TechNuggets Academy
Professional Cloud Security Engineer

Free Google Cloud Certified - Professional Cloud Security Engineer Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$2005 exam domainsLevel Advanced2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Configuring Access
A company's CI/CD pipeline runs on GitHub Actions and needs to deploy resources to a Google Cloud project. Security policy prohibits storing any long-lived credentials in the pipeline configuration. Which solution BEST meets this requirement?
Workload Identity Federation lets external workloads (like GitHub Actions) exchange a short-lived OIDC token for temporary Google credentials via service account impersonation, eliminating the need for any downloaded key.
Question 2 of 12 · Securing Communications and Boundary Protection
A company has multiple GCP projects for different application teams (finance, HR, and marketing). The security team wants centralized control over network resources and firewall rules, while allowing each application team to independently manage resources such as Compute Engine instances and Cloud SQL databases in their own projects. Which networking approach BEST meets this requirement?
Shared VPC lets a host project centrally own the network topology and firewall rules while service projects attach Compute Engine, GKE, or Cloud SQL resources to shared subnets, giving the security team centralized network governance without limiting per-team resource management.
Question 3 of 12 · Ensuring Data Protection
A healthcare analytics team stores credit card numbers in BigQuery. Analysts must be able to JOIN records across multiple tables using the card number as a key, but the actual card numbers must never be visible to analysts, and the tokenized value must retain the same 16-digit numeric format so downstream validation logic still works. Which Sensitive Data Protection technique should they apply?
FPE is deterministic (same input always produces the same token) and preserves the original format/length, so analysts can still join on the tokenized value while the real card number is never exposed.
Question 4 of 12 · Managing Operations
A company's CI/CD pipeline deploys container images to a GKE cluster running production payment workloads. The security team wants to guarantee that only images which have passed a CVE vulnerability scan and been explicitly approved can ever be deployed to that cluster, even if a developer tries to deploy directly with kubectl. Which solution BEST meets this requirement?
Binary Authorization enforces admission control at the cluster level (via a webhook), so it blocks any deployment path -- CI/CD or manual kubectl -- unless the image carries a valid attestation from the required attestor, giving true deploy-time enforcement.
Question 5 of 12 · Supporting Compliance Requirements
A financial services company operating on Google Cloud must comply with a regulation stating that Google support personnel must not access the customer's data without the customer explicitly authorizing each specific access request in advance. Which Google Cloud capability satisfies this requirement?
Access Approval requires Google support staff to obtain explicit customer approval before accessing customer content, satisfying a 'pre-authorization required' regulatory control.
Question 6 of 12 · Configuring Access
Which statement correctly describes how IAM deny policies interact with allow policies in Google Cloud?
IAM deny policies are evaluated together with allow policies at every resource level; an explicit deny always wins over any allow grant, including permissions held by highly privileged roles like Owner.
Question 7 of 12 · Securing Communications and Boundary Protection
An organization runs Compute Engine VMs that must call Cloud Storage and BigQuery APIs. For security reasons these VMs must not have external IP addresses, but connectivity to Google APIs must continue to work. Which feature should be enabled on the VM's subnet to satisfy this requirement?
Private Google Access is a subnet-level setting that allows VMs without external IP addresses to reach Google APIs and services using internal IP addresses, exactly matching the described requirement.
Question 8 of 12 · Ensuring Data Protection
A financial services customer's compliance team requires that the actual key material used to encrypt their Cloud Storage data never resides within Google's infrastructure at any point, and that key access requests can be logged and audited by an external, non-Google system. Which Google Cloud capability satisfies this requirement?
Cloud EKM lets you keep key material in a supported external key management partner system outside Google's infrastructure. Google calls out to the external system for every cryptographic operation, allowing the external system to log and audit access independently of Google.
Question 9 of 12 · Managing Operations
A security team needs to detect network-based threats such as malware command-and-control traffic and port scans by inspecting packet payloads traversing a VPC, without deploying, licensing, or managing third-party IDS software themselves. Which Google Cloud service should they use?
Cloud IDS is a fully managed service (built on Palo Alto Networks technology) that mirrors and inspects packet payloads for known threat signatures, correlating findings and reporting them, without requiring the customer to operate any third-party appliance.
Question 10 of 12 · Supporting Compliance Requirements
A healthcare company must ensure that customer data is processed and stored only within a specific region, that support access is restricted to personnel meeting defined criteria, and that compliance controls map to a named regulatory framework such as FedRAMP or IL4. Which Google Cloud product should they provision?
Assured Workloads is purpose-built to enforce a bundle of controls — data residency, personnel access restrictions, and control mapping to specific compliance regimes (FedRAMP, IL4, EU regions, etc.) — in a single managed folder.
Question 11 of 12 · Configuring Access
An on-call engineer needs elevated access to a production project for exactly 4 hours to troubleshoot an incident. The security team requires an approval workflow, automatic expiration of the grant, and a full audit trail of the request and usage. Which Google Cloud capability BEST satisfies these requirements?
Privileged Access Manager is purpose-built for just-in-time privileged access: it supports requestor/approver workflows, automatically expiring grants, and detailed audit logging of the entire request lifecycle.
Question 12 of 12 · Securing Communications and Boundary Protection
A SaaS company hosts a proprietary service in its own VPC network and needs to let multiple customer VPC networks in different organizations privately consume this service. The company wants to avoid overlapping IP address conflicts and must not expose its entire VPC network topology to customers. Which solution BEST meets these requirements?
Private Service Connect lets the provider publish a service via a service attachment; consumers create endpoints with private IPs in their own VPCs, avoiding IP overlap conflicts and without exposing the provider's full network topology, which is the standard pattern for multi-tenant SaaS consumption.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →

Professional Cloud Security Engineer exam — quick answers

How much does the Professional Cloud Security Engineer exam cost?

The exam fee is approximately $200 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 5 domains: Configuring Access (25%), Securing Communications and Boundary Protection (22%), Ensuring Data Protection (23%), Managing Operations (19%), Supporting Compliance Requirements (11%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Configuring Access →Securing Communications and Boundary Protection →Ensuring Data Protection →Managing Operations →