Professional Cloud Security Engineer: controls and evidence
Prepare for Professional Cloud Security Engineer with eight lessons, 50 questions, and eight cases on identity, perimeters, data, detection, and governance.
Objectives and progression
Eight lessons with guided application, 50 questions, and eight original cases. Internal assessment of 32 decisions in 60 minutes. Fictional banking examples cover authorization, data exposure, recovery, auditing, and governance requirements. Initial coverage without executable labs or exhaustive treatment of directories, DNS, NGFW, or every product objective. Current Google-linked guide inspected 2026-09-30; edition date not stated. Five approximate weights: 25/22/23/19/11. Exam of 50–60 items in 120 minutes, in English and Japanese. A public numerical passing threshold is unconfirmed.
Audience: Security and platform engineers and APS professionals designing, operating, and investigating Google Cloud controls.
Prerequisites: Networking, IAM, cloud, container, and data-management experience. No formal certification prerequisite; practical Google Cloud experience recommended.
370 estimated study minutes
- Distinguish people, workloads, and temporary grants with traceable identity.
- Explain effective access using grants, denials, and scope.
- Distinguish ingress control, service context, and rule observation.
- Evaluate data and transport boundaries with representative evidence.
- Design the cryptographic lifecycle without losing recovery capability.
- Preserve data utility without confusing transformation, authorization, and blocking.
- Build accessible evidence and connect findings to verifiable actions.
- Translate requirements into controls and evidence with explicit limits.
Modules
- Federation and temporary access
- IAM, deny, and inheritance
- IAP, WAF, and perimeters
- Connectivity and perimeter migration
- Keys, recovery, and data in use
- Minimization, secrets, and AI
- Auditing, detection, and response
- Assurances, residency, and responsibilities
Continue learning
- Professional Cloud DevOps Engineer
- Professional Cloud Architect
- CompTIA Security+
- SC-200 — Security Operations Analyst
- Production Support L3
References and version
Current linked guide; edition date unconfirmed (2026-09-30 inspection)
- Google Cloud certification FAQs · 2026-09-30
- Well-Architected Framework · 2026-09-30
- IAM overview · 2026-09-30
- Resource hierarchy · 2026-09-30
- Workload Identity Federation · 2026-09-30
- Private Service Connect · 2026-09-30
- Cloud Interconnect overview · 2026-09-30
- Cloud KMS key rotation · 2026-09-30
- Binary Authorization overview · 2026-09-30
- Secret Manager best practices · 2026-09-30
- Cloud Logging routing and sinks · 2026-09-30
- Gemini Enterprise Agent Platform overview · 2026-09-30
- Professional Cloud Security Engineer certification · 2026-09-30
- Professional Cloud Security Engineer exam guide · 2026-09-30
- Workforce Identity Federation · 2026-09-30
- Privileged Access Manager overview · 2026-09-30
- IAM deny policies · 2026-09-30
- Service perimeter dry run mode · 2026-09-30
- Cloud Audit Logs overview · 2026-09-30
- Access Approval overview · 2026-09-30
- Access Transparency overview · 2026-09-30
- Security Command Center overview · 2026-09-30
- Identity-Aware Proxy overview · 2026-09-30
- Cloud Armor security policy overview · 2026-09-30
- Cloud NAT overview · 2026-09-30
- Model Armor overview · 2026-09-30
- Confidential VM overview · 2026-09-30
- Sensitive Data Protection pseudonymization · 2026-09-30
- VPC Service Controls overview · 2026-09-30
- Service account impersonation · 2026-09-30
- Cloud External Key Manager · 2026-09-30
- Mute findings in Security Command Center · 2026-09-30
What you will explore
0 / 8Federation and temporary access
Distinguish people, workloads, and temporary grants with traceable identity.
IAM, deny, and inheritance
Explain effective access using grants, denials, and scope.
IAP, WAF, and perimeters
Distinguish ingress control, service context, and rule observation.
Connectivity and perimeter migration
Evaluate data and transport boundaries with representative evidence.
Keys, recovery, and data in use
Design the cryptographic lifecycle without losing recovery capability.
Minimization, secrets, and AI
Preserve data utility without confusing transformation, authorization, and blocking.
Auditing, detection, and response
Build accessible evidence and connect findings to verifiable actions.
Assurances, residency, and responsibilities
Translate requirements into controls and evidence with explicit limits.