Google Cloud Professional Cloud Security Engineer Practice Test
Gana confianza para Google Cloud Professional Cloud Security Engineer. Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.
Probar una preguntaDescripción y detalles del examen
The Google Cloud Professional Cloud Security Engineer certification validates advanced technical skills in designing, implementing, and managing security controls and governance frameworks within the Google Cloud Platform (GCP) ecosystem. This credential demonstrates a professional's ability to secure infrastructure, applications, data, and operations using Google Cloud's native security tools and services. Certified engineers are proficient in configuring identity and access management (IAM), network security architectures, data protection mechanisms, and security operations (SecOps) workflows. The certification is recognized globally as a benchmark for cloud security expertise, signaling to employers a deep, practical understanding of the shared responsibility model, threat mitigation, and compliance automation in a cloud-native context. Earning this certification positions you as a critical asset for organizations undergoing digital transformation, where securing cloud workloads is paramount to business continuity and risk management.
Preguntas de Muestra
Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.
During a security review of a GKE cluster, an auditor finds that all pods are running as the Compute Engine default service account, which has `roles/editor` at the project level. The security team wants to remediate this using the principle of least privilege without service account keys. Which approach should they implement?
A Cloud Run service needs to connect to a Cloud SQL instance that has only a private IP (no public IP). By default, Cloud Run functions/services run in a Google-managed network without access to customer VPCs. What must be configured to allow the Cloud Run service to reach the Cloud SQL private IP?
A large enterprise has granted `roles/bigquery.dataEditor` to a broad Google Group for data pipeline work. A compliance audit identifies that one subgroup -" contractors in group `[email protected]` -" must never be able to delete BigQuery datasets, even if they inherit that role through the group. The security team considers using an IAM Deny Policy. What is true about how IAM Deny Policies interact with allow policies in this scenario?
A GKE Standard cluster runs pods that process cardholder data. The auditor asks for node boot integrity, workload identity without keys, and encryption of Kubernetes secrets at the application layer with a customer-managed key. Which combination addresses all three?
A security team enables automatic key rotation with a 90-day rotation period on a Cloud KMS key used for CMEK encryption of a Cloud Storage bucket. A compliance officer asks: "After the key rotates, will previously stored objects need to be re-encrypted with the new key version?" What is the correct answer?
Oportunidades profesionales y salario
Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.
Qué temas cubre este examen
Usa las ponderaciones publicadas de los dominios para planificar tu estudio. Los resultados de práctica no predicen tu puntuación en el examen de certificación.