表示モード
画像位置
文字位置
理解度の自動記録
Q1Google Professional Cloud Security Engineer
Q1. A company’s routine network security review involves verifying an application’s communication paths, analyzing request handling, and inspecting firewall rules.
The company wants a setup where the development team can deploy new applications without having to go through this entire review each time.
How should you advise them?
Show answer
Correct answer: B. Mandate the adoption of Infrastructure as Code (IaC) and perform static analysis within the CI/CD pipeline to enforce policies.
Because manual reviews every time impose a heavy burden on development, the best approach is to define infrastructure as code (IaC) and automatically detect policy violations through static analysis within the CI/CD pipeline.Since security and compliance standards can be validated automatically before deployment, control is maintained while development speed is preserved.Inspection via Forseti or a VPC router only detects issues after the fact in production and does not provide preventive control.On the exam, remember that IaC plus in-pipeline policy checks is the correct answer as the “shift-left” approach that automates reviews and applies guardrails early.Google Cloud documentation: Policy validation for Terraform configurations
Q2Google Professional Cloud Security Engineer
Q2. To meet a PCI DSS requirement, an organization wants to ensure that all outbound traffic is explicitly permitted.
Which cloud services can meet this requirement without adding compensating controls (choose 2)?
Show answer
Correct answer: C, D
Managed services such as App Engine and Cloud Functions let you set ingress firewall rules, but by default they provide no mechanism to control egress (outbound) traffic.The PCI DSS requirement demands ensuring that all outbound traffic is explicitly permitted.Compute Engine and GKE can explicitly control egress traffic with VPC firewall rules, so they can meet the requirement without adding compensating controls.On the exam, the deciding factor is that for requirements needing egress control, you choose IaaS or container platforms that let you directly control the network.Google Cloud documentation: PCI DSS compliance on Google Cloud
Q3Google Professional Cloud Security Engineer
Q3. Your company operates a website on Google Cloud that stores personally identifiable information (PII).
To comply with data privacy regulations, this data must be retained only for a defined period and completely deleted once that period expires.
Data that has not yet reached the retention period must not be deleted.
You want to automate this compliance process.
How should you respond?
Show answer
Correct answer: C. Store the data in a Cloud Storage bucket and configure Object Lifecycle Management on that bucket.
Cloud Storage Object Lifecycle Management can automatically delete only objects that have passed their deadline, based on conditions such as an object’s age.Because it can automatically delete only the expired PII while retaining data that has not yet reached its deadline, it matches the requirement precisely.A BigQuery table expiration applies to the entire table, and a Persistent Disk can only be deleted at the disk level, so neither is suited to fine-grained deletion based on the age of individual data.On the exam, Cloud Storage lifecycle management is the standard correct answer for retention-period-based automatic deletion.Google Cloud documentation: Object Lifecycle Management
Q4Google Professional Cloud Security Engineer
Q4. Your division is developing an advanced machine learning (ML) model that predicts customer behavior in order to improve the accuracy of promotional campaigns.
The BigQuery dataset used for training contains highly sensitive personal information.
You need to design the security controls around the AI/ML pipeline.
Data privacy must be maintained throughout the model lifecycle, and personal data must not be used in the training process.
In addition, access to this dataset must be restricted to only a limited number of authorized personnel.
How should you respond?
Show answer
Correct answer: B. Use the Cloud Data Loss Prevention (DLP) API to de-identify sensitive data before model training, and implement strict IAM policies for access control to BigQuery.
The core requirement is to prevent personal data from being used in training, and this is achieved through de-identification of the data.Cloud DLP (now Sensitive Data Protection) is a purpose-built tool that transforms sensitive elements through masking or tokenization, reducing risk while preserving usefulness.CMEK and Confidential VM are effective for encryption and runtime protection, but they are not a means of excluding personal data itself from training.Access restriction is handled by IAM.On the exam, remember that DLP / SDP is the correct answer for ensuring the privacy of the data content itself.Google Cloud documentation: De-identifying sensitive data
Q5Google Professional Cloud Security Engineer
Q5. In your division, the security team and the network engineering team need visibility into any network anomalies within and between VPCs, internal traffic between VMs, traffic between internet endpoints and VMs, and traffic from production VMs to Google Cloud services.
Which method should you use?
Show answer
Correct answer: B. Configure a Packet Mirroring policy.
Packet Mirroring replicates the full packets (including payloads) of the target VMs’ inbound and outbound traffic and sends them to inspection tools such as an IDS for detailed analysis.It broadly captures communication between VMs, between the internet and VMs, and from VMs to Google services, enabling deep network anomaly detection.VPC Flow Logs provide only a sample of flow metadata (source, destination, volume, etc.) and cannot detect payload-level anomalies.Cloud Audit Logs record administrative operations, not communication content.On the exam, Packet Mirroring is the correct answer when anomaly detection based on complete packet content is required.Google Cloud documentation: Packet Mirroring overview
Q6Google Professional Cloud Security Engineer
Q6. A security vulnerability assessment revealed that cloud administrators leave Google Cloud CLI sessions open for many days.
To reduce the risk of attackers exploiting these idle sessions, you need to set the session duration to the minimum.
How should you respond?
Show answer
Correct answer: B. Set the reauthentication frequency of Google Cloud Session Control to 1 hour.
Setting the reauthentication frequency of Google Cloud Session Control causes the gcloud CLI refresh token to expire after the specified period, requiring users to reauthenticate periodically.Setting the frequency to the minimum of 1 hour minimizes the time window in which an attacker can exploit an open session.Option A’s session control for Google services targets web sessions such as Gmail and does not control reauthentication for Google Cloud / gcloud.C and D are constraints related to service account credentials and are unrelated to interactive CLI sessions.On the exam, it is important to distinguish the scope of the two.Google Cloud documentation: Best practices for mitigating compromised OAuth tokens for gcloud CLI
Q7Google Professional Cloud Security Engineer
Q7. In your division, a service account is used to authenticate data transfers from a specific Compute Engine VM instance to a designated Cloud Storage bucket.
An engineer accidentally deleted that service account, and the application stopped working.
You want to restore the application as quickly as possible without compromising security.
How should you respond?
Show answer
Correct answer: B. Use the undelete command to restore the deleted service account.
If it is within 30 days of deletion, gcloud iam service-accounts undelete can restore the service account while preserving its original unique ID (subject ID), so existing permissions and references remain valid.Recreating with the same name changes the internal unique ID, so the previous IAM bindings are not restored and it will not work as expected.Disabling authentication compromises security, and reusing another account violates least privilege.On the exam, remember that restoration is the first choice for a recently deleted service account, and recreating with the same name does not recover its identity.Google Cloud documentation: Deleting and undeleting service accounts
Q8Google Professional Cloud Security Engineer
Q8. Your division wants to configure the Google Cloud environment so that network resources such as firewall rules, subnets, and routes can be controlled centrally.
You also have an on-premises environment that must be able to access Google Cloud resources through a private VPN connection.
These network resources must be managed by the network security team.
What kind of network design should you adopt to meet these requirements?
Show answer
Correct answer: A. A Shared VPC network consisting of a host project and service projects.
With Shared VPC, the host project centrally manages subnets, firewall rules, and routes, and multiple service projects use that common network.By having the network security team manage the host project, you achieve both centralized network control and separation of duties at the same time.VPC peering only connects networks and cannot provide centralized management, and granting the Compute Admin role per project disperses permissions and weakens control.On-premises can connect via a VPN on the host project side.On the exam, centralization of network management equals Shared VPC as the standard correct answer.Google Cloud documentation: Shared VPC
Q9Google Professional Cloud Security Engineer
Q9. You plan to deploy cloud infrastructure using a CI/CD cluster running on Compute Engine.
You want to minimize the risk of its credentials being stolen by a third party.
How should you respond?
Show answer
Correct answer: C. Create a custom service account for the cluster. Enable the organization policy constraints/iam.disableServiceAccountKeyCreation at the project level.
The best practice for workloads on Compute Engine is to attach a dedicated custom service account—rather than a user account—for authentication.By prohibiting the creation of service account keys (long-lived static credentials) with the disableServiceAccountKeyCreation constraint, the key files that would be the target of theft cease to exist.A service account attached to a VM automatically obtains short-lived tokens, so there is no need to distribute or store keys.Vault storage or the user account approach leaves the risk of leaking long-lived credentials.On the exam, prohibiting key creation is the standard means of reducing leakage risk.Google Cloud documentation: Restricting service accounts with organization policies
Q10Google Professional Cloud Security Engineer
Q10. You are developing a new application that uses only Compute Engine VMs.
This application runs 5 different batch jobs once a day.
Each batch job requires a dedicated set of permissions for Google Cloud resources outside the application.
You need a secure access design for the batch jobs that follows the principle of least privilege.
How should you respond?
Show answer
Correct answer: B. Create a general-purpose service account “g-sa” to orchestrate the batch jobs. Create one service account “b-sa-[1-5]” per batch job and grant each only the permissions its job needs. Grant g-sa the Service Account Token Creator role, use g-sa to obtain short-lived access tokens for b-sa-[1-5], and run each batch job with the respective b-sa’s permissions.
By preparing a dedicated service account (b-sa-[1-5]) for each job and granting each only the permissions it needs, you thoroughly enforce least privilege.Because g-sa is granted the Service Account Token Creator role to impersonate the service accounts and each job runs with short-lived access tokens, no long-lived keys are handled at all.An approach like Option D that generates and stores keys introduces new key leakage risk.Workload identity federation is mainly intended for federation from external IdPs.On the exam, for job isolation within GCP, “dedicated SA plus impersonation plus short-lived tokens” is the correct answer.Google Cloud documentation: Creating short-lived credentials (impersonation)
