Cloud Pass
One connected path to exam readinessSuccess StoriesFAQBlog
  1. Cloud Pass
  2. GCP
  3. Google Professional Cloud Security Engineer

Exam preparation hub

GCP · Professional

Google Professional Cloud Security Engineer

Prepare for this GCP Professional exam. Try an exam-style question first, then review the exam domains and practice-test format.

Browse 340+ Questions

Exam preparation details

340+

Practice Questions

5

Exam Domains

3

Practice Tests

120

Minutes

Practice-test format

50 Questions · 120 Minutes · Passing Score 700/1000

Practice QuestionsExam DomainsSuccess Stories

Try it free

Answer a question and inspect the explanation quality

Submit your answer to see the reasoning for every option, key learning points, and related services.

Practice Questions 1

Your company uses GitLab CI/CD with shared SaaS runners to build and deploy services to Google Cloud. Security policy requires that pipelines obtain short‑lived credentials (maximum 15 minutes), avoid storing service account keys, and restrict access to a single repository path (group/project: acme/platform/app) and branch (main) using OIDC token claims. You must allow the pipeline to access Google Cloud resources in the most secure way while meeting these constraints. What should you do?

Creating and storing a service account key in GitLab variables violates the requirement to avoid service account keys and introduces long-lived credentials that can be exfiltrated from shared SaaS runners. Even if masked/protected, keys are still static secrets with rotation and leakage risks. It also doesn’t naturally enforce repo-path/branch restrictions via OIDC claims; access control would be detached from the job identity.
Encrypting and committing a service account key is still key-based authentication and fails the “avoid storing service account keys” requirement. Encryption-at-rest does not eliminate the fundamental risk: the key must be decrypted at runtime, and the passphrase becomes another secret to protect. This approach increases operational burden (rotation, revocation, audit) and is not aligned with keyless best practices.
Using GKE Workload Identity is designed for workloads running on GKE, not for external SaaS runners. Exposing metadata credentials to GitLab runners is an anti-pattern and expands the attack surface; it also complicates network boundary protection and does not provide a clean way to restrict access based on GitLab OIDC claims (repo path/branch). It adds unnecessary infrastructure and does not meet the stated constraints.
Workload Identity Federation with GitLab OIDC is the secure, keyless method for external CI/CD. It enables short-lived credentials via STS token exchange, avoids service account keys entirely, and supports ABAC by mapping and enforcing OIDC claims (e.g., project_path and ref) with an attribute condition restricted to acme/platform/app and main. Granting Workload Identity User to the provider principal and least-privilege roles to the service account meets security policy requirements.

Exam Domains

Use the exam weights to decide which domains to study first.

Configuring AccessWeight 25%
Securing Communications and Establishing Boundary ProtectionWeight 22%
Ensuring Data ProtectionWeight 23%
Managing OperationsWeight 19%
Supporting Compliance RequirementsWeight 11%

Success Stories(6)

P
P***********Nov 25, 2025

Study period: 2 months

I used Cloud Pass during my last week of study, and it helped reinforce everything from beyondcorp principles to securing workloads. It’s straightforward, easy to use, and genuinely helps you understand security trade-offs.

길
길**Nov 23, 2025

Study period: 1 month

I completed every question before taking the exam and passed right away. A little over 40 percent felt similar, and I solved the unfamiliar types using my understanding of the concepts.

D
D***********Nov 12, 2025

Study period: 1 month

I would like to thanks the team of Cloud Pass for these greats materials. This helped me passing the exam last week. Most of the questions in exam as the sample questions and some were almost similar. Thank you again Cloud Pass

O
O**********Oct 29, 2025

Study period: 1 month

Absolutely invaluable resource to prepare for the exam. Explanations and questions are spot on to give you a sense of what is expected from you on the actual test.

O
O**********Oct 29, 2025

Study period: 1 month

I realized I was weak in log-based alerts and access boundary configurations. Solving questions here helped me quickly identify and fix those gaps. The question style wasn’t identical to the exam, but the concepts were spot-on.

Other GCP Certifications

Google Professional Cloud DevOps Engineer

Google Professional Cloud DevOps Engineer

Professional

Google Associate Cloud Engineer

Google Associate Cloud Engineer

Associate

Google Professional Cloud Network Engineer

Google Professional Cloud Network Engineer

Professional

Google Associate Data Practitioner

Google Associate Data Practitioner

Associate

Google Cloud Digital Leader

Google Cloud Digital Leader

Foundational

Google Professional Cloud Architect

Google Professional Cloud Architect

Professional

Google Professional Cloud Database Engineer

Google Professional Cloud Database Engineer

Professional

Google Professional Data Engineer

Google Professional Data Engineer

Professional

Google Professional Cloud Developer

Google Professional Cloud Developer

Professional

Google Professional Machine Learning Engineer

Google Professional Machine Learning Engineer

Professional

Start Practicing Now

Download Cloud Pass and start practicing all Google Professional Cloud Security Engineer exam questions.

Get it on Google PlayDownload on the App Store

Cloud Pass

Study every question with Cloud Pass

Practice exam-style questions, review every option, and ask the AI Tutor whenever you get stuck.

Get it on Google PlayDownload on the App Store
Cloud PassCloud Pass

IT Certification Practice App

Certifications

AWSGoogle CloudMicrosoft Azure

Resources

FAQBlog

Legal

Privacy PolicyTerms of Service

Company

ContactDelete Account

© Copyright 2026 Cloud Pass, All rights reserved.

support@cloudpass.pro