Free sample, no account needed

    GCP - Professional Cloud Security Engineer Practice Questions & Free Practice Exam

    5 free GCP - Professional Cloud Security Engineer practice questions below, with instant explanations. The full simulator contains hundreds of exam-style questions across every topic.

    1Question 1

    On-call engineers need `roles/cloudsql.editor` only when an incident is open. Each grant must require approval from a second human, must revoke automatically after at most two hours, and must leave no standing permission afterward. Which control meets all three requirements?

    2Question 2

    Routine project IAM administration on a Google Cloud organization should NOT use which principal?

    3Question 3

    An engineer runs a fleet of healthcare imaging Compute Engine VMs without external IP addresses in one region. The VMs must initiate outbound connections to a public container registry for image pulls, but no URL filtering or TLS inspection is required, and all inbound paths from the internet must stay closed. Which Google Cloud service satisfies the requirement with the smallest configuration footprint?

    4Question 4

    Which property of a Secret Manager secret is permanent and cannot be changed after the secret is created?

    5Question 5

    On a GKE Standard cluster, which party operates the Kubernetes control plane components such as the API server, scheduler, and etcd?

    Create a free account and keep going

    Free members study the full GCP - Professional Cloud Security Engineer theory course and get a much larger slice of the question bank, with progress tracking that remembers exactly where they stopped.

    Full theory course

    Every chapter, free

    More practice questions

    Beyond this sample

    Progress & explanations

    Picks up where you left