GCP Security Engineer Practice

Practice 60 original Google Cloud Professional Cloud Security Engineer questions covering identity, data, network, workload, operations and compliance, with detailed explanations.

Level: Google Cloud Professional Cloud Security Engineer Difficulty: advanced 60 questions 60 min
Choose a practice mode, answer each GCP Security Engineer question, then review the explanation. Wrong answers are saved locally for review.
Day streak: 0 days Saved only on this device
Progress 0 / 60
Question 1

What is Cloud IAM?

Select an answer
Question 2

What is a service account?

Select an answer
Question 3

What is a custom role?

Select an answer
Question 4

What is an organization policy?

Select an answer
Question 5

What is workload identity federation?

Select an answer
Question 6

What is Identity-Aware Proxy?

Select an answer
Question 7

What is Cloud Identity?

Select an answer
Question 8

What is a group in IAM?

Select an answer
Question 9

What is least privilege?

Select an answer
Question 10

Match each identity concept to its purpose.

Question 11

What is Cloud KMS?

Select an answer
Question 12

What is a customer-managed encryption key?

Select an answer
Question 13

What is Cloud DLP?

Select an answer
Question 14

What is encryption at rest?

Select an answer
Question 15

What is encryption in transit?

Select an answer
Question 16

What is a retention policy?

Select an answer
Question 17

What is Secret Manager?

Select an answer
Question 18

What is data access logging?

Select an answer
Question 19

What is key rotation?

Select an answer
Question 20

Match each data protection concept to its purpose.

Question 21

What is a firewall rule?

Select an answer
Question 22

What is Cloud Armor?

Select an answer
Question 23

What is VPC peering?

Select an answer
Question 24

What is Private Google Access?

Select an answer
Question 25

What is Cloud NAT?

Select an answer
Question 26

What is Shared VPC?

Select an answer
Question 27

What is packet mirroring?

Select an answer
Question 28

What is VPC Service Controls?

Select an answer
Question 29

What is Private Service Connect?

Select an answer
Question 30

Match each network security concept to its purpose.

Question 31

What is GKE hardening?

Select an answer
Question 32

What is Binary Authorization?

Select an answer
Question 33

What is Container Analysis?

Select an answer
Question 34

What is Workload Identity in GKE?

Select an answer
Question 35

What is a Shielded VM?

Select an answer
Question 36

What is a Confidential VM?

Select an answer
Question 37

What is OS patch management?

Select an answer
Question 38

What is a namespace in Kubernetes?

Select an answer
Question 39

What is a private GKE cluster?

Select an answer
Question 40

Match each workload security concept to its purpose.

Question 41

What is Security Command Center?

Select an answer
Question 42

What is Cloud Logging?

Select an answer
Question 43

What is Cloud Monitoring?

Select an answer
Question 44

What are audit logs?

Select an answer
Question 45

What is an alerting policy?

Select an answer
Question 46

What is Event Threat Detection?

Select an answer
Question 47

What is a vulnerability scan?

Select an answer
Question 48

What is a security finding?

Select an answer
Question 49

What is log-based alerting?

Select an answer
Question 50

Match each security operations concept to its purpose.

Question 51

What is a compliance framework?

Select an answer
Question 52

What is a resource hierarchy?

Select an answer
Question 53

What is data residency?

Select an answer
Question 54

What is Assured Workloads?

Select an answer
Question 55

What is Access Transparency?

Select an answer
Question 56

What is a quota?

Select an answer
Question 57

What is a label?

Select an answer
Question 58

What is a folder in the resource hierarchy?

Select an answer
Question 59

What is a compliance report?

Select an answer
Question 60

Match each compliance concept to its purpose.