PCSE Sample Questions & Answers
Free Professional Cloud Security Engineer practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full PCSE simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Managing operations · Configuring and monitoring Security Command Center
A startup has deployed its entire infrastructure on Google Cloud. The CTO is concerned about the security posture and wants to proactively identify misconfigurations, such as publicly exposed Cloud Storage buckets, overly permissive IAM policies, and open firewall rules. The solution must be a managed Google Cloud service that provides a centralized dashboard of findings and integrates with the existing resource hierarchy. Which service should they implement?
Show answer & explanation
Correct answer: C
Security Command Center (SCC) is Google Cloud's centralized security and risk management platform. Its built-in service, Security Health Analytics, automatically scans for common misconfigurations and vulnerabilities across the organization, providing findings in a centralized dashboard. This perfectly matches the CTO's requirements for a managed, proactive security posture management tool.
- Question 2Intermediate
Securing communications and establishing boundary protection · Identifying use cases and configuring VPC Service Controls
True or False: A VPC Service Controls perimeter, when configured with an access level based on IP address, can restrict access to Google Cloud APIs like BigQuery to only requests originating from a corporate on-premises network.
Show answer & explanation
Correct answer: A
This statement is true. A VPC Service Controls perimeter defines a virtual boundary for Google Cloud services. An Access Level is a condition that can be applied to this perimeter, and it can be based on attributes like IP address, device type, or user identity. By creating an access level that specifies the public IP ranges of the corporate network, you can enforce that only requests from that location can access the protected services within the perimeter.
- Question 3Intermediate
Ensuring data protection · Managing encryption at rest, in transit, and in use
A new regulation requires your company to use FIPS 140-2 Level 3 validated hardware security modules (HSMs) for managing the encryption keys used to protect your most sensitive data in Cloud Storage. Your security policy prohibits Google personnel from having any access to the key material. Which Cloud KMS solution should you implement?
Show answer & explanation
Correct answer: C
Cloud EKM allows you to use keys managed in a supported third-party key management system to protect data in Google Cloud. By connecting it to your own FIPS 140-2 Level 3 validated HSM, you retain full control over the keys, and Google personnel have no access to the key material. Cloud HSM is FIPS 140-2 Level 3 validated, but it is a Google-managed service, which doesn't meet the strict requirement of prohibiting any Google personnel access.
- Question 4AdvancedSelect 2
Configuring access · Securing and protecting service accounts
You are the security lead for a retail company. During a post-incident review of a data breach, it was discovered that a compromised service account key with Project Owner permissions was used to exfiltrate data from a production project. To prevent this from happening again, you want to implement a defense-in-depth strategy that limits the potential damage of a compromised credential. Which TWO controls would be most effective? (Select TWO)
Show answer & explanation
Correct answers: A, B
- Question 5Intermediate
Configuring access · Defining the resource hierarchy
An organization wants to enforce that all new Compute Engine instances are created from a set of approved, hardened OS images. They also need to prevent developers from enabling serial port access on any VM. Which Google Cloud feature should be used to enforce these two requirements across the entire organization?
Show answer & explanation
Correct answer: C
The Organization Policy Service is designed for this exact purpose. It allows administrators to enforce constraints on how resources can be configured. The
compute.trustedImageProjectsconstraint can be used to define a list of projects from which images can be used, andcompute.disableSerialPortAccesscan be set toTrueto prevent serial port access. Applying these at the organization root enforces them everywhere. - Question 6Advanced
Managing operations · Automating infrastructure and application security
A DevOps team is building a CI/CD pipeline to deploy containerized applications to Cloud Run. A security requirement states that only container images that have passed a vulnerability scan and have been approved by a QA lead can be deployed to the production environment. How can you automate this enforcement?
Show answer & explanation
Correct answer: B
Binary Authorization is the service designed for this use case. You can create a policy that enforces that container images must be signed by specific attestors before they can be deployed. In this scenario, you would create two attestors: one for the automated vulnerability scanner and another for the QA lead. The policy for the production Cloud Run service would require valid attestations from both, thus automating the enforcement of the security requirement.
- Question 7Intermediate
Securing communications and establishing boundary protection · Configuring boundary segmentation
Your company is deploying a multi-tier web application in a single VPC. The tiers are: Web (internet-facing), App (internal), and Database (internal). According to security best practices, you need to implement network segmentation to control traffic flow between these tiers. Specifically:
- The internet should only be able to reach the Web tier on TCP port 443.
- The Web tier should only be able to reach the App tier on TCP port 8080.
- The App tier should only be able to reach the Database tier on TCP port 3306.
- No other traffic should be allowed between tiers.
What is the most effective way to implement this using Google Cloud networking features?
Show answer & explanation
Correct answer: B
Using service accounts for firewall rules is the most secure and manageable method. Unlike network tags, which can be modified by any user with instance admin permissions, service account usage is governed by IAM. By creating specific ingress rules for each tier (e.g., an ingress rule for the App tier allowing TCP:8080 from the Web tier's service account), you create a robust, identity-based segmentation model that adheres to the principle of least privilege.
- Question 8Advanced
Configuring access · Managing Cloud Identity
You need to grant a third-party auditing firm temporary, time-limited access to view configurations of all resources within a specific project. The firm uses its own corporate identity provider (IdP) for authentication and does not have Google accounts. You want to provide this access without creating and managing new user accounts in your Cloud Identity domain. What is the most secure and appropriate method?
Show answer & explanation
Correct answer: B
Workforce Identity Federation is designed for this exact scenario. It allows you to grant IAM roles to users from an external identity provider without synchronizing user identities into your Cloud Identity domain. You can configure a trust relationship with the auditor's IdP (e.g., Azure AD, Okta) and use attribute mapping to grant them appropriate, temporary access to Google Cloud resources.
- Question 9Intermediate
Ensuring data protection · Securing secrets with Secret Manager
A developer needs to retrieve secrets from Secret Manager for an application running on their local workstation, which is connected to the corporate network. The company policy prohibits the use of long-lived service account keys on developer machines. The developer is authenticated to Google Cloud via the gcloud CLI using their corporate identity. What is the recommended approach for the application to access the secrets?
Show answer & explanation
Correct answer: C
This is the recommended practice for local development. The
gcloud auth application-default logincommand stores the developer's user credentials in a well-known location on the local machine. The Google Cloud client libraries are designed to automatically find and use these credentials via the Application Default Credentials (ADC) strategy. This avoids the use of service account keys and leverages the developer's existing identity and permissions. - Question 10Beginner
Managing operations · Configuring and analyzing network logs
You are investigating a security incident and need to analyze network traffic between two specific Compute Engine instances that occurred yesterday. You have been informed that VPC Flow Logs are enabled for the subnet containing the instances. How can you perform this analysis?
Show answer & explanation
Correct answer: B
VPC Flow Logs are sent to Cloud Logging. The most direct way to analyze this historical traffic is to go to the Logs Explorer in Cloud Logging, select the appropriate log bucket, and build a query that filters for the specific log name (
vpc_flows), the source and destination IP addresses of the instances, and the time range of the incident.
Ready for the real thing?
The full PCSE simulator has every exam-style question, timed mode, and instant scoring.