Official Bank 0/314

Professional Cloud Security Engineer Exam (Google Cloud) - Google Cloud Exam Questions

Last updated on July 22, 2026

97% Exam Compliance
314 Total Questions
1
Question
Your application is deployed as a highly available cross-region solution behind a global external HTTP(S) load balancer. You notice significant spikes in traffic from multiple IP addresses but it is unknown whether the IPs are malicious. You are concerned about your application's availability. You want to limit traffic from these clients over a specified time interval.

What should you do?
Options
A Configure a rate_based_ban action by using Google Cloud Armor and set the ban_duration_sec parameter to the specified time interval.
B Configure a firewall rule in your VPC to throttle traffic from the identified IP addresses.
C Configure a deny action by using Google Cloud Armor to deny the clients that issued too many requests over the specified time interval.
D Configure a throttle action by using Google Cloud Armor to limit the number of requests per client over a specified time interval.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
An organization is migrating from their current on-premises productivity software systems to G Suite. Some network security controls were in place that were mandated by a regulatory body in their region for their previous on-premises system. The organization’s risk team wants to ensure that network security controls are maintained and effective in G Suite. A security architect supporting this migration has been asked to ensure that network security controls are in place as part of the new shared responsibility model between the organization and Google Cloud.

What solution would help meet the requirements?
Options
A Ensure that firewall rules are in place to meet the required controls.
B Set up an array of Virtual Private Cloud (VPC) networks to control network security as mandated by the relevant regulation.
C Set up Cloud Armor to ensure that network security controls can be managed for G Suite.
D Network security is a built-in solution and Google’s Cloud responsibility for SaaS products like G Suite.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
You are troubleshooting access denied errors between Compute Engine instances connected to a Shared VPC and BigQuery datasets. The datasets reside in a project protected by a VPC Service Controls perimeter. What should you do?
Options
A Add the host project containing the Shared VPC to the service perimeter.
B Create a perimeter bridge between the service project where the Compute Engine instances reside and the perimeter that contains the protected BigQuery datasets.
C Add the service project where the Compute Engine instances reside to the service perimeter.
D Create a service perimeter between the service project where the Compute Engine instances reside and the host project that contains the Shared VPC.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
You are a member of your company's security team. You have been asked to reduce your Linux bastion host external attack surface by removing all public IP addresses. Site Reliability Engineers (SREs) require access to the bastion host from public locations so they can access the internal VPC
while off-site. How should you enable this access?
Options
A Implement Cloud VPN for the region where the bastion host lives.
B Implement Google Cloud Armor in front of the bastion host.
C Implement OS Login with 2-step verification for the bastion host.
D Implement Identity-Aware Proxy TCP forwarding for the bastion host.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
You discovered that sensitive personally identifiable information (PII) is being ingested to your Google Cloud environment in the daily ETL process from an on-premises environment to your BigQuery datasets. You need to redact this data to obfuscate the PII, but need to re-identify it for data analytics purposes. Which components should you use in your solution? (Choose two.)
Select 2
Options
A Cloud Data Loss Prevention with deterministic encryption using AES-SIV
B Secret Manager
C Cloud Data Loss Prevention with automatic text redaction
D Cloud Key Management Service
E Cloud Data Loss Prevention with cryptographic hashing
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.