PCSE Practice Exam: Professional Cloud Security Engineer
GCP security: IAM deep cuts, VPC controls, KMS, and compliance without the anxiety.
What you'll be tested on
- IAM and Policies
- Network Security
- Data Protection
- Security Operations
- Compliance
Sample PCSE questions
A customer needs an alternative to storing their plain text secrets in their source-code management (SCM) system. How should the customer achieve this using Google Cloud Platform?
- Use Cloud Source Repositories, and store secrets in Cloud SQL.
- Encrypt the secrets with a Customer-Managed Encryption Key (CMEK), and store them in Cloud Storage.
- Run the Cloud Data Loss Prevention API to scan the secrets, and store them in Cloud SQL.
- Deploy the SCM to a Compute Engine VM with local SSDs, and enable preemptible VMs.
Show answer
B — Encrypt the secrets with a Customer-Managed Encryption Key (CMEK), and store them in Cloud Storage.Encrypting secrets with a customer-managed encryption key in Cloud KMS and storing the ciphertext in Cloud Storage keeps plain text secrets out of source control while letting the team control key rotation, access, and audit. The application decrypts at runtime via KMS. Storing secrets in Cloud SQL still leaves them readable in plain text to anyone with database access. Cloud DLP is for discovering and de-identifying sensitive data, not secrets management. Running the SCM on preemptible VMs with local SSDs is unrelated and actually increases risk of losing the SCM instance.
Your team wants to centrally manage GCP IAM permissions from their on-premises Active Directory Service. Your team wants to manage permissions by AD group membership. What should your team do to meet these requirements?
- Set up Cloud Directory Sync to sync groups, and set IAM permissions on the groups.
- Set up SAML 2.0 Single Sign-On (SSO), and assign IAM permissions to the groups.
- Use the Cloud Identity and Access Management API to create groups and IAM permissions from Active Directory.
- Use the Admin SDK to create groups and assign IAM permissions from Active Directory.
Show answer
A — Set up Cloud Directory Sync to sync groups, and set IAM permissions on the groups.Cloud Directory Sync (GCDS) synchronizes users and groups from on-premises Active Directory into Cloud Identity or Google Workspace, so AD group membership maps directly to Google groups. IAM policies can then be granted to those synced groups, achieving centralized, group-based permission management. SAML SSO only federates authentication and does not provision groups for IAM. The IAM API and Admin SDK are management interfaces, not synchronization tools, so they cannot by themselves keep AD group membership in sync with Google Cloud.
A customer needs to launch a 3-tier internal web application on Google Cloud Platform (GCP). The customer's internal compliance requirements dictate that end- user access may only be allowed if the traffic seems to originate from a specific known good CIDR. The customer accepts the risk that their application will only have SYN flood DDoS protection. They want to use GCP's native SYN flood protection. Which product should be used to meet these requirements?
- Cloud Armor
- VPC Firewall Rules
- Cloud Identity and Access Management
- Cloud CDN
Show answer
B — VPC Firewall RulesVPC firewall rules let you restrict ingress to specific source CIDR ranges, which satisfies the requirement that traffic only appears to originate from a known-good CIDR. GCP's global network fabric absorbs and mitigates SYN floods natively at the infrastructure level, so no extra DDoS product is needed. Cloud Armor provides Layer 7 WAF features and DDoS defense behind a load balancer, which is more than required and needs an external HTTP(S) load balancer. IAM controls identities, not network traffic, and Cloud CDN is for content caching.
Access plans
| Access | Price |
|---|---|
| 3 months | |
| 1 year | |
| Lifetime |
Free preview inside — try 5 questions before you pay anything.
FAQ
How many practice questions are in this PCSE bank?
376 questions covering the current PCSE Professional Cloud Security Engineer syllabus, every one with the correct answer and an explanation.How long is the real PCSE exam?
The official PCSE exam gives you 120 minutes. Our timed exam mode uses the same limit so the pace feels familiar.What does PCSE access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.