Courseiva

PCA · topic practice

Design for security and compliance practice questions

This domain covers designing Google Cloud architectures that protect data and meet regulatory obligations. Expect questions on CMEK and Cloud KMS, VPC firewall rules and hierarchical policies, VPC Service Controls perimeters, IAM least privilege, and audit logging. Scenarios are framed around HIPAA, GDPR, or data residency, and you must pick the control that satisfies the stated requirement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Design for security and compliance

What the exam tests

What to know about Design for security and compliance

Be able to select the right Google Cloud control for a stated compliance or security requirement: CMEK via Cloud KMS, VPC Service Controls, firewall rules, Cloud Armor, or audit logs. The most important thing is matching the control to the exact threat and regulatory obligation described.

Choosing Cloud KMS CMEK versus Google-managed or CSEK encryption for data at rest

Using VPC firewall rules, hierarchical firewall policies, and Cloud Armor to restrict traffic

Applying VPC Service Controls perimeters and ingress/egress rules to prevent data exfiltration

Reading Cloud Audit Logs to determine why a resource change such as a firewall rule failed

Watch out for

Common Design for security and compliance exam traps

  • ▸Assuming CMEK alone satisfies compliance; HIPAA and GDPR also require access controls, audit logging, and network restrictions.
  • ▸Confusing Cloud Armor, which filters HTTP(S) load balancer traffic, with VPC firewall rules that govern instance-level traffic.
  • ▸Forgetting that a denied API call appears in audit logs with the specific IAM or policy reason, not as a silent failure.

Practice set

Design for security and compliance questions

20 questions · select your answer, then reveal the explanation

An e-commerce platform uses Cloud SQL for MySQL to store user profiles and order history. The security team wants to ensure that database administrators (DBAs) cannot view plaintext credit card numbers stored in the database. They also want to minimize application changes. What should they do?

A company wants to ensure that only Compute Engine instances with a specific service account can access a Cloud Storage bucket. Which IAM condition should they use?

Which THREE are valid methods to protect sensitive data in BigQuery?

Your company runs a multi-region web application on Google Kubernetes Engine (GKE) with pods that process sensitive user data. The application uses Cloud SQL for PostgreSQL as the backend database. Your security team has implemented the following controls: 1) All traffic to the database is encrypted using SSL/TLS. 2) The GKE cluster uses Workload Identity to bind Kubernetes service accounts to IAM service accounts. 3) The Cloud SQL instance is configured with a public IP address and authorized networks to allow only the GKE cluster's node IP ranges. 4) The database credentials are stored in Secret Manager and mounted as volumes in the pods. Recently, a security audit revealed that a pod was compromised due to a container vulnerability. The attacker was able to exfiltrate sensitive data directly from the Cloud SQL database using the credentials from Secret Manager. The security team wants to prevent such exfiltration in the future while minimizing changes to the application code. Which course of action should you recommend?

An organization has set the IAM policy constraint 'constraints/iam.allowedPolicyMemberDomains' with the values shown. Which of the following users can be granted an IAM role on a project in this organization? (Choose all that apply.)

Exhibit

Refer to the exhibit.

```yaml
# organization_policy.yaml
constraint: constraints/iam.allowedPolicyMemberDomains
listPolicy:
  allowedValues:
    - C0xxxxxxx  # Google Cloud organization ID
    - A1b2C3d4E5f6G7h8I9j0K1l2M3n4O5p6  # Cloud Identity domain: example.com
```

Your company has a production environment on Google Cloud that includes Compute Engine instances, Cloud Storage buckets, and BigQuery datasets. Security policies require that all data at rest is encrypted with CMEK, and audit logs must be retained for 7 years. The current configuration uses Google-managed encryption keys. You have been asked to transition to CMEK for all resources. After enabling CMEK for new resources, you discover that the existing resources are not re-encrypted. To comply with the policy, you need to re-encrypt the existing data. What should you do?

Question 7easymultiple choice
Review the full subnetting walkthrough →

An engineer runs the above command and sees two firewall rules that allow SSH access. A security review requires that SSH access be allowed only from the bastion subnet 10.0.1.0/24. What should the engineer do to meet the requirement?

Network Topology
filter="allowed.ports:22"format=jsonRefer to the exhibit.```"name": "allow-ssh-ingress","network": "default","direction": "INGRESS","priority": 1000,"sourceRanges": ["0.0.0.0/0"],"allowed": [{"IPProtocol": "tcp", "ports": ["22"]}],"targetTags": ["ssh-allowed"]},"name": "allow-ssh-from-bastion","sourceRanges": ["10.0.1.0/24"],

A company needs to ensure that only approved machine images can be used to create Compute Engine instances to meet security compliance. Which two methods should they use? (Choose two.)

What is the effective access of the service account sa@project.iam.gserviceaccount.com to the bucket?

Exhibit

Refer to the exhibit.

```json
{
  "bindings": [
    {
      "role": "roles/storage.objectViewer",
      "members": [
        "user:alice@example.com"
      ]
    },
    {
      "role": "roles/storage.objectAdmin",
      "members": [
        "user:bob@example.com",
        "serviceAccount:sa@project.iam.gserviceaccount.com"
      ]
    }
  ]
}
```

A firewall rule is configured to allow inbound TCP traffic on ports 80 and 443 from the IP ranges 203.0.113.0/24 and 198.51.100.0/24 to instances with the tag 'web-server'. Which traffic will this rule allow?

Exhibit

Refer to the exhibit.

```
gcloud compute firewall-rules describe my-rule
---
allowed:
- IPProtocol: tcp
  ports:
  - 80
  - 443
direction: INGRESS
sourceRanges:
- 10.0.0.0/8
- 192.168.0.0/16
targetTags:
- web-server
```

When will the key be automatically rotated?

Network Topology
location us-central1keyring my-keyringRefer to the exhibit.```createTime: '2024-01-01T00:00:00Z'destroyScheduledDuration: 86400simportOnly: falselabels:environment: productionname: projects/my-project/locations/us-central1/keyRings/my-keyring/cryptoKeys/my-keynextRotationTime: '2024-04-01T00:00:00Z'primary:name: projects/my-project/locations/us-central1/keyRings/my-keyring/cryptoKeys/my-key/cryptoKeyVersions/1state: ENABLEDrotationPeriod: 7776000sversionTemplate:algorithm: GOOGLE_SYMMETRIC_ENCRYPTIONprotectionLevel: HSM

A financial institution deploys a containerized application on GKE with Binary Authorization enabled. They want to ensure that only images signed by their internal CI/CD pipeline are deployed, and they also need to allow a break-glass procedure using a specific image from a curated registry. How should they configure Binary Authorization?

A security architect is designing a zero-trust network for applications running on Compute Engine. They want to enforce that all traffic between VMs must be encrypted and authenticated, regardless of the VPC network. Which approach meets this requirement?

A company manages secrets for multiple microservices using Secret Manager. They need to ensure that each service can access only its own secrets, and that all access is logged. What is the best IAM architecture?

Which TWO methods can be used to encrypt data at rest in BigQuery?

Which TWO practices improve the security of a Cloud Run service?

Which THREE services can be used to audit changes to resources in a Google Cloud project?

Alice needs to read objects in the bucket 'secret-bucket'. Based on the IAM policy, what is her effective access?

Exhibit

Refer to the exhibit.

IAM policy for project my-project:
```json
{
  "bindings": [
    {
      "role": "roles/storage.objectViewer",
      "members": ["user:alice@example.com"]
    },
    {
      "role": "roles/storage.objectAdmin",
      "members": ["user:alice@example.com"]
    }
  ],
  "denyRules": [
    {
      "denialCondition": {
        "expression": "resource.name.startsWith('projects/my-project/buckets/secret-bucket')"
      },
      "members": ["user:alice@example.com"],
      "role": "roles/storage.objectViewer"
    }
  ]
}
```

A company is deploying a web application on Google Kubernetes Engine (GKE) and needs to ensure that the application's service account can only pull images from a specific Container Registry repository. What is the best practice to enforce this?

A company wants to allow developers to create service accounts in a project but prevent them from granting the 'roles/iam.serviceAccountUser' role to any user. Which organization policy constraint should they set?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Design for security and compliance sessions

Start a Design for security and compliance only practice session

Every question in these sessions is drawn from the Design for security and compliance domain — nothing else.

Related practice questions

Related PCA topic practice pages

Move into related areas when this topic feels solid.

Analysing and Optimising Technical and Business Processes practice questions

Analysing and Optimising Technical and Business Processes practice questions for PCA.

Managing Implementation and Ensuring Solution and Operations Reliability practice questions

Targeted PCA practice covering Managing Implementation and Ensuring Solution and Operations Reliability.

Managing and Provisioning a Solution Infrastructure practice questions

Practise PCA questions linked to Managing and Provisioning a Solution Infrastructure.

Designing for Security and Compliance practice questions

Work through PCA questions on Designing for Security and Compliance.

Design for security and compliance practice questions

Design for security and compliance practice questions for PCA.

Design and plan a cloud solution architecture practice questions

Work through PCA questions on Design and plan a cloud solution architecture.

Manage and provision cloud infrastructure practice questions

Manage and provision cloud infrastructure practice questions for PCA.

Analyze and optimize technical and business processes practice questions

Analyze and optimize technical and business processes practice questions for PCA.

Ensure solution and operations reliability practice questions

Sharpen your PCA knowledge of Ensure solution and operations reliability.

Manage implementation of cloud architecture practice questions

Work through PCA questions on Manage implementation of cloud architecture.

PCA fundamentals practice questions

Practise PCA questions linked to PCA fundamentals.

PCA scenario practice questions

Work through PCA questions on PCA scenario.

Frequently asked questions

What does the PCA exam test about Design for security and compliance?
Be able to select the right Google Cloud control for a stated compliance or security requirement: CMEK via Cloud KMS, VPC Service Controls, firewall rules, Cloud Armor, or audit logs. The most important thing is matching the control to the exact threat and regulatory obligation described.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Design for security and compliance questions in a focused session?
Yes — the session launcher on this page draws every question from the Design for security and compliance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCA topics?
Use the topic links above to move to related areas, or go back to the PCA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCA exam covers. They are not copied from any real exam or dump site.