Professional Cloud Security Engineer Exam Blueprint

60Questions
120 minDuration
$200Price
2 yearsValid For
2Languages
Practice Professional Cloud Security Engineer on QuizForge

Credential type: certification examination · verified on the issuer's site September 18, 2026 issuer page

Exam Domains

1 Configuring access 25%
  • 1.1Managing Cloud Identity
    Configuring Google Cloud Directory Sync and implement single sign-on (SSO) with a third-party identity provider; Managing a super administrator account; Automating the user lifecycle management process; Administering user accounts and groups programmatically; Configuring Workforce Identity Federation
  • 1.2Managing service accounts
    Securing and protecting service accounts (including default service accounts); Identifying scenarios requiring service accounts; Creating, disabling, and authorizing service accounts; Securing, auditing, and mitigating the usage of service account keys; Managing and creating short-lived credentials; Configuring Workload Identity Federation; Managing service account impersonation
  • 1.3Managing authentication
    Creating a password and session management policy for user accounts; Setting up Security Assertion Markup Language (SAML) and OAuth; Configuring and enforcing 2-step verification
  • 1.4Managing and implementing authorization controls
    Managing privileged roles and separation of duties with Identity and Access Management (IAM) roles and permissions; Managing IAM and access control list (ACL) permissions; Granting permissions to different types of identities using IAM conditions and IAM deny policies; Defining access control at the organization, folder, project, and resource level using the principle of least privilege; Configuring Access Context Manager; Applying Policy Intelligence; Managing permissions through groups; Identifying use cases and configuring Privileged Access Manager
  • 1.5Defining the resource hierarchy
    Managing folders and projects at scale; Managing pre-built or custom organization policies for the organization, folders, and projects; Using the resource hierarchy for access control and permissions inheritance
2 Securing communications and establishing boundary protection 22%
  • 2.1Designing and configuring perimeter security
    Configuring network perimeter controls (e.g., Cloud Next Generation Firewall [Cloud NGFW] rules and policies, Identity-Aware Proxy [IAP], load balancers, and Certificate Authority Service); Setting up application layer inspection on Cloud NGFW (e.g., layer 7); Differentiating between private and public IP addressing; Configuring web application firewalls (e.g., Google Cloud Armor); Deploying Secure Web Proxy; Configuring Cloud DNS security settings; Continually monitoring and restricting configured APIs
  • 2.2Configuring boundary segmentation
    Configuring security properties of a VPC network, VPC peering, Shared VPC, and firewall rules; Configuring network isolation and data encapsulation for N-tier applications; Identifying use cases and configuring VPC Service Controls
  • 2.3Establishing private connectivity
    Designing and configuring private connectivity between VPC networks and Google Cloud projects (Shared VPC, VPC peering, and Private Google Access for on-premises hosts); Designing and configuring private connectivity and encryption between data centers and VPC network (e.g., HA VPN, Cloud Interconnect); Establishing private connectivity between VPC and Google APIs (Private Google Access, Private Google Access for on-premises hosts, restricted Google access, Private Service Connect); Using Cloud NAT to enable outbound traffic
3 Ensuring data protection 23%
  • 3.1Protecting sensitive data and preventing data loss
    Configuring Sensitive Data Protection (SDP) (e.g., discovering and redacting personally identifiable information (PII), configuring pseudonymization and format preserving encryption); Restricting access to Google Cloud data services (e.g., BigQuery, Cloud Storage, and Cloud SQL datastores); Securing secrets with Secret Manager; Protecting and managing compute instance metadata
  • 3.2Managing encryption at rest, in transit, and in use
    Identifying use cases for Google default encryption, customer-managed encryption keys (CMEK), and Cloud External Key Manager (EKM); Determining when to use software and hardware keys; Creating and managing encryption keys for CMEK and EKM (e.g., key rotation and revocation, key import); Applying encryption methods to various use cases; Configuring object lifecycle policies for Cloud Storage; Enabling Confidential Computing
  • 3.3Securing AI workloads
    Implementing security and privacy controls for AI/ML systems to protect against unintentional exploitation of data or models; Determining security requirements for IaaS-hosted and PaaS-hosted training models; Implementing security controls for Vertex AI
4 Managing operations 19%
  • 4.1Automating infrastructure and application security
    Automating security scanning for Common Vulnerabilities and Exposures (CVEs) through a continuous integration and delivery (CI/CD) pipeline; Configuring Binary Authorization to secure GKE clusters or Cloud Run; Automating virtual machine and container image creation (e.g., hardening, maintenance, VM patch management); Managing policy and drift detection at scale (e.g., cloud security posture management, custom organization policies and custom modules for Security Health Analytics)
  • 4.2Configuring logging, monitoring, and detection
    Configuring and analyzing network logs (Cloud Next Generation Firewall [Cloud NGFW], VPC flow logs, Packet Mirroring, Cloud Intrusion Detection System [Cloud IDS], Log Analytics); Designing an effective logging strategy; Logging, monitoring, responding to, and remediating security incidents; Designing secure access to logs; Exporting logs to external security systems; Configuring and analyzing Google Cloud Audit Logs and data access logs; Configuring log exports (log sinks and aggregated sinks); Configuring and monitoring Security Command Center
5 Supporting compliance requirements 11%
  • 5.1Adhering to regulatory and industry standards requirements for the cloud
    Determining technical needs relative to compute, data, network, and storage; Evaluating the shared responsibility model; Configuring security controls within cloud environments to support compliance requirements (e.g., Assured Workloads, organizational policies, Access Transparency, Access Approval, regionalization of data and services); Determining the Google Cloud environment in scope for regulatory compliance; Mapping compliance requirements to Google Cloud services and security controls (e.g., network and access segmentation, audit log coverage)

Exam Details

Question TypesMultiple Choice, Multiple Select
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, government-issued photo ID with full name, photo, and signature. Name must match registration exactly.
RenewalRequired -- Recertify by passing the same or higher-level exam before expiry. Associate certs valid 3 years; Professional certs valid 2 years.
Retake Policy14-day waiting period after first failed attempt. 60-day waiting period after second failed attempt. 1-year waiting period after third failed attempt within 12 months.
LanguagesEnglish, Japanese

Official Study Resources