Google CloudProfessional

Professional Cloud Security Engineer

PCSE

Design and implement secure workloads and infrastructure on Google Cloud.

Duration
120 min
Exam questions
50–60
Passing score
Pass / Fail (undisclosed)
Exam fee
$200
Question formats:Multiple choiceMultiple response
Free plan
3 free papers
Free account
Mocks locked
Pro only
Upgrade to Pro
Every paper and mock exam.
See Pro

Start with free papers Free

You get 3 free practice papers with your plan.

Free
Mixed paper 1
Domain 1 · 25 questions
Free
Mixed paper 2
Domain 1 · 25 questions
Free
Mixed paper 3
Domain 1 · 25 questions

Domain papers 500 questions

Free
Mixed paper 1
25 questions · 60 min
Free
Mixed paper 2
25 questions · 60 min
Free
Mixed paper 3
25 questions · 60 min
Pro
Mixed paper 4
25 questions · 60 min
Pro
Mixed paper 5
25 questions · 60 min
Pro
Mixed paper 6
25 questions · 60 min
Pro
Mixed paper 7
15 questions · 36 min

Mock exams Pro

Full-length, exam-like practice tests. Available with Pro.

Mock exam 1
55 questions · 120 min
Mock exam 2
55 questions · 120 min
Mock exam 3
55 questions · 120 min

Try a sample question

All 10 sample questions →
Question 1Configuring access

A studio's CI pushes images to Artifact Registry through a workload identity pool whose OIDC provider is bound pool-wide to the Artifact Registry Writer role. A reviewer shows that a pipeline from an unrelated repository in the same CI tenant can push. No credential file may be stored in CI. What should you do?

  1. A.

    Add an attribute condition accepting only the studio's repository claim, and bind the role to that narrowed principal set.

  2. B.

    Move the binding to the default Cloud Build service account and trigger builds by webhook.

  3. C.

    Create a service account key for a dedicated push account and store it as an encrypted variable in the pipeline.

  4. D.

    Keep the pool-wide binding but reduce the provider's token lifetime to the minimum.

Show answer

Answer: A

An attribute condition on the provider plus a binding to the narrowed principal set restricts token exchange to the studio's own repository.

  • A. Attribute conditions reject token exchange for other repositories, and binding to the narrowed principal set stops an accepted token from mapping to broad access.
  • B. Changing build systems does not repair the trust relationship, and exposing the broad default Cloud Build identity to an external trigger widens the problem.
  • C. A downloadable key is exactly the credential Workload Identity Federation exists to remove, and the requirement forbids storing credential files.
  • D. Token lifetime limits how long a credential lasts, not who may obtain one; an unrelated pipeline can keep requesting fresh tokens.

What's on the exam

5 domains · 14 task statements, straight from the official exam guide (as of 2026-09-14).

  1. 1.1Managing Cloud Identity
    • Configuring Google Cloud Directory Sync and implement single sign-on (SSO) with a third-party identity provider.
    • Managing a super administrator account.
    • Automating the user lifecycle management process.
    • Administering user accounts and groups programmatically.
    • Configuring Workforce Identity Federation
  2. 1.2Managing service accounts
    • Securing and protecting service accounts (including default service accounts).
    • Identifying scenarios requiring service accounts.
    • Creating, disabling, and authorizing service accounts.
    • Securing, auditing, and mitigating the usage of service account keys.
    • Managing and creating short-lived credentials.
    • Configuring Workload Identity Federation.
    • Managing service account impersonation.
  3. 1.3Managing authentication
    • Creating a password and session management policy for user accounts.
    • Setting up Security Assertion Markup Language (SAML) and OAuth.
    • Configuring and enforcing 2-step verification.
  4. 1.4Managing and implementing authorization controls
    • Managing privileged roles and separation of duties with Identity and Access Management (IAM) roles and permissions.
    • Managing IAM and access control list (ACL) permissions.
    • Granting permissions to different types of identities using IAM conditions and IAM deny policies.
    • Defining access control at the organization, folder, project, and resource level using the principle of least privilege.
    • Configuring Access Context Manager.
    • Applying Policy Intelligence.
    • Managing permissions through groups.
    • Identifying use cases and configuring Privileged Access Manager.
  5. 1.5Defining the resource hierarchy
    • Managing folders and projects at scale.
    • Managing pre-built or custom organization policies for the organization, folders, and projects.
    • Using the resource hierarchy for access control and permissions inheritance.

Outline reproduced from the vendor's public exam guide for study reference.Official guide

PCSE practice — frequently asked questions

Are these real PCSE exam questions?

No. Every question on CertifyCloudx is original, written by us against Google Cloud's publicly available PCSE exam guide to rehearse the skills it lists. None are actual exam questions, and CertifyCloudx is not affiliated with or endorsed by Google Cloud.

How many PCSE practice questions are there?

500 practice questions, including 3 full-length timed mock exams and 48 domain papers of up to 25 questions (mixed and by topic). Every question has a detailed explanation of why the right answer wins and why each distractor loses.

Is the content up to date with the current PCSE exam guide?

The questions are written against the PCSE exam guide dated 2026-09-14, and we revise them when Google Cloud updates the guide.

What question formats are covered?

The same formats the real PCSE uses: Multiple choice, Multiple response. Each is rendered and graded the way the exam does it.

How long is the PCSE exam and how many questions does it have?

According to Google Cloud's published exam details: 50–60 questions, 120 minutes, passing score Pass / Fail (undisclosed). Our mock exams use the same time limit, with a question count in the middle of that range. Always confirm current details with Google Cloud before booking.

Can I practise PCSE for free?

Yes. 3 papers are free, with up to 10 questions a day on the free plan and no card needed. Pro unlocks every paper and mock exam with no daily limit.

Does CertifyCloudx guarantee that I will pass?

No practice material can guarantee a result. CertifyCloudx helps you find and close your weak areas — accuracy by exam-guide domain and topic shows what to study next.