Courseiva

PCA · topic practice

Designing for Security and Compliance practice questions

This domain covers how to design identity, access, network, and data protection on Google Cloud. Questions present a scenario and ask which IAM role, service account, firewall rule, or security service satisfies least-privilege and compliance requirements. Expect to choose between Cloud IAM, IAP, Cloud Armor, VPC Service Controls, Cloud KMS, and Secret Manager, and to reason about service accounts versus user credentials.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Designing for Security and Compliance

What the exam tests

What to know about Designing for Security and Compliance

Be able to choose the right Google Cloud security control for a scenario and grant least-privilege access. The single most important thing is knowing that IAP requires both enabling the IAP service and granting the IAP-secured Web App User role to users, while service accounts should be attached to instances for API access.

Granting least-privilege IAM roles, including predefined roles like roles/iap.httpsResourceAccessor for Identity-Aware Proxy.

Attaching and using service accounts so Compute Engine instances can call Google Cloud APIs securely.

Configuring Cloud Armor security policies with reCAPTCHA Enterprise and Google Cloud Armor bot management rules.

Using Secret Manager for secret storage, versioning, automatic rotation, and integration with Cloud Functions.

Watch out for

Common Designing for Security and Compliance exam traps

  • ▸Assuming IAP alone grants access; you must also grant the IAP-secured Web App User role to each user or group.
  • ▸Attaching a service account to an instance after creation without stopping it, or granting broad scopes instead of narrow IAM roles.
  • ▸Confusing Cloud Armor with Cloud IAP: Cloud Armor filters at the edge, while IAP authenticates and authorizes users.

Practice set

Designing for Security and Compliance questions

20 questions · select your answer, then reveal the explanation

A company wants to use its existing Active Directory credentials to authenticate users to the GCP Console. Which service should they integrate with?

A company uses Cloud Armor to protect an HTTP(S) Load Balancer. They want to block traffic from a specific IP address range during off-peak hours but allow it during peak hours. How can they achieve this?

A company wants to enforce that only approved container images can be deployed to GKE. They also want to ensure images are scanned for vulnerabilities before deployment. Which two GCP services should they use? (Choose TWO).

A company needs to store secrets used by multiple GCP services. They require automatic rotation of secrets every 30 days and integration with Cloud Functions. Which two GCP services should they use? (Choose TWO).

A company wants to protect a web application from SQL injection and cross-site scripting (XSS) attacks. They also need to block traffic from specific geographic regions. Which three features of Cloud Armor should they use? (Choose THREE).

A company needs to ensure that data stored in Cloud Storage is encrypted with customer-managed keys that are rotated every 90 days. Which two steps must be taken to achieve this? (Choose TWO).

Question 7mediummultiple choice
Read the full VPN explanation →

A company wants to restrict access to their Cloud Storage bucket so that only requests from within a specific VPC network are allowed, and all other traffic (including internet) is denied. They also need to allow access from on-premises through a VPN. Which configuration should they use?

An engineer needs to grant a service account the ability to create and manage VMs in a specific project, but only those VMs with a certain label. Which IAM feature should they use?

A company wants to allow a Kubernetes pod in GKE to access a Cloud Storage bucket using the pod's own identity, without managing long-lived credentials. They have created a Google service account (GSA) and a Kubernetes service account (KSA). What should they do to bind the KSA to the GSA?

A company wants to use Cloud DLP to scan a Cloud Storage bucket for personally identifiable information (PII) and de-identify the data before storing it in another bucket. Which TWO actions should they take? (Choose 2)

A company uses Cloud Identity to manage users and wants to allow employees to authenticate to Google Cloud using their existing corporate Active Directory credentials. Which solution should they implement?

A company wants to use their own HSM to hold encryption keys for Google Cloud services, but they want Google Cloud to perform cryptographic operations without exposing the keys. Which service should they use?

An organization needs to grant a third-party auditor read-only access to view all resources in a project, including sensitive data like IAM policies and logs. Which role should be assigned?

A security engineer needs to allow a Compute Engine instance with the service account 'sa-prod@project.iam.gserviceaccount.com' to connect to a Cloud SQL instance over a private IP. The VPC has no firewall rules allowing this traffic. What is the MOST secure way to grant access?

A company uses Cloud Key Management Service (Cloud KMS) with a customer-managed encryption key (CMEK) to encrypt data in BigQuery. They want to ensure the key can only be used by the BigQuery service account in the 'us-central1' region. Which IAM condition should be added to the key's IAM policy?

Question 16hardmultiple choice
Read the full VPN explanation →

A company is migrating an on-premises application to Google Cloud. The application requires access to a legacy database that can only be reached from a specific on-premises IP address. The company has established a Cloud VPN tunnel. What is the MOST secure way to ensure that only the migrated application's Compute Engine instances can initiate connections to the on-premises database?

A company wants to enforce that all data stored in Cloud Storage buckets is encrypted with a key that they manage and rotate quarterly. They also want to ensure that the key is stored in a hardware security module (HSM). Which combination of services should they use?

An engineer is configuring Cloud Armor security policies for an HTTPS Load Balancer. They want to block requests from a specific IP range but allow all other traffic. What is the correct way to configure this?

A security team needs to restrict access to a set of Cloud Storage buckets so that only Compute Engine instances with a specific service account can read objects. Which TWO steps should they take? (Choose two.)

A company wants to use Cloud Key Management Service (Cloud KMS) to manage encryption keys for multiple applications. They have the following requirements: 1) Keys must be automatically rotated every 90 days. 2) Different applications should have access only to their own keys. 3) All key operations must be logged for audit purposes. Which THREE steps should they take? (Choose three.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Designing for Security and Compliance sessions

Start a Designing for Security and Compliance only practice session

Every question in these sessions is drawn from the Designing for Security and Compliance domain — nothing else.

Related practice questions

Related PCA topic practice pages

Move into related areas when this topic feels solid.

Analysing and Optimising Technical and Business Processes practice questions

Analysing and Optimising Technical and Business Processes practice questions for PCA.

Managing Implementation and Ensuring Solution and Operations Reliability practice questions

Targeted PCA practice covering Managing Implementation and Ensuring Solution and Operations Reliability.

Managing and Provisioning a Solution Infrastructure practice questions

Practise PCA questions linked to Managing and Provisioning a Solution Infrastructure.

Designing for Security and Compliance practice questions

Work through PCA questions on Designing for Security and Compliance.

Design for security and compliance practice questions

Design for security and compliance practice questions for PCA.

Design and plan a cloud solution architecture practice questions

Work through PCA questions on Design and plan a cloud solution architecture.

Manage and provision cloud infrastructure practice questions

Manage and provision cloud infrastructure practice questions for PCA.

Analyze and optimize technical and business processes practice questions

Analyze and optimize technical and business processes practice questions for PCA.

Ensure solution and operations reliability practice questions

Sharpen your PCA knowledge of Ensure solution and operations reliability.

Manage implementation of cloud architecture practice questions

Work through PCA questions on Manage implementation of cloud architecture.

PCA fundamentals practice questions

Practise PCA questions linked to PCA fundamentals.

PCA scenario practice questions

Work through PCA questions on PCA scenario.

Frequently asked questions

What does the PCA exam test about Designing for Security and Compliance?
Be able to choose the right Google Cloud security control for a scenario and grant least-privilege access. The single most important thing is knowing that IAP requires both enabling the IAP service and granting the IAP-secured Web App User role to users, while service accounts should be attached to instances for API access.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Designing for Security and Compliance questions in a focused session?
Yes — the session launcher on this page draws every question from the Designing for Security and Compliance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCA topics?
Use the topic links above to move to related areas, or go back to the PCA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCA exam covers. They are not copied from any real exam or dump site.