer-managed' means 'not stored in Google Cloud.'

How to eliminate wrong answers

Option A is wrong because default encryption uses Google-managed keys that Google generates, rotates, and stores — the customer has no control over the key. Option B is wrong because Cloud HSM stores keys in a hardware security module managed by Google Cloud, which contradicts 'not stored in Google Cloud.' Option D is wrong because CMEK with Cloud KMS stores the customer-managed key in Cloud KMS, which is inside Google Cloud — the key is customer-managed but still stored by Google.

47
MCQhard

A company uses Assured Workloads to meet FedRAMP compliance. They need to ensure that only authorized personnel can access data access audit logs for their projects. Which IAM role should they grant to the security team?

A.roles/logging.privateLogViewer
B.roles/logging.viewer
C.roles/iam.securityReviewer
D.roles/logging.admin
AnswerA

roles/logging.privateLogViewer grants access to data access audit logs, which are otherwise restricted to project owners by default. Assigning it to the security team satisfies the FedRAMP requirement that only authorised personnel can read those logs, without granting broader logging permissions.

Why this answer

roles/logging.privateLogViewer grants read access to private logs, which includes Data Access audit logs, and is the least-privilege role designed for viewing sensitive audit data. Data Access logs are classified as private logs in Cloud Logging, so the security team needs a role that explicitly includes logging.privateLogs.view permission. This satisfies the FedRAMP requirement that only authorized personnel can view data access audit logs.

Exam trap

The trap here is confusing roles/logging.viewer with roles/logging.privateLogViewer — candidates assume 'viewer' covers all logs, but Data Access audit logs require the privateLogViewer role specifically.

How to eliminate wrong answers

Option B is wrong because roles/logging.viewer grants access to _Default and _Required log buckets but explicitly excludes private logs such as Data Access audit logs. Option C is wrong because roles/iam.securityReviewer only allows viewing IAM policies and roles; it does not grant any log-reading permissions. Option D is wrong because roles/logging.admin grants full administrative control over logging (creating sinks, deleting logs, managing exclusions), which violates least privilege for a team that only needs to read audit logs.

48
MCQmedium

A company wants to enforce that all API calls to GCP services from outside their corporate network come through a specific Cloud VPN tunnel. Which GCP service can enforce this policy?

A.VPC Service Controls
B.Cloud NAT
C.Identity-Aware Proxy
D.Cloud Armor
AnswerA

VPC Service Controls creates a service perimeter that restricts API access to authorised networks, so requests from outside the corporate network are denied unless they traverse the specified Cloud VPN tunnel. This satisfies the stem's requirement to enforce tunnel-only access to GCP service APIs.

Why this answer

VPC Service Controls lets you define a service perimeter around GCP resources (such as Cloud Storage, BigQuery, and APIs) and restrict access so that requests must originate from within an authorized network — including a specific Cloud VPN tunnel or VPC network. By configuring an access level based on the VPN tunnel's source IP range or network, you can enforce that API calls to protected services from outside the corporate network are denied unless they traverse the specified VPN.

Exam trap

PCA often tests the distinction between network-layer controls (firewall, Cloud NAT) and service-perimeter controls (VPC Service Controls), catching candidates who pick Cloud NAT or Cloud Armor for API access enforcement.

How to eliminate wrong answers

Option B is wrong because Cloud NAT provides outbound internet connectivity for private instances — it does not enforce access policies on inbound API calls. Option C is wrong because Identity-Aware Proxy controls access to web applications and VMs based on identity, not network path enforcement for API calls to GCP services. Option D is wrong because Cloud Armor protects against DDoS and web attacks at the edge (HTTP/S load balancer level) and does not enforce service-level API access based on network origin.

49
MCQhard

A multinational corporation needs to ensure that data stored in Cloud Storage buckets in their Google Cloud organization cannot be accessed from outside their corporate network, even if IAM policies are misconfigured. They want to enforce this at the organization level with minimal administrative overhead. What should they do?

A.Create a VPC Service Controls perimeter that includes the Cloud Storage service and the projects containing the buckets, and configure access levels to allow only corporate IP ranges.
B.Enable Cloud Armor security policies on all Cloud Storage buckets to block external IPs.
C.Use IAM Conditions on all Cloud Storage IAM bindings to allow access only from corporate IP ranges.
D.Apply an organization policy constraint `storage.publicAccessPrevention` to all buckets.
AnswerA

VPC Service Controls create a security perimeter around Google Cloud services, preventing data exfiltration even if IAM is misconfigured. By including Cloud Storage and configuring access levels based on corporate IP ranges, access from outside the network is blocked. This is enforced at the organization level and requires minimal per-project configuration, meeting the requirement for centralized control.

Why this answer

VPC Service Controls provide a centralized, organization-level security perimeter that prevents access to Cloud Storage from outside authorized networks, even if IAM policies are misconfigured. By defining access levels based on corporate IP ranges, the organization can ensure that only requests from the corporate network are allowed. This is the most effective and least administrative approach compared to per-binding IAM Conditions or bucket-level constraints.

Exam trap

The trap here is assuming that IAM Conditions or public access prevention alone can enforce network-based access control at scale.

50
MCQhard

A healthcare company runs a multi-tenant SaaS platform on Google Cloud. Each tenant has a dedicated folder inside a single organization, with projects for each environment. A recent audit found that a compromised service account in one tenant's dev project could enumerate and read Cloud Storage buckets belonging to other tenants because the service account had been granted roles/storage.admin at the organization level by mistake. The security team wants a preventive control that blocks any future IAM binding that grants a role to a principal at a scope broader than a single project, unless the principal is part of a small break-glass group. They also want the control to apply automatically to all new projects. What should the architect implement?

A.Create an organization policy with the iam.allowedPolicyMemberDomains constraint set to the company's Cloud Identity domain, and apply it to the organization node.
B.Enable IAM Conditions on all role bindings and require a condition that the resource name matches the tenant's folder path.
C.Create an organization policy with the iam.disablePolicyMemberDomainCheck constraint and apply it to the organization node.
D.Configure an organization policy using a custom constraint on the iam.googleapis.com/AllowPolicy resource, denying bindings where the resource scope is the organization or a folder unless the principal is in the break-glass group.
AnswerD

Custom organization policy constraints can evaluate IAM allow policies and deny bindings based on the resource hierarchy level and the principal. By scoping the constraint to the organization node it is inherited by all current and future projects and folders, blocking the exact misconfiguration that allowed the compromised service account to reach other tenants' buckets while permitting the break-glass group.

Why this answer

The requirement is a preventive, hierarchy-wide guardrail against overly broad IAM grants. Custom organization policy constraints on the IAM allow policy resource can inspect both the binding's scope and the principal, so a rule that denies organization- and folder-level grants except for a designated break-glass group enforces least privilege automatically for existing and new projects. Domain-based and condition-based approaches either do not address scope breadth or rely on per-binding correctness, so they would not have prevented the audit finding.

Exam trap

The trap here is assuming that iam.allowedPolicyMemberDomains or IAM Conditions provide preventive scope guardrails, when domain constraints only limit identity domains and conditions must be attached correctly to every binding.

51
Multi-Selecthard

A healthcare organization is designing a Google Cloud environment to comply with HIPAA. They need to ensure that all access to sensitive data is logged and that only authorized personnel can access it. They plan to use Cloud Audit Logs and IAM. Which two configurations should they implement? (Choose two.)

Select 2 answers
A.Set the organization policy constraint `iam.disableServiceAccountKeyCreation` to prevent key leakage.
B.Enable Data Access audit logs for all services that store or process ePHI.
C.Enable VPC Service Controls to create a service perimeter around the project containing ePHI.
D.Use IAM Conditions to restrict access to sensitive data based on IP address and device type.
E.Grant the `roles/iam.securityReviewer` role to all employees who need to view audit logs.
AnswersB, D

Data Access audit logs record read and write operations on user data, which is essential for HIPAA compliance to track who accessed ePHI. By default, these logs are disabled for most services, so explicitly enabling them for services like Cloud Storage, BigQuery, and Cloud SQL ensures a complete audit trail. This helps detect unauthorized access and supports forensic investigations, meeting the logging requirement.

Why this answer

Enabling Data Access audit logs ensures that all access to ePHI is recorded, which is a HIPAA requirement. Using IAM Conditions restricts access based on context, ensuring only authorized personnel from trusted environments can access data. Together, these provide both logging and access control.

The other options either over-provision access or address different security concerns not directly tied to the stated needs.

Exam trap

The trap here is assuming that enabling any audit logs by default is sufficient, or that broad roles like securityReviewer are acceptable for compliance.

52
MCQmedium

A company wants to use Customer-Managed Encryption Keys (CMEK) for data at rest in Cloud Storage, but also needs to ensure that the keys are stored in a hardware security module (HSM) to meet compliance requirements. Which Cloud KMS key type should they choose?

A.Predefined key
B.External key (Cloud External Key Manager)
C.Software-backed key
D.Cloud HSM key
AnswerD

Cloud HSM keys store key material in FIPS 140-2 Level 3 validated hardware security modules, satisfying the compliance requirement for HSM-backed keys. Software and Cloud KMS keys hold material in software, so they fail that constraint. CMEK for Cloud Storage accepts Cloud HSM keys directly.

Why this answer

Cloud HSM keys in Cloud KMS are backed by a FIPS 140-2 Level 3 validated hardware security module, satisfying compliance requirements that mandate HSM-backed key storage. This is the only Cloud KMS key type that provides hardware-backed protection while remaining fully managed within Google Cloud.

Exam trap

PCA often tests the CMEK key-type hierarchy — candidates confuse Cloud EKM (external, sovereignty-focused) with Cloud HSM (hardware-backed, in-GCP), or pick software keys assuming all KMS keys are equally secure.

How to eliminate wrong answers

Option A is wrong because 'predefined key' is not a Cloud KMS key type — it is a distractor term; Cloud KMS offers software, HSM, and external key types. Option B is wrong because Cloud External Key Manager (Cloud EKM) stores keys outside Google Cloud in a third-party KMS (e.g., Thales, Fortanix), which is for sovereignty requirements, not for HSM-backed keys within GCP. Option C is wrong because software-backed keys are stored in software and do not meet HSM compliance mandates.

53
MCQhard

A company with multiple projects must ensure that no data can be exfiltrated from a specific project's Cloud Storage buckets to unauthorized locations outside the organization. They also need to allow access only from a corporate VPN IP range. Which configuration meets these requirements?

A.Configure a VPC Service Controls perimeter with an access level restricted to the corporate VPN IP range.
B.Set firewall rules to block all traffic except from the VPN.
C.Use IAM conditions to restrict access based on IP address.
D.Use Cloud Armor with IP whitelisting.
AnswerA

VPC Service Controls perimeters block data exfiltration from Cloud Storage by restricting access to resources inside the perimeter, and the access level limits entry to the corporate VPN IP range. This satisfies both the exfiltration prevention and VPN-only access constraints.

Why this answer

VPC Service Controls creates a security perimeter around Google Cloud services (including Cloud Storage) that prevents data exfiltration by blocking access from outside the perimeter, even if IAM permissions would otherwise allow it. Access levels within the perimeter can be restricted to specific IP ranges (such as the corporate VPN CIDR), so only requests originating from those IPs can reach the protected resources. This combination of perimeter + access level directly satisfies both requirements: preventing exfiltration to unauthorized locations and limiting access to the VPN range.

Exam trap

The trap here is confusing network-level controls (firewall rules, Cloud Armor) with service-level data exfiltration prevention; candidates often pick firewall rules because they think of 'blocking traffic,' but VPC Service Controls is the only option that creates a data boundary for managed services like Cloud Storage.

How to eliminate wrong answers

Option B is wrong because VPC firewall rules only control traffic to and from VM instances within a VPC; they do not govern access to managed services like Cloud Storage, which are accessed via Google's APIs outside the VPC data path. Option C is wrong because IAM conditions with IP-based restrictions can limit who can call an API from a given IP, but they do not create a data exfiltration boundary — a user with valid credentials and permissions from an allowed IP could still copy data to an external bucket or project. Option D is wrong because Cloud Armor protects HTTP(S) load-balanced applications from web attacks and provides IP allow/deny at the edge, not access control for Cloud Storage APIs or data exfiltration prevention.

54
MCQeasy

A company wants to protect their web application hosted on Google Cloud HTTP(S) Load Balancer from common web attacks like SQL injection and cross-site scripting (XSS). Which GCP service should they use?

A.Identity-Aware Proxy (IAP)
B.Cloud CDN
C.VPC Service Controls
D.Cloud Armor
AnswerD

Cloud Armor provides edge security policies on the HTTP(S) load balancer, with preconfigured WAF rules that block SQL injection and XSS at layer 7. It satisfies the requirement to filter common web attacks before traffic reaches the backend application.

Why this answer

Cloud Armor provides WAF (Web Application Firewall) capabilities including preconfigured rules to block OWASP Top 10 attacks like SQL injection and XSS. IAP is for access control, not attack prevention. VPC Service Controls are for data exfiltration prevention.

Cloud CDN is for caching content.

55
MCQmedium

A company wants to use their existing Active Directory for authentication to Google Cloud. They need to sync user and group identities to Cloud Identity and allow users to log in with their corporate credentials. Which two services should they use together?

A.Cloud Directory Sync and Workload Identity
B.Cloud Directory Sync and SAML SSO
C.SAML SSO and IAP
D.Cloud Identity and IAP
AnswerB

Cloud Directory Sync provisions users and groups from Active Directory into Cloud Identity, keeping identities aligned. SAML SSO then federates authentication so users sign in with corporate credentials, satisfying both the sync requirement and the existing-AD login constraint without duplicating passwords.

Why this answer

Cloud Directory Sync (CDS) syncs users and groups from LDAP/AD to Cloud Identity. SAML SSO allows users to authenticate using their corporate credentials. IAP is for application access, not directory sync.

Cloud Identity as a standalone does not sync automatically. Workload Identity is for Kubernetes.

56
MCQmedium

A security engineer wants to configure Identity-Aware Proxy (IAP) for an HTTPS load-balanced application to enforce zero-trust access. Users will authenticate with their Google accounts. What is the minimum set of IAM roles needed for a user to access the application behind IAP?

A.roles/iam.serviceAccountUser
B.roles/iap.tunnelResourceAccessor
C.roles/iap.httpsResourceAccessor
D.roles/compute.viewer
AnswerC

roles/iap.httpsResourceAccessor grants a principal the ability to reach an IAP-protected HTTPS resource, satisfying the minimum-access requirement. It is the sole role needed for end users; roles/iap.admin and related roles govern configuration, not access, so they are unnecessary here.

Why this answer

To access an application protected by IAP over HTTPS, a user must have the IAP-secured Web App User role (roles/iap.httpsResourceAccessor) on the resource. This role grants permission to access the resource through IAP. The other roles are not sufficient: roles/iam.serviceAccountUser is for managing service accounts, roles/iap.tunnelResourceAccessor is for TCP forwarding, and roles/compute.viewer only allows viewing Compute Engine resources, not accessing the application.

57
MCQmedium

A healthcare company stores sensitive patient data in Cloud Storage. They must ensure that data is encrypted at rest with a key that they manage, and that the key is automatically rotated every 90 days. They also need to be able to audit key usage. Which approach should they take?

A.Use a Cloud HSM key with a rotation period of 90 days, and configure the bucket with a retention policy that enforces encryption.
B.Use Customer-Supplied Encryption Keys (CSEK) with a 90-day rotation managed by the application, and enable Cloud Audit Logs for Cloud Storage.
C.Create a Cloud KMS key with a rotation period of 90 days, grant the Cloud Storage service account encrypt/decrypt permissions on the key, and configure the bucket to use that key as the default encryption key.
D.Create a Cloud KMS key with a rotation period of 90 days, and use an organization policy constraint to require CMEK on all Cloud Storage buckets.
AnswerC

Cloud KMS supports automatic key rotation, which can be set to 90 days. Granting the Cloud Storage service account permissions on the key allows the bucket to use it for encryption. Setting the bucket default key ensures all objects are encrypted with the CMEK. Cloud KMS audit logs capture key usage, meeting the auditing requirement.

Why this answer

Cloud KMS provides automatic key rotation and audit logging. By setting a bucket default key, all objects are encrypted with the CMEK. Granting the Cloud Storage service account encrypt/decrypt permissions is required for the bucket to use the key.

This approach meets encryption, rotation, and auditing requirements with minimal overhead.

Exam trap

The trap here is assuming that organization policy constraints automatically apply a specific CMEK, when they only enforce that some CMEK is used.

58
MCQhard

A company is deploying a multi-tenant SaaS application on GKE. Each tenant's data must be isolated at the network level. They want to use a single GKE cluster but ensure that pods from different tenants cannot communicate with each other. Which GCP feature should they use?

A.Istio service mesh
B.VPC Service Controls
C.Kubernetes Network Policies
D.GKE Sandbox
AnswerC

Kubernetes Network Policies are pod-level firewall rules applied within a single cluster, selecting pods by label and restricting ingress and egress. This isolates each tenant's pods so cross-tenant traffic is denied, meeting the network-level isolation constraint without separate clusters.

Why this answer

Kubernetes Network Policies are the native Kubernetes feature that allows you to define rules controlling traffic between pods. By creating NetworkPolicy resources that select pods based on labels (e.g., tenant labels), you can isolate tenants so that pods from different tenants cannot communicate with each other. This provides network-level isolation within a single GKE cluster.

Exam trap

The trap is confusing network isolation with other GKE features like GKE Sandbox (which isolates workloads at the kernel level) or Istio (which provides service mesh capabilities). The question specifically asks for network-level isolation between pods, which is achieved with Kubernetes Network Policies.

How to eliminate wrong answers

Option A is wrong because Istio service mesh provides traffic management, security, and observability, but it is not the primary mechanism for network isolation; it can enforce policies but requires additional configuration and is not the native Kubernetes feature for pod-level network isolation. Option B is wrong because VPC Service Controls is designed to protect Google Cloud managed services (like Cloud Storage, BigQuery) from data exfiltration, not to isolate pod-to-pod communication within a GKE cluster. Option D is wrong because GKE Sandbox provides an additional layer of isolation between the container and the host kernel using gVisor, but it does not control network communication between pods; it is for workload isolation, not network segmentation.

59
MCQhard

A company uses Cloud KMS with CMEK to encrypt data stored in BigQuery. They need to audit who has used the encryption key and when. Which type of audit log should they enable?

A.Network Security audit logs
B.Admin Activity audit logs
C.System Event audit logs
D.Data Access audit logs
AnswerD

Data Access audit logs record every read, write, and cryptographic operation against BigQuery data, including Cloud KMS key usage for CMEK decryption. Admin Activity logs only capture configuration changes, not key use. Enabling Data Access logging therefore reveals who used the key and when, satisfying the audit requirement.

Why this answer

Data Access audit logs record API calls that read or modify user data, including calls to Cloud KMS for encryption and decryption operations. To audit who used a CMEK key and when, you need Data Access audit logs for Cloud KMS, as these logs capture key usage events such as Encrypt, Decrypt, and GenerateDataKey. Admin Activity logs only record changes to resource configurations, not data access.

Exam trap

The trap is assuming Admin Activity logs capture key usage because they are always on and record administrative actions; however, key usage (encrypt/decrypt) is a data access operation, so Data Access logs are required.

How to eliminate wrong answers

Option A is wrong because Network Security audit logs are not a standard audit log type in Google Cloud; audit logs are categorized as Admin Activity, Data Access, System Event, and Policy Denied. Option B is wrong because Admin Activity audit logs record operations that modify the configuration or metadata of resources (e.g., creating a key, changing IAM policies), but they do not capture data access operations like using a key to encrypt or decrypt data. Option C is wrong because System Event audit logs record Google Cloud administrative actions that modify resources, not user-initiated data access.

60
MCQmedium

A company runs a public-facing web application on Compute Engine instances behind an external HTTP(S) load balancer. They want to protect the application from common web attacks such as SQL injection and cross-site scripting, and they also want to restrict access to known IP ranges. Which Google Cloud service should they use?

A.VPC firewall rules to allow only specific IP ranges and block malicious traffic.
B.Cloud CDN with signed URLs to restrict access and cache content.
C.Cloud Armor security policy with preconfigured WAF rules and IP allowlist rules.
D.Identity-Aware Proxy (IAP) to authenticate users and enforce access policies.
AnswerC

Cloud Armor provides WAF capabilities with preconfigured rules for OWASP Top 10 threats like SQL injection and XSS, and it supports IP allowlist/denylist rules. It integrates with external HTTP(S) load balancers to filter traffic at the edge. This directly meets both requirements: protecting against web attacks and restricting access by IP. It is the native Google Cloud solution for this scenario.

Why this answer

Cloud Armor is the correct choice because it provides both WAF protection against common web attacks and IP-based access control. It is designed to work with external HTTP(S) load balancers, making it the appropriate service for securing a public web application. The other options either lack WAF capabilities or are intended for different use cases such as performance or identity-based access.

Exam trap

The trap here is confusing network-layer firewall rules with application-layer WAF, or assuming IAP provides WAF protection.

61
Multi-Selectmedium

A company wants to implement a zero-trust access model for internal web applications running on Compute Engine. They need to authenticate users using corporate credentials and enforce context-aware access based on device posture and IP address. Which TWO services should they use?

Select 2 answers
A.VPC Service Controls
B.Cloud VPN
C.Cloud Identity
D.Cloud Armor
E.Identity-Aware Proxy (IAP)
AnswersC, E

Cloud Identity provides the corporate credential directory and user authentication, which IAP then consumes to verify identity. It supplies the identity plane needed for zero-trust access to the Compute Engine applications, satisfying the corporate credentials requirement.

Why this answer

Cloud Identity (C) is correct because it provides the identity provider and user/group management that lets the company authenticate users with their corporate credentials, which is the foundation of a zero-trust identity model. Identity-Aware Proxy (IAP) (E) is correct because it enforces context-aware access to internal web applications on Compute Engine, evaluating user identity plus device posture and IP address before granting access, exactly matching the scenario's requirements. VPC Service Controls (A) is not correct here because it protects Google Cloud APIs and services at the perimeter level rather than authenticating users to internal web apps.

Cloud VPN (B) only provides encrypted network connectivity and does not perform user authentication or context-aware access control. Cloud Armor (D) is a WAF/DDoS protection service that filters traffic at the edge but does not authenticate users or enforce device-posture-based access.

Exam trap

PCA often tests... the components of zero-trust architecture, and candidates might confuse IAP with Cloud Armor or VPC Service Controls, which serve different purposes.

62
Multi-Selecthard

An organization needs to comply with FedRAMP requirements and restrict data storage to specific regions. They also need to audit all admin activities and data access. Which three components should they implement? (Choose three.)

Select 3 answers
A.VPC Service Controls
B.Data Access audit logs
C.Cloud Armor
D.Admin Activity audit logs
E.Assured Workloads
AnswersB, D, E

Data Access audit logs record every read and write against stored data, satisfying the stem's requirement to audit all data access. Unlike Admin Activity logs, which capture only configuration changes, these logs provide the per-object visibility FedRAMP auditors demand for demonstrating continuous monitoring of regulated data.

Why this answer

Assured Workloads (E) is correct because it is the Google Cloud service specifically designed to enforce regulatory compliance frameworks such as FedRAMP and to restrict data storage and processing to specific regions through its compliance controls. Admin Activity audit logs (D) are correct because they record all administrative and configuration changes made to resources, which is required to audit all admin activities. Data Access audit logs (B) are correct because they capture read and write operations on user data, satisfying the requirement to audit all data access.

VPC Service Controls (A) is not selected because, while it provides service perimeter security to mitigate data exfiltration, it does not itself enforce FedRAMP compliance or regional data residency. Cloud Armor (C) is not selected because it is a WAF/DDoS protection service for external HTTP(S) load balancers and does not address compliance, data residency, or audit logging requirements.

63
Multi-Selectmedium

A healthcare company stores protected health information in Cloud Storage and BigQuery. Compliance requires that access to this data be auditable and that no single administrator can both modify data and erase the audit trail. The security architect is designing the logging and access model. Which two actions should the architect take? (Choose two.)

Select 2 answers
A.Use BigQuery row-level security to restrict which rows each analyst can read, and rely on that as the sole audit mechanism for PHI access.
B.Grant project owners the Logging Admin role so they can manage log sinks and adjust retention as operational needs change.
C.Create a dedicated log bucket with a locked retention policy and grant the security team roles/logging.viewer on it while removing Logging Admin from data project owners.
D.Enable Cloud Audit Logs Data Access logs for Cloud Storage and BigQuery and route them to a log bucket in a separate project with a locked retention policy.
E.Store audit logs in the same Cloud Storage bucket as the PHI so that access reviews cover both data and logs in a single IAM policy.
AnswersC, D

A locked retention policy on a dedicated log bucket prevents deletion or modification of logs for the retention period, even by project owners, which enforces immutability. Granting the security team only Logging Viewer separates audit review from data administration, ensuring no single admin controls both data changes and the audit record.

Why this answer

Auditability and separation of duties require capturing Data Access logs for the services holding PHI and storing them where data administrators cannot alter them. Routing logs to a separate project's log bucket with a locked retention policy makes the trail immutable, and limiting the security team to Logging Viewer while removing Logging Admin from data owners ensures no single person can both change data and erase the evidence.

Exam trap

The trap here is treating log retention as a routine operational setting that project owners should manage, when locked retention and role separation are what actually prevent an administrator from erasing the audit trail.

64
MCQmedium

A company wants to enforce that all secrets used by applications running on Compute Engine are rotated automatically every 30 days. Which GCP service should they use to store and manage these secrets?

A.Cloud Key Management Service with CMEK
B.Secret Manager
C.Environment variables
D.Cloud KMS
AnswerB

Secret Manager stores application secrets and supports automatic rotation schedules, meeting the 30-day rotation requirement. Compute Engine workloads retrieve secrets via the API or client libraries, so credentials are never hard-coded, and rotation happens centrally without redeploying applications.

Why this answer

Google Cloud Secret Manager is purpose-built for storing, versioning, and rotating secrets such as API keys, passwords, and certificates. It supports automatic rotation via Pub/Sub notifications and Cloud Functions/Cloud Run, and it integrates natively with Compute Engine workloads through IAM and the Secret Manager API. Cloud KMS, by contrast, manages encryption keys, not application secrets.

Exam trap

PCA often tests the confusion between Cloud KMS (encryption keys) and Secret Manager (application secrets) — candidates must distinguish 'managing keys that encrypt data' from 'storing and rotating credentials.'

How to eliminate wrong answers

Option A is wrong because Cloud KMS with CMEK manages customer-managed encryption keys used to encrypt data at rest — it does not store or rotate application secrets like database passwords. Option C is wrong because environment variables are a delivery mechanism, not a secret store; they are visible in process listings, lack versioning, auditing, and rotation, and are explicitly discouraged for secrets by Google's best practices. Option D is wrong because Cloud KMS is a key management service for cryptographic keys (symmetric/asymmetric), not a secret vault — it cannot store arbitrary secret payloads or rotate them on a 30-day schedule.

65
MCQeasy

A startup runs a public API on Compute Engine behind an external HTTP(S) load balancer. The security team wants to block common web attacks such as SQL injection and cross-site scripting at the edge, with minimal changes to the application, and they want the protection rules to be managed centrally and updated as new signatures are released. What should the architect recommend?

A.Enable Identity-Aware Proxy on the backend service and require Google account authentication for all API calls.
B.Install a third-party WAF on each Compute Engine instance and configure it to read request bodies before the application does.
C.Deploy Cloud Armor security policies with preconfigured WAF rules and attach the policy to the backend service of the external HTTP(S) load balancer.
D.Create VPC firewall rules that deny traffic containing suspicious URL patterns to the load balancer's forwarding rule.
AnswerC

Cloud Armor attaches to the backend service of an external HTTP(S) load balancer and offers preconfigured WAF rules based on the ModSecurity core rule set, covering SQL injection and cross-site scripting. Google maintains and updates the signatures, so the startup gets edge protection without modifying application code, matching the centralized management requirement.

Why this answer

Cloud Armor is Google Cloud's edge security service that attaches to external HTTP(S) load balancer backend services. Its preconfigured WAF rules, derived from the ModSecurity core rule set, detect and block SQL injection, cross-site scripting, and other OWASP-style attacks. Because Google manages the rule signatures and policies are configured once at the load balancer, the application needs no changes and protection is centralized.

Exam trap

The trap here is confusing identity-based access control or network firewall rules with application-layer attack filtering, which only Cloud Armor performs at the load balancer edge.

66
MCQeasy

Which Google Cloud service allows organizations to define perimeters that protect resources and data from exfiltration to other VPCs or networks?

A.Private Service Connect
B.Identity-Aware Proxy (IAP)
C.Cloud Armor
D.VPC Service Controls
AnswerD

VPC Service Controls define service perimeters that restrict access to Google Cloud resources, preventing data exfiltration across project, VPC or network boundaries. This directly satisfies the requirement to protect resources and data from unauthorised movement to other VPCs or networks.

Why this answer

VPC Service Controls lets organizations define service perimeters that restrict access to Google Cloud services and prevent data exfiltration across project, VPC, or network boundaries. It enforces context-aware access at the API level, blocking operations that would move data outside the perimeter even if IAM would otherwise allow them. This is exactly the 'protect resources and data from exfiltration to other VPCs or networks' requirement.

Exam trap

PCA often tests the confusion between network-level controls (Private Service Connect, Cloud Armor) and API-level data-exfiltration controls (VPC Service Controls) — the key discriminator is whether the question mentions preventing data movement across boundaries.

How to eliminate wrong answers

Option A is wrong because Private Service Connect provides private connectivity to Google APIs and third-party services via internal IPs — it controls how traffic reaches services, not whether data can be exfiltrated across perimeters. Option B is wrong because Identity-Aware Proxy (IAP) controls user access to web applications and VMs based on identity and context, but it does not define data-exfiltration perimeters around GCP services. Option C is wrong because Cloud Armor is a WAF/DDoS protection service that filters HTTP(S) traffic at the edge — it protects against attacks, not against data exfiltration between projects or VPCs.

67
MCQmedium

A security admin wants to audit all 'create' and 'delete' operations on Compute Engine instances in a project for the last 90 days. Which type of audit log should they query?

A.Data Access audit logs
B.Admin Activity audit logs
C.System Event audit logs
D.Policy Denied audit logs
AnswerB

Admin Activity audit logs capture permanent metadata writes such as instance creation and deletion, and are always enabled with 400-day retention, satisfying the 90-day requirement. Data Access logs record reads and are disabled by default, so they cannot reliably supply this Compute Engine administrative history.

Why this answer

Admin Activity audit logs record all write operations (create, update, delete) on project resources, including Compute Engine instances, and are always enabled with a 400-day retention. Querying Admin Activity logs for the last 90 days will show all create and delete operations on instances. Data Access logs, by contrast, record read operations and are disabled by default.

Exam trap

The trap is conflating Admin Activity with Data Access logs; candidates may think Data Access logs capture all operations, but they only capture reads and are off by default, while Admin Activity logs capture writes and are always on.

How to eliminate wrong answers

Option A is wrong because Data Access audit logs record read operations (e.g., get, list) and are not enabled by default; they would not capture create/delete operations. Option C is wrong because System Event audit logs record Google-initiated system events like live migration or maintenance, not user-initiated create/delete operations. Option D is wrong because Policy Denied audit logs record when a request is denied by a security policy (e.g., VPC Service Controls), which is not the same as auditing successful create/delete operations.

68
MCQmedium

A company needs to protect an HTTPS load-balanced web application from OWASP Top 10 attacks, including SQL injection and cross-site scripting. Which GCP service should they enable?

A.Cloud NAT
B.Cloud CDN
C.Identity-Aware Proxy
D.Cloud Armor
AnswerD

Cloud Armor provides web application firewall filtering at the load balancer, inspecting HTTP traffic to block SQL injection and cross-site scripting. This satisfies the requirement to defend the HTTPS application against OWASP Top 10 attacks.

Why this answer

Cloud Armor is Google Cloud's web application firewall (WAF) and DDoS protection service that provides protection against OWASP Top 10 attacks, including SQL injection and cross-site scripting. It integrates with external HTTP(S) load balancers to filter malicious traffic at the edge. Enabling Cloud Armor security policies allows you to block or allow requests based on preconfigured WAF rules.

Exam trap

The trap is confusing Cloud Armor with other GCP services like Cloud CDN or IAP, which serve different purposes (content delivery and access control, respectively).

How to eliminate wrong answers

Option A is wrong because Cloud NAT is a network address translation service for outbound internet access, not for protecting inbound web traffic. Option B is wrong because Cloud CDN is a content delivery network that caches content at edge locations, but it does not provide WAF capabilities. Option C is wrong because Identity-Aware Proxy (IAP) provides authentication and authorization for applications, but it does not protect against OWASP Top 10 attacks like SQL injection or XSS.

69
MCQhard

A financial services company runs workloads on GKE and wants to ensure only container images that have been approved by the security team can be deployed. The approval process involves signing images after vulnerability scanning. Which GCP service should be integrated with GKE to enforce this policy?

A.Cloud Key Management Service (Cloud KMS)
B.Cloud Build
C.Artifact Registry
D.Binary Authorization
AnswerD

Binary Authorization enforces deploy-time admission control on GKE by verifying cryptographic signatures (attestations) created after vulnerability scanning, blocking any image lacking a valid attestor signature. This directly satisfies the stem's requirement that only security-team-approved, signed images reach the cluster, rather than merely scanning or storing them.

Why this answer

Binary Authorization is a GCP service that enforces deploy-time security policies on GKE clusters. It ensures that only container images that have been signed by trusted authorities (after vulnerability scanning) are deployed. By integrating Binary Authorization with GKE, the company can enforce that only approved images are deployed.

Exam trap

PCA often tests the distinction between services that build, store, and enforce policies on container images; candidates may confuse Artifact Registry (storage) with Binary Authorization (enforcement), but Binary Authorization is specifically for deploy-time policy enforcement.

How to eliminate wrong answers

Option A is wrong because Cloud KMS is a key management service used to create and manage cryptographic keys, but it does not enforce deployment policies on GKE. Option B is wrong because Cloud Build is a CI/CD service that can build and test images, but it does not enforce deployment admission control. Option C is wrong because Artifact Registry is a repository for container images, but it does not enforce that only signed images are deployed; it can store images but not control deployment.

70
MCQhard

A financial services company stores regulated data in BigQuery datasets. Auditors require that all data access be logged with the identity of the user, the query text, and the timestamp, and that logs be retained for 365 days and be immutable. The security team wants to use Google Cloud-native tools with minimal operational overhead. What should they implement?

A.Enable BigQuery Data Access audit logs in Cloud Audit Logs, then create a log sink to a Cloud Storage bucket with a 365-day retention policy and a Bucket Lock.
B.Enable BigQuery Data Access audit logs and configure a log sink to a BigQuery dataset with a 365-day partition expiration and table-level IAM restrictions.
C.Use BigQuery's INFORMATION_SCHEMA.JOBS_BY_PROJECT view to query historical job metadata, and export results to Cloud Storage on a daily schedule via a Cloud Scheduler job.
D.Enable VPC Service Controls for BigQuery and configure access levels that log all API calls to Cloud Logging with a 365-day retention period.
AnswerA

BigQuery Data Access audit logs capture the identity, query text, and timestamp for data access. Sinking them to a Cloud Storage bucket with a retention policy and Bucket Lock makes the logs immutable for the required period. This uses native Cloud Audit Logs and Cloud Storage features with minimal operational overhead, meeting all auditor requirements.

Why this answer

BigQuery Data Access audit logs provide the required identity, query text, and timestamp for every data access. Routing them through a log sink to a Cloud Storage bucket with a retention policy and Bucket Lock ensures immutability for 365 days. This combination uses native Google Cloud services and requires no custom code or third-party tooling, minimizing operational overhead.

Exam trap

The trap here is confusing BigQuery INFORMATION_SCHEMA job history or VPC Service Controls logs with Cloud Audit Logs, which are the only native source that captures full Data Access audit records with query text.

71
MCQhard

A multinational corporation needs to comply with data residency requirements for EU customer data. They want to ensure that data stored in Cloud Storage, BigQuery, and Cloud SQL for EU customers never leaves the European Union, even by administrators. They also want to detect and remediate any configuration drift that could violate this policy. What should they implement?

A.Deploy all workloads in EU regions and use a custom Terraform module that validates region parameters before deployment.
B.Create an organization policy constraint 'constraints/gcp.resourceLocations' with allowed values set to EU regions, and apply it at the organization level. Use Security Command Center to monitor for violations.
C.Configure VPC Service Controls perimeters around EU projects and use Access Context Manager to restrict access to EU-based identities.
D.Use Cloud KMS with EU-based key rings to encrypt all EU customer data, and rely on key location to enforce data residency.
AnswerB

The organization policy constraint 'constraints/gcp.resourceLocations' restricts where resources can be created to specified locations, such as EU regions. Applying it at the organization level ensures all projects inherit the restriction. Security Command Center can detect violations and misconfigurations, providing the required monitoring and remediation capability.

Why this answer

The organization policy constraint 'constraints/gcp.resourceLocations' is the native Google Cloud control that restricts resource creation to specified locations. Applied at the organization level, it ensures all projects inherit the EU-only restriction, preventing administrators from creating resources outside the EU. Security Command Center provides continuous monitoring and can detect any drift or violations, enabling remediation.

Exam trap

The trap here is assuming that VPC Service Controls or Cloud KMS key location enforces data residency, when only the 'constraints/gcp.resourceLocations' organization policy constraint restricts where resources can be physically created.

72
MCQmedium

An organization requires that all container images deployed to GKE be signed and verified before deployment. Which GCP service should be used?

A.Container Registry vulnerability scanning
B.Binary Authorization
C.Cloud Build
D.Artifact Registry
AnswerB

Binary Authorization enforces deploy-time attestation on GKE, blocking unsigned or unverified container images before they reach the cluster. It satisfies the stem's requirement for signature verification at deployment by validating attestations from trusted authorities, unlike vulnerability scanning or registry-level controls, which cannot gate admission.

Why this answer

Binary Authorization is a GCP service that enforces deploy-time security controls on GKE by ensuring only trusted container images are deployed. It uses attestations created by trusted authorities to verify that an image has been signed and meets specific criteria before allowing deployment. This directly satisfies the requirement for signed and verified images.

Exam trap

PCA often tests the difference between image scanning (vulnerability detection) and image signing/verification (policy enforcement). Candidates may confuse vulnerability scanning with Binary Authorization's enforcement role.

How to eliminate wrong answers

Option A is wrong because Container Registry vulnerability scanning only identifies vulnerabilities in images; it does not enforce signing or verification. Option C is wrong because Cloud Build is a CI/CD service for building and deploying containers, not for enforcing deployment policies. Option D is wrong because Artifact Registry is a repository for storing and managing container images, not for policy enforcement.

73
MCQeasy

A company wants to control which resources can be accessed by a service account in a specific project. Which IAM policy binding approach should be used?

A.Use VPC Service Controls to restrict the service account
B.Grant the service account a role at the project or resource level
C.Add the service account to a Cloud Identity group and grant the group a role
D.Grant the service account a role at the organization level
AnswerB

Binding a role to the service account at the project or specific resource level scopes its permissions precisely, so access is limited to the intended resources. IAM policies attached at those levels define exactly which actions the service account may perform.

Why this answer

Granting the service account a role at the project or resource level follows the principle of least privilege by scoping permissions to only the resources the service account needs to access. This is the standard IAM policy binding approach in Google Cloud for controlling access within a specific project. It avoids over-privileged access and aligns with security best practices.

Exam trap

The trap is choosing organization-level grants or VPC Service Controls because they sound more secure or comprehensive, but the exam expects you to apply least privilege by scoping the role to the project or resource level.

How to eliminate wrong answers

Option A is wrong because VPC Service Controls are used to define security perimeters around Google Cloud services to mitigate data exfiltration risks, not to grant or restrict IAM permissions for a service account. Option C is wrong because adding the service account to a Cloud Identity group and granting the group a role is an indirect method that can work but is not the primary or most direct policy binding approach for scoping access to a specific project — it adds unnecessary complexity and doesn't inherently limit scope to the project. Option D is wrong because granting a role at the organization level gives the service account access to all projects in the organization, violating least privilege and the requirement to restrict access to a specific project.

74
MCQeasy

A developer needs to grant a Compute Engine instance the ability to read from a Cloud Storage bucket. The instance does not have a service account attached. What should the developer do?

A.Create a service account and assign it the Storage Object Viewer role, then attach the service account to the instance.
B.Add the instance's external IP to the bucket permissions.
C.Generate a JSON key for a user account and store it on the instance.
D.Create a firewall rule to allow access to Cloud Storage.
AnswerA

A service account supplies the identity the instance lacks; granting it roles/storage.objectViewer authorises reads from the bucket, and attaching it to the instance lets applications obtain credentials automatically via the metadata server. Without an attached service account, no workload identity exists to authorise the request.

Why this answer

A Compute Engine instance must have a service account attached to obtain Google Cloud credentials for API calls. The developer should create a service account, grant it the Storage Object Viewer role (or a custom role with storage.objects.get/list), and attach it to the instance. The instance can then use the metadata server to obtain short-lived tokens and read the bucket.

Exam trap

PCA often tests whether candidates confuse network-level controls (firewall rules, external IPs) with IAM authorization, or recommend insecure JSON keys instead of attaching a service account.

How to eliminate wrong answers

Option B is wrong because Cloud Storage IAM does not grant access based on an instance's external IP address; IP-based rules apply to firewall rules, not bucket IAM. Option C is wrong because generating a JSON key for a user account and storing it on the instance is an insecure anti-pattern that violates least privilege and key management best practices. Option D is wrong because firewall rules control network traffic to VMs, not IAM authorization to Cloud Storage APIs.

75
Multi-Selecthard

Your company is designing a secure architecture for a new application on Google Cloud. They need to ensure that service accounts used by the application have only the necessary permissions, and that any use of those service accounts is auditable. Which two actions should they take? (Choose two.)

Select 2 answers
A.Create a custom role that includes all permissions the application might need in the future, to avoid frequent updates.
B.Use service account keys and rotate them every 90 days to ensure secure authentication.
C.Assign the service accounts the Project Editor role to simplify permission management.
D.Grant the service accounts predefined roles that include only the required permissions, and avoid using basic roles like Editor.
E.Enable Data Access audit logs for all services used by the application to capture service account activity.
AnswersD, E

Using predefined roles that contain only the necessary permissions follows the principle of least privilege. Basic roles like Editor grant broad permissions across many services, violating least privilege. This action reduces the risk of excessive access and is a recommended practice for secure architecture.

Why this answer

Least privilege is achieved by granting only the necessary predefined roles and avoiding basic roles. Auditability of service account usage requires enabling Data Access audit logs, which are not enabled by default. Together, these actions ensure that service accounts have minimal permissions and that their actions are logged for auditing.

Exam trap

The trap here is assuming that Admin Activity audit logs capture all service account usage, when Data Access logs are needed for read/write operations.

Page 1 of 2 · 79 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Pca Security Compliance questions.

CCNA Pca Security Compliance Questions — Page 1 of 2 | Courseiva