Free GCP-PCSE sample questions
Real questions from the Professional Cloud Security Engineer practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 6 of 12 free sample questions.
Aegis Healthcare uses Google Cloud to store sensitive patient records in a specific folder named 'PatientData'. The organization has an IAM Allow policy at the folder level granting the 'Data Analysts' group the `roles/bigquery.dataViewer` role. However, a recent compliance audit requires that a specific contractor team (which is part of the Data Analysts group) must NEVER have access to the 'PatientData' folder under any circumstances. What is the most robust and scalable way to enforce this restriction?
Zephyr Financial is implementing least privilege across its engineering teams. Site Reliability Engineers (SREs) normally only have Viewer access to production projects. During a P1 incident, they need elevated privileges (e.g., `roles/compute.admin`) to mitigate issues, but these privileges must expire automatically after 2 hours and require approval from an engineering manager. Which Google Cloud service should be configured to meet this requirement?
A retail company has acquired a smaller startup. The startup's employees currently use Okta for identity management. The parent company wants to grant the startup's developers access to specific Google Cloud Console projects without creating new user accounts in the parent company's Google Workspace/Cloud Identity domain. Which solution should the cloud security engineer implement?
A Terraform CI/CD pipeline runs on a Google Kubernetes Engine (GKE) cluster using a dedicated service account named `sa-terraform-runner`. This service account needs to deploy resources across multiple projects by assuming the identity of a highly privileged service account named `sa-org-admin`. Which IAM role must be granted to `sa-terraform-runner` on the `sa-org-admin` service account to allow this impersonation?
Kallisto Corp operates under strict European data residency laws. The compliance team mandates that no Google Cloud resources can be created outside of the `europe-west1` and `europe-west3` regions. Which TWO actions should the security engineer take to enforce this requirement comprehensively across the entire organization? (Select TWO)
6 more free samples are waiting
Create a free account to unlock the whole GCP-PCSE sample bank, or get full access to all 180 practice questions in the simulator.