Skip to main content
Google Cloud ⭐ Premium

Google Cloud Professional Cloud Security Engineer (PCSE) - 340 Questions

By Webmaster Certland ❤️ 0 likes

Practice exam for the Google Cloud Professional Cloud Security Engineer (PCSE) certification. Covers configuring access, securing communications and boundary protection, ensuring data protection, managing operations, and supporting compliance requirements.

🔒

Premium Content

This exam is exclusive to Premium users. Upgrade to get unlimited access!

Become Premium

👁️ Free Preview (5 of 340 questions)

1. A company is migrating from an on-premises Microsoft Active Directory environment to Google Cloud. They need to synchronize their existing AD users and groups into Cloud Identity without disrupting existing authentication workflows. Which tool should the security engineer configure to accomplish this?

A Google Cloud Directory Sync (GCDS)
B Google Cloud Identity Platform
C Google Cloud Directory API
D Identity-Aware Proxy (IAP)

2. A security engineer is configuring Google Cloud Directory Sync (GCDS) for a company that has 50,000 Active Directory users. The engineer needs to ensure that only users in specific AD Organizational Units (OUs) are synchronized to Cloud Identity, and that deleted AD users are automatically removed from Cloud Identity. Which GCDS configuration best satisfies these requirements?

A Sync all OUs and manually remove users from Cloud Identity when they are deleted in AD
B Configure GCDS scoping rules to include only the target OUs and enable user deletion sync so deleted AD users are removed from Cloud Identity
C Configure GCDS to listen for AD change events and trigger sync only when users are added or deleted
D Use SCIM provisioning directly from Active Directory to Cloud Identity without GCDS

3. An enterprise wants to enable Single Sign-On (SSO) for their Google Cloud users. The company already operates an identity provider (IdP) that supports SAML 2.0. A security engineer needs to configure the IdP so that Google Cloud acts as the service provider. What configuration is required on the Google Admin console side?

A Create an OAuth 2.0 client in the Google Cloud console and provide the client ID to the IdP
B Install and run Google Cloud Directory Sync on the IdP server to enable SSO
C In the Google Admin console, configure the third-party SSO profile by providing the IdP's SSO URL, entity ID, and certificate
D Configure Workforce Identity Federation with the IdP as the OIDC provider in Google Cloud IAM

4. A company's Cloud Identity domain is configured with SAML SSO through a third-party IdP. A user reports they can log in through the IdP dashboard but cannot access the Google Cloud console. The SAML assertion is being sent, but authentication fails. What is the most likely cause?

A The IdP is not mapping the NameID attribute to the user's primary email address in Cloud Identity
B The IdP itself has an authentication failure that prevents the SAML assertion from being generated
C The SAML signing certificate in the Google Admin console does not match the certificate used by the IdP
D Google Cloud Directory Sync has not yet synchronized the user's account to Cloud Identity

5. A company wants to allow contractors who do not have Cloud Identity accounts to access Google Cloud resources using their existing corporate credentials managed in an external OIDC-compliant identity provider. The solution must not require creating Cloud Identity accounts for each contractor. Which Google Cloud feature should the security engineer configure?

A Configure SSO with the external OIDC provider in the Google Admin console so contractors can authenticate via their IdP
B Use Google Cloud Identity Platform to authenticate contractors and grant them access to Google Cloud resources
C Configure Workload Identity Federation with the external OIDC provider to issue short-lived credentials
D Configure Workforce Identity Federation with the external OIDC provider and grant IAM roles to the federated identities

Want to test yourself for real?

Create a free account and run our exam simulation engine.

Free No credit card
  • Simulation engine
  • Up to 10 questions per attempt
  • Score & basic stats
Create free account Already have an account? Sign in
Best
Premium Premium
  • All 340 questions
  • Detailed explanations
  • Smart Practice + Focus Mode
⭐ Get Premium

Discussion

No comments yet. Be the first to start the discussion!

Sign in to join the discussion.