GCP-PCSE Sample Questions

GCP-PCSE Sample Questions & Answers

Cloud Identity, service accounts, and authentication take the biggest share, next to perimeter and boundary security, preventing data loss and encrypting data at rest, in transit, and for AI workloads, automating security operations, and compliance adherence.

Launch the full GCP-PCSE simulator →

Showing 6 of 12 free samples.

  1. Question 1Beginner

    Configuring Access · Configuring Workforce Identity Federation

    A retail company has acquired a smaller startup. The startup's employees currently use Okta for identity management. The parent company wants to grant the startup's developers access to specific Google Cloud Console projects without creating new user accounts in the parent company's Google Workspace/Cloud Identity domain. Which solution should the cloud security engineer implement?

    Show answer & explanation

    Correct answer: B

    Workforce Identity Federation allows you to grant external user identities (like those managed in Okta, Azure AD, or other OIDC/SAML IdPs) access to Google Cloud resources without needing to sync them into Cloud Identity or Google Workspace. It is specifically designed for workforce users accessing the Cloud Console or APIs.

  2. Question 2Intermediate

    Configuring Access · Managing service account impersonation

    A Terraform CI/CD pipeline runs on a Google Kubernetes Engine (GKE) cluster using a dedicated service account named sa-terraform-runner. This service account needs to deploy resources across multiple projects by assuming the identity of a highly privileged service account named sa-org-admin. Which IAM role must be granted to sa-terraform-runner on the sa-org-admin service account to allow this impersonation?

    Show answer & explanation

    Correct answer: C

    To impersonate a service account and generate short-lived OAuth 2.0 access tokens, signed JWTs, or signed blobs, the principal (in this case, sa-terraform-runner) must be granted the Service Account Token Creator role (roles/iam.serviceAccountTokenCreator) on the target service account (sa-org-admin). The Service Account User role is used for attaching service accounts to resources, not for direct API impersonation.

  3. Question 3IntermediateSelect 2

    Configuring Access · Managing pre-built or custom organization policies for the organization, folders, and projects

    Kallisto Corp operates under strict European data residency laws. The compliance team mandates that no Google Cloud resources can be created outside of the europe-west1 and europe-west3 regions. Which TWO actions should the security engineer take to enforce this requirement comprehensively across the entire organization? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    To restrict the physical location of newly created resources across the entire organization, you must use the Organization Policy Service. Specifically, you configure the constraints/gcp.resourceLocations constraint at the organization node and set the allowed values to the required European regions.

    To restrict the physical location of newly created resources across the entire organization, you must use the Organization Policy Service. Specifically, you configure the constraints/gcp.resourceLocations constraint at the organization node and set the allowed values to the required European regions.

  4. Question 4Advanced

    Configuring Access · Configuring Google Cloud Directory Sync and implementing SSO with third-party identity providers

    Case Study: GlobalMed Logistics

    GlobalMed Logistics is migrating its entire infrastructure to Google Cloud. The company has a complex on-premises environment with 15,000 employees managed via Microsoft Active Directory (AD).

    Currently, users authenticate to various internal applications using on-premises AD Federation Services (AD FS). The Chief Security Officer (CSO) mandates that the existing AD must remain the single source of truth for all identities, password policies, and group memberships. Furthermore, users must be able to seamlessly log into the Google Cloud Console and Google Workspace using their existing Windows domain credentials.

    You have been hired as the Lead Cloud Security Engineer to design the identity architecture.

    Which combination of technologies and configurations is required to fulfill the CSO's identity and authentication requirements?

    Show answer & explanation

    Correct answer: C

    To use Active Directory as the single source of truth while enabling Google Cloud access, you must use GCDS to synchronize the users and groups (but not passwords) to Cloud Identity. For authentication, you configure Cloud Identity to use SAML SSO, redirecting authentication requests to the on-premises AD FS. This ensures passwords never leave the on-premises environment and AD remains the authoritative IdP.

    sequenceDiagram participant User participant GCP as Google Cloud Console participant CI as Cloud Identity participant ADFS as On-Prem AD FS User->>GCP: 1. Navigate to Console GCP->>CI: 2. Redirect for Auth CI->>ADFS: 3. SAML Redirect to IdP ADFS->>User: 4. Prompt for AD Credentials User->>ADFS: 5. Provide Credentials ADFS->>CI: 6. SAML Assertion CI->>GCP: 7. Access Granted

  5. Question 5Intermediate

    Configuring Access · Managing and creating short-lived credentials

    A custom application running on an on-premises server needs temporary access to a Google Cloud Storage bucket to upload nightly database backups. To adhere to security best practices, the security team refuses to issue a persistent service account key. Instead, an automated proxy server with a highly privileged credential will broker access. Which API method should the proxy server call to generate a short-lived token for the on-premises application to use?

    Show answer & explanation

    Correct answer: B

    The IAM Service Account Credentials API provides the generateAccessToken method, which allows a highly privileged identity (acting as a broker) to impersonate a target service account and generate a short-lived OAuth 2.0 access token (valid for up to 1 hour by default). This token can then be safely passed to the on-premises application to upload the files.

  6. Question 6Intermediate

    Configuring Access · Configuring Access Context Manager

    A financial institution wants to implement a BeyondCorp zero-trust model for accessing the Google Cloud Console. They require that administrators can only access the Console if they are using a company-issued device with an up-to-date OS, and their IP address falls within the corporate VPN range. Which Google Cloud service combination should be used to define and enforce these requirements?

    Show answer & explanation

    Correct answer: B

    Access Context Manager allows you to define fine-grained, attribute-based access control rules (Access Levels) based on attributes such as device state, IP address, and user identity. When integrated with BeyondCorp Enterprise (using Endpoint Verification/Workspace Endpoint Management), it can enforce that only trusted, compliant corporate devices from specific IP ranges can access the Google Cloud Console and APIs.

Ready for the real thing?

The full GCP-PCSE simulator has every exam-style question, timed mode, and instant scoring.