PCSE sample questions with answers

10 free practice questions for the Professional Cloud Security Engineer exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Configuring access

A studio's CI pushes images to Artifact Registry through a workload identity pool whose OIDC provider is bound pool-wide to the Artifact Registry Writer role. A reviewer shows that a pipeline from an unrelated repository in the same CI tenant can push. No credential file may be stored in CI. What should you do?

  1. A.

    Add an attribute condition accepting only the studio's repository claim, and bind the role to that narrowed principal set.

  2. B.

    Move the binding to the default Cloud Build service account and trigger builds by webhook.

  3. C.

    Create a service account key for a dedicated push account and store it as an encrypted variable in the pipeline.

  4. D.

    Keep the pool-wide binding but reduce the provider's token lifetime to the minimum.

Show answer

Answer: A

An attribute condition on the provider plus a binding to the narrowed principal set restricts token exchange to the studio's own repository.

  • A. Attribute conditions reject token exchange for other repositories, and binding to the narrowed principal set stops an accepted token from mapping to broad access.
  • B. Changing build systems does not repair the trust relationship, and exposing the broad default Cloud Build identity to an external trigger widens the problem.
  • C. A downloadable key is exactly the credential Workload Identity Federation exists to remove, and the requirement forbids storing credential files.
  • D. Token lifetime limits how long a credential lasts, not who may obtain one; an unrelated pipeline can keep requesting fresh tokens.
Question 2Configuring access

After a project owner deleted a log sink and the bucket holding evidence, a bank wants nobody in the production folder to delete log sinks or buckets, whatever role they hold. A four-person incident group must still delete them in a declared emergency, and existing bindings must not be edited. Which guardrail should you implement?

  1. A.

    An organization policy constraint on the folder blocking deletion of Logging and Storage resources.

  2. B.

    Custom roles replacing Owner throughout the folder, omitting the two delete permissions.

  3. C.

    An IAM deny policy on the production folder denying both delete permissions to all principals, with an exception for the incident group.

  4. D.

    A locked retention policy on the evidence bucket plus alerts on deletion attempts.

Show answer

Answer: C

IAM deny policies evaluate before allow policies and apply to every principal including Owners, with exception principals for the incident group.

  • A. Organization policy constraints govern resource configuration, not which principals may call particular API methods such as deleting a sink.
  • B. Rewriting hundreds of bindings as custom roles is large and fragile, and a single later grant of a predefined role reopens the gap.
  • C. Deny policies are evaluated before allow policies, are inherited from the folder, and support exception principals for the incident group.
  • D. Retention locks protect object content rather than the sink, and alerting on attempts is detective when the requirement asks for prevention.
Question 3Configuring access

A nightly container on a partner's infrastructure federates into Google Cloud and impersonates a service account holding Storage Object Admin over 40 buckets, although it touches one bucket for 20 minutes. Auditors want the credential as narrow and short-lived as the job. Which two techniques should you apply? (Choose TWO.)

Choose 2.

  1. A.

    Apply a credential access boundary when exchanging the token so it grants object access to one bucket only.

  2. B.

    Call the IAM Service Account Credentials API for a short-lifetime access token instead of holding one all night.

  3. C.

    Create a service account key with a custom expiry timestamp inside the key file.

  4. D.

    Add an IAM condition allowing access only from the partner's public IP range.

  5. E.

    Grant Storage Admin instead so the job can create and delete its own bucket.

Show answer

Answer: A, B

Short-lived tokens from the Service Account Credentials API plus a credential access boundary produce a credential limited to one bucket and to the length of the job.

  • A. A credential access boundary produces a downscoped token limited to one bucket, so a compromised run cannot reach the other 39.
  • B. Generating an access token with an explicit short lifetime bounds the credential to the duration of the job instead of the whole night.
  • C. Service account key files have no Google-enforced expiry field; a key remains valid until it is deleted or its account is disabled.
  • D. A source-IP condition limits where a credential may be used, not which buckets it reaches, so the 40-bucket exposure remains inside the partner network.
  • E. Storage Admin adds bucket-level administration on top of object access, widening the blast radius the auditors want narrowed.
Question 4Configuring access

A media group blocks public Cloud Storage access with an organization-node constraint. A new subsidiary must publish marketing assets from two buckets in three projects. The exception must be centrally governed, visible in inventory, and impossible for the subsidiary's owners to apply themselves, and the hierarchy cannot change. Which mechanism should you use?

  1. A.

    A resource manager tag attached centrally, with a conditional organization policy rule that relaxes the constraint where the tag is present.

  2. B.

    A project-level organization policy on each of the three projects with inheritance disabled.

  3. C.

    Removal of the organization-level constraint, applied instead to every other folder.

  4. D.

    The Organization Policy Administrator role granted to the subsidiary's project owners.

Show answer

Answer: A

Tag-conditioned organization policy grants the exception centrally and makes it visible, because only the tag holder can attach the tag that relaxes the constraint.

  • A. Tag-conditioned policy keeps the exception centrally controlled, visible in inventory, and revocable by detaching a tag the subsidiary cannot attach.
  • B. A project-level override with inheritance disabled is invisible outside that project's policy and can be set by any project policy administrator.
  • C. Removing the organization-level default means anything outside the re-applied folders is unprotected, inverting the secure default for one exception.
  • D. Delegating Organization Policy Administrator lets the subsidiary relax any constraint, which is the loss of central governance the security lead refused.
Question 5Configuring access

A payments processor federates every employee sign-in to an external identity provider. Compliance requires multi-factor authentication on every sign-in to Google Cloud with no exception, and an engineer proposes enforcing 2-Step Verification for all users in Cloud Identity. Recommend the design that actually satisfies the control.

  1. A.

    Enforce 2-Step Verification for all users and rely on it to challenge federated users after the identity provider's assertion.

  2. B.

    Require multi-factor authentication at the external identity provider, and enforce security-key 2-Step Verification on the SSO-excluded super administrator accounts.

  3. C.

    Bind an Access Context Manager access level requiring a managed device to every project.

  4. D.

    Disable the identity provider for privileged users and have them use Google passwords with 2-Step Verification.

Show answer

Answer: B

When sign-in is federated, the identity provider performs the challenge, so multi-factor must be enforced there, with Cloud Identity 2-Step Verification covering the SSO-excluded break-glass administrators.

  • A. Google's 2-Step Verification applies when Google authenticates the user; it does not challenge a user who arrived through a federated assertion.
  • B. Multi-factor is enforced where the challenge happens, at the identity provider, while Cloud Identity 2-Step Verification covers the SSO-excluded break-glass accounts.
  • C. An access level adds device and network conditions to authorization decisions; it is not a second authentication factor and does not satisfy the control.
  • D. Removing privileged users from single sign-on discards the identity provider's conditional access and risk signals for the highest-value accounts.
Question 6Configuring access

Eleven external auditors need seven weeks of read-only access to two projects. Legal will not create Cloud Identity accounts for non-employees, the audit firm insists its staff authenticate at its own OIDC provider under its own MFA policy, and access must end with the engagement. How should you provide the access?

  1. A.

    Grant viewer roles to a group holding the auditors' personal Google accounts.

  2. B.

    Create a workforce identity pool with the firm's OIDC provider and grant viewer roles to its principal set.

  3. C.

    Create eleven Cloud Identity accounts in a separate organizational unit and delete them afterwards.

  4. D.

    Create a workload identity pool with the firm's OIDC provider and have auditors exchange tokens from their workstations.

Show answer

Answer: B

Workforce Identity Federation lets an external workforce authenticate at its own identity provider and use the console, gcloud and BigQuery without any Cloud Identity account being created.

  • A. Consumer Google accounts cannot be governed by the company: multi-factor cannot be enforced, sessions cannot be revoked centrally, and the identities outlive the engagement.
  • B. A workforce identity pool federates the audit firm's OIDC users into IAM without provisioning accounts, supports console and gcloud, and is revoked by disabling the provider.
  • C. Creating managed accounts for non-employees is exactly what the legal team refused, and it adds licensing, tracking and offboarding work for a seven-week engagement.
  • D. Workload Identity Federation is designed for applications and CI systems; it does not provide a human sign-in experience for the Cloud Console.
Question 7Configuring access

A pipeline creates about 300 Google groups per quarter using a service account key with domain-wide delegation that impersonates a super administrator, which security says can act on any user's data. It must keep running unattended without downloaded key files. What should you do?

  1. A.

    Grant the pipeline's service account Organization Administrator to manage groups.

  2. B.

    Keep domain-wide delegation but limit it to the group scopes and rotate the key monthly.

  3. C.

    Assign Groups Admin to a dedicated service account and call the Cloud Identity Groups API using short-lived impersonated tokens.

  4. D.

    Have the pipeline write a CSV file that Google Cloud Directory Sync reads on its next scheduled synchronization run.

Show answer

Answer: C

A service account with the Groups Admin role calling the Cloud Identity Groups API removes domain-wide delegation entirely, and impersonation removes the key file.

  • A. Organization Administrator manages the resource hierarchy, not Cloud Identity groups, so the pipeline would fail while holding an extremely broad grant.
  • B. Narrowed scopes still leave a delegation that acts as users, and a rotated key is still a downloadable long-lived credential the requirement forbids.
  • C. The Groups Admin role on a service account plus the Cloud Identity Groups API removes delegation, and impersonation supplies short-lived credentials instead of a key file.
  • D. GCDS synchronizes from an authoritative directory on a schedule; driving it from a pipeline-generated CSV is unsupported and introduces batch latency.
Question 8Configuring access

A security team must introduce a strict access level for console and API access across an organization of 12,000 users, and has been told that a lockout would be unacceptable. They want to observe which real requests the level would refuse before it refuses anything. Which two practices should they adopt? (Choose TWO.)

Choose 2.

  1. A.

    Lower the Google Cloud session length so that affected users re-authenticate and pick up the new level sooner.

  2. B.

    Apply the access level in a dry-run or monitoring configuration first, so violations are reported without being enforced.

  3. C.

    Set the access level to combine its conditions with OR so that any single condition admits the request.

  4. D.

    Grant the security team the organization administrator role so it can lift the restriction quickly if needed.

  5. E.

    Begin enforcement for a small pilot group before widening the scope to the whole organization.

  6. F.

    Disable Endpoint Verification during the rollout so device conditions are ignored until enforcement begins.

Show answer

Answer: B, E

Observing violations without enforcing them, then enforcing for a pilot group first, are the two practices that surface real impact before it becomes an outage.

  • A. Shortening sessions pushes users onto an untested control sooner, increasing rather than reducing risk.
  • B. Dry-run or monitoring reporting shows which real requests would be refused while refusing none of them.
  • C. Combining conditions with OR loosens the level and changes what the control means rather than de-risking it.
  • D. A standing organization administrator grant is a large privilege to hold for a hypothetical rollback.
  • E. A pilot group bounds the failure domain once enforcement genuinely begins.
  • F. Disabling Endpoint Verification removes the signal the level depends on, so the observation measures the wrong thing.
Question 9Configuring access

An internal expenses application runs on Compute Engine behind an HTTPS load balancer and is currently reachable by anyone who knows its address. It must be reachable only by members of the finance group, only from company-managed devices, and the application's source code cannot be modified because the vendor no longer supports it. What should you do?

  1. A.

    Publish the application on an external address and restrict it with a Cloud Armor policy that lists the home address of each finance user.

  2. B.

    Require each finance user to connect over a virtual private network and authenticate to the application with a shared password.

  3. C.

    Put the instances in a VPC Service Controls perimeter and add the finance group to the perimeter's access level.

  4. D.

    Enable Identity-Aware Proxy on the backend, grant the finance group the IAP-secured Web App User role, and require an access level describing managed devices.

Show answer

Answer: D

Identity-Aware Proxy provides application-level authentication and authorization without code changes, and an access level adds the managed-device requirement.

  • A. Cloud Armor filters network traffic to a publicly exposed application and has no notion of identity or device posture.
  • B. This is network-perimeter thinking plus a shared credential, which removes per-user attribution entirely.
  • C. VPC Service Controls guards Google Cloud services against exfiltration; it does not front or authorize a customer application.
  • D. IAP authenticates and authorizes before the request reaches the backend, and an access level adds the managed-device condition.
Question 10Configuring access

A company wants a single classification value attached high in the hierarchy so that every project and resource beneath it is treated as regulated by conditional IAM bindings and by policy, with the ability to override the value on one subsidiary folder. Which mechanism should be used?

  1. A.

    A label applied to the folder, since labels are inherited by every project and resource beneath the folder they are set on.

  2. B.

    An organization policy constraint whose allowed value carries the classification string.

  3. C.

    A Resource Manager tag bound to the folder, since tag bindings are inherited by descendants and can be overridden lower down.

  4. D.

    A project-level metadata entry replicated into every project by the project factory.

Show answer

Answer: C

Tag bindings are inherited down the hierarchy and can be overridden on a descendant, and tags are readable by IAM conditions and by organization policy.

  • A. Labels are per-resource metadata, are not inherited, and are not usable as a condition or policy input this way.
  • B. A constraint's allowed values restrict resource configuration; a constraint is not a store for classification data.
  • C. Tag bindings are inherited, can be overridden on a descendant, and are readable by IAM conditions and organization policy.
  • D. Metadata is per project or instance and plays no part in hierarchy inheritance or IAM evaluation.

Keep going with 490 more PCSE questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

PCSE sample questions with answers (10 free) · CertifyCloudx