Google Cloud Professional Cloud Security EngineerStudy guide
The professional certification for designing/implementing secure Google Cloud via IAM, boundary defense, data protection, security operations, and compliance (Professional Cloud Security Engineer).
About Google Cloud Professional Cloud Security Engineer (GCP-PCSE)
Google Cloud Professional Cloud Security Engineer (GCP-PCSE) is a Professional / Expert-level certification from Google Cloud. This page organizes the exam scope into a 5-chapter, 10-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Configuring access~25%
- Securing communications and establishing boundary protection~22%
- Ensuring data protection~23%
- Managing operations~19%
- Supporting compliance requirements~11%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://cloud.google.com/learn/certification/cloud-security-engineer
1Configuring access
- 1.1Cloud Identity, service accounts, and authentication
Understand Cloud Identity management (Google Cloud Directory Sync, SSO with third-party IdPs, super admin, user-lifecycle automation, Workforce Identity Federation), securing service accounts (default SAs, key auditing/mitigation, short-lived credentials, Workload Identity Federation, impersonation), and authentication (password/session policy, SAML/OAuth, 2-step verification).
- 1.2Authorization controls and resource hierarchy
Understand IAM privileged roles and separation of duties, IAM/ACL permissions, IAM conditions and IAM deny policies, least privilege at organization/folder/project/resource, Access Context Manager, Policy Intelligence, permissions via groups, Privileged Access Manager, and the resource hierarchy (managing folders/projects at scale, pre-built/custom org policies, inheritance).
2Securing communications and establishing boundary protection
- 2.1Perimeter security and edge defense
Understand network perimeter controls (Cloud NGFW rules/policies, Identity-Aware Proxy [IAP], load balancers, Certificate Authority Service), Cloud NGFW application-layer (L7) inspection, private/public IP, web application firewall (Google Cloud Armor), Secure Web Proxy, Cloud DNS security settings, and continually monitoring/restricting configured APIs.
- 2.2Boundary segmentation and private connectivity
Understand security properties of VPC/VPC peering/Shared VPC/firewall, network isolation and data encapsulation for N-tier apps, VPC Service Controls use cases/config, private connectivity between VPCs/projects (Shared VPC, VPC peering, Private Google Access for on-prem), encrypted connectivity between data centers and VPC (HA VPN, Cloud Interconnect), private connectivity to Google APIs (Private Google Access, restricted Google access, Private Service Connect), and egress via Cloud NAT.
3Ensuring data protection
- 3.1Sensitive data protection and data loss prevention
Understand Sensitive Data Protection (SDP) for PII discovery/redaction, pseudonymization, and format-preserving encryption; restricting access to Google Cloud data services (BigQuery, Cloud Storage, Cloud SQL); securing secrets with Secret Manager; and protecting/managing compute instance metadata.
- 3.2Encryption and securing AI workloads
Understand use cases for Google default encryption, customer-managed encryption keys (CMEK), and Cloud External Key Manager (EKM); choosing software vs hardware keys; creating/managing CMEK/EKM keys (rotation/revocation/import); encryption methods per use case; Cloud Storage object lifecycle; Confidential Computing; and security/privacy controls for AI/ML systems and Vertex AI.
4Managing operations
- 4.1Automating infrastructure and application security
Understand automating CVE scanning in CI/CD, Binary Authorization to secure GKE/Cloud Run, automating VM/container image creation (hardening, maintenance, VM patch management), and managing policy/drift detection at scale (cloud security posture management [CSPM], custom org policies, custom modules for Security Health Analytics).
- 4.2Logging, monitoring, and threat detection
Understand configuring/analyzing network logs (Cloud NGFW, VPC flow logs, Packet Mirroring, Cloud IDS, Log Analytics), an effective logging strategy, incident logging/monitoring/response/remediation, secure access to logs, exporting logs to external security systems, configuring/analyzing Cloud Audit Logs and data access logs, log exports (log sinks, aggregated sinks), and configuring/monitoring Security Command Center.
5Supporting compliance requirements
- 5.1Regulatory requirements and the shared responsibility model
Understand determining technical needs for compute/data/network/storage, evaluating the shared responsibility model, identifying the Google Cloud environment in scope for regulatory compliance, and mapping compliance requirements to Google Cloud services and security controls (network/access segmentation, audit-log coverage).
- 5.2Compliance controls and regionalization
Understand configuring security controls that support compliance (Assured Workloads, organization policies, Access Transparency, Access Approval, regionalization of data and services) and implementing the mapping of compliance requirements to Google Cloud services/controls (network/access segmentation, audit-log coverage).

