ExamDumpster

Free GCP-PCSE sample questions

Real questions from the Professional Cloud Security Engineer practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 6 of 12 free sample questions.

Question 1Choose one

NovaTech is a multi-cloud organization that runs its primary CI/CD pipelines in AWS. These AWS-based pipelines need to deploy infrastructure and upload build artifacts to Google Cloud. The Chief Information Security Officer (CISO) has strictly forbidden the creation and export of long-lived Google Cloud Service Account keys to prevent credential leakage. Which approach is the most secure and optimal way to grant the AWS pipelines access to Google Cloud resources?

Question 2Choose one

Aegis Healthcare uses Google Cloud to store sensitive patient records in a specific folder named 'PatientData'. The organization has an IAM Allow policy at the folder level granting the 'Data Analysts' group the `roles/bigquery.dataViewer` role. However, a recent compliance audit requires that a specific contractor team (which is part of the Data Analysts group) must NEVER have access to the 'PatientData' folder under any circumstances. What is the most robust and scalable way to enforce this restriction?

Question 3Choose one

Zephyr Financial is implementing least privilege across its engineering teams. Site Reliability Engineers (SREs) normally only have Viewer access to production projects. During a P1 incident, they need elevated privileges (e.g., `roles/compute.admin`) to mitigate issues, but these privileges must expire automatically after 2 hours and require approval from an engineering manager. Which Google Cloud service should be configured to meet this requirement?

Question 4Choose one

A retail company has acquired a smaller startup. The startup's employees currently use Okta for identity management. The parent company wants to grant the startup's developers access to specific Google Cloud Console projects without creating new user accounts in the parent company's Google Workspace/Cloud Identity domain. Which solution should the cloud security engineer implement?

Question 5Choose one

A Terraform CI/CD pipeline runs on a Google Kubernetes Engine (GKE) cluster using a dedicated service account named `sa-terraform-runner`. This service account needs to deploy resources across multiple projects by assuming the identity of a highly privileged service account named `sa-org-admin`. Which IAM role must be granted to `sa-terraform-runner` on the `sa-org-admin` service account to allow this impersonation?

Question 6Choose 2

Kallisto Corp operates under strict European data residency laws. The compliance team mandates that no Google Cloud resources can be created outside of the `europe-west1` and `europe-west3` regions. Which TWO actions should the security engineer take to enforce this requirement comprehensively across the entire organization? (Select TWO)

6 more free samples are waiting

Create a free account to unlock the whole GCP-PCSE sample bank, or get full access to all 180 practice questions in the simulator.

Create account