Official Bank 0/224

Professional Cloud Security Engineer Exam (PROFESSIONAL-CLOUD-SECURITY-ENGINEER) - Google Cloud Actual Exam Questions

Last updated on May 14, 2026

97% Exam Compliance
224 Total Questions
1
Question

Your company is storing sensitive data in Cloud Storage. You want a key generated on-premises to be used in the encryption process. What should you do?

Options
A

Use the Cloud Key Management Service to manage a data encryption key (DEK).

B

Use the Cloud Key Management Service to manage a key encryption key (KEK). 4XHVWLRQV�DQG�$QVZHUV�3') ������

C

Use customer-supplied encryption keys to manage the data encryption key (DEK).

D

Use customer-supplied encryption keys to manage the key encryption key (KEK).

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

In a shared security responsibility model for IaaS, which two layers of the stack does the customer share responsibility for? (Choose two.)

Select 2
Options
A

Hardware

B

Network Security

C

Storage Encryption

D

Access Policies 4XHVWLRQV�DQG�$QVZHUV�3') ������

E

Boot

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

Your organization is using Active Directory and wants to configure Security Assertion Markup Language (SAML). You must set up and enforce single sign-on (SSO) for all users. What should you do?

Options
A

Manage SAML profile assignments. •

B

Create a new SAML profile. •

C

Configure prerequisites for OpenID Connect (OIDC) in your Active Directory (AD) tenant •

D

Enable OpenID Connect (OIDC) in your Active Directory (AD) tenant. •

E

Upload the X.509 certificate. •

F

Populate the sign-in and sign-out page URLs. •

G

Verify the AD domain. •

H

Verify the domain.

I

Enable the change password URL. •

J

Upload the X.509 certificate. •

K

Decide which users should use SAML. •

L

Configure Entity ID and ACS URL in your IdP.

M

Configure Entity ID and ACS URL in your IdP

N

Assign the pre-configured profile to the select organizational units (OUs) and groups.

O

1- Create a new SAML profile. •

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

A customer has an analytics workload running on Compute Engine that should have limited internet access. Your team created an egress firewall rule to deny (priority 1000) all traffic to the internet. The Compute Engine instances now need to reach out to the public repository to get security updates. What should your team do? 4XHVWLRQV�DQG�$QVZHUV�3') ������

Options
A

Create an egress firewall rule to allow traffic to the CIDR range of the repository with a priority greater than 1000.

B

Create an egress firewall rule to allow traffic to the CIDR range of the repository with a priority less than 1000.

C

Create an egress firewall rule to allow traffic to the hostname of the repository with a priority greater than 1000.

D

Create an egress firewall rule to allow traffic to the hostname of the repository with a priority less than 1000.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

A customer’s company has multiple business units. Each business unit operates independently, and each has their own engineering group. Your team wants visibility into all projects created within the company and wants to organize their Google Cloud Platform (GCP) projects based on different business units. Each business unit also requires separate sets of IAM permissions. Which strategy should you use to meet these needs?

Options
A

Create an organization node, and assign folders for each business unit.

B

Establish standalone projects for each business unit, using gmail.com accounts.

C

Assign GCP resources in a project, with a label identifying which business unit owns the resource.

D

Assign GCP resources in a VPC for each business unit to separate network access. 4XHVWLRQV�DQG�$QVZHUV�3') ������

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.